Sponsored By:


www.tenablesecurity.com


http://twitter.com/pauldotcom


http://www.facebook.com/group.php?gid=6678027341


www.youtube.com/pauldotcom




February 8, 2010

What I learned at Shmoocon 2010

Another successful Shmoocon! This year's conference was well run, tons of fun, and informative. As always what follows is my "What I Learned At Shmoocon" factoids:

  • The small feeling of safety I once had using GSM is completely gone. It now falls into the same category as "Wifi".
  • Mike Poor looks hot in pink (and is the proud owner of a *really* stretched out pink ladies hack naked tank top)
  • Giving the I-Hacked guys a soldering iron results in "Bad things" (depends on your perspective). Injecting audio into the A/V system during a talk and monitoring hotel radio communications are some of the things that sound fun, but were definitely NOT attempted by anyone we know (for the record).
  • Even if it is 3:00AM and I have been drinking I can still "evangelize"
  • PaulHoldingCourt.jpg
    PaulDotCom Holding "Court" In the Hotel Lounge

  • Just because your Bluetooth dongle is paired with a mouse doesn't mean it won't accept keystrokes. This changes my perspective on Bluetooth security and how I use Bluetooth devices: I won't use Bluetooth on anything that passes my data.
  • Kismet now supports passive and active Bluetooth scanning. I've been looking for a replacement to btscanner and hope this is it. By the way, make sure you give Mike Kershaw a beer and thank him for writing Kismet. (Rel1k also got a beer for his work on FastTrack and SET).
  • All nipples are not created equal
  • You can name a drink whatever you want and even call it a F%$*ing Lolipop (jagermeister and Root Beer)
  • Cigars are not as enjoyable when you are standing in the cold with snow blowing all over you
  • Being confronted with the following decision is not easy: Face dehydration (and possible resulting death) or use your credit card in the vending machine at a hacker conference.
  • Shmoo-vending.png
    Slide Your Card Here.....To Get Pwned

  • Our listeners rule and thanked us with beer (explains the dehydration eh?). We love our listeners (but not like that, well maybe). A side note, our favorite beers that we may, or may not have brought to the conference in an unmarked box, are G. Schneider & Sohn Aventinus and Westmalle Trapist Ale (Dubbel).
  • Don't let Carlos get a hold of your toothbrush, ever. And don't mention the toothbrush thing around his family (sorry Carlos!)
  • Mick is no longer allowed on the podcast sober, he is far more entertaining when is is completely drunk. He will express his undying love for Notacon and hockey and force you to love those things just as much as he does.
  • mick_and_jim.jpg
    Hockey & Notacon Bitches!

  • Lockpicking is great fun! I learned that you should check if the lock is open before trying to pick it. Nothing is worse that successfully "picking" the lock only to find out you've locked it, not opened it.
  • PaulDotCom (Larry & Mick) release details on the Cactus Project, showcasing the dangers of P2P networks with respects to data leakage. More details will be released in the coming weeks.
  • When the Shmooball launcher takes aim, run for cover. Larry, along with intern Darren, produced the most spectacular Shmooball cannon ever. While it may not have taken first place in the contest, Bruce can show you a perfectly round bruise on his rib cage as an example of its force.
  • Larry-Shmoocannon.png
    You Have 10 Seconds To Comply...

Thanks to everyone for a great time, espcially the Shmoocon staff, PaulDotCom Crew, and of course all of our fans. We hope to have the store back up and running so you can buy some PaulDotCom "Hack Naked" gear. Can't wait for next year!

February 4, 2010

PaulDotCom Security Weekly - Episode 185 Part 2 - January 28, 2010

The PaulDotCom crew discuss the stories of the week...

larryeatswrt.jpg

Full Show Notes

Direct Audio Download

Hosts: Larry "HaxorTheMatrix" Pesce, Paul "PaulDotCom" Asadoorian, John Strand, Mick Douglas, Carlos "Dark0perator" Perez

Audio Feeds:

PaulDotCom Security Weekly - Episode 185 Part 1 - January 28, 2010

The PaulDotCom crew interviews David Maman, CTO of GreenSQL ...

car-securityfail.jpg

Full Show Notes

Direct Audio Download

Hosts: Larry "HaxorTheMatrix" Pesce, Paul "PaulDotCom" Asadoorian, John Strand, Mick Douglas, Carlos "Dark0perator" Perez

Audio Feeds:

January 31, 2010

PaulDotCom Security Weekly - Episode 184 Part 2 - January 21, 2010

The PaulDotCom crew discuss the stories of the week...

184pt2art.png

Full Show Notes

Direct Audio Download

Hosts: Larry "HaxorTheMatrix" Pesce, Paul "PaulDotCom" Asadoorian, John Strand, Mick Douglas, Carlos "Dark0perator" Perez

Audio Feeds:

CSAW Challenge - Reflections on Pools of Radiance

Doug Burks who maintains the Security Onion project turned me on to the CSAW's Exercises for the burgeoning Army of ninjas. As I went through the challenges two things came to mind. First I thought it might make a good blog posting. Secondly I started reminiscing about Dungeons and Dragons' Pools of Radiance.

Pool's of Radiance was a Dungeons and Dragons simulation for my Commodore 64. The game was great, but in order to combat the software privacy that was so prevelant at the time Strategic Simulation, the games manufacturer, required that you enter a code off of a code wheel to play the game. If you didn't buy the game you supposedly wouldn't have a code wheel and you wouldn't be able to play. Well, I did have a code wheel, but having to dig it out every time I wanted to play was a pain. The result was my first soiree with assembly language. I didn't know what I was doing, but I quickly learned that by changing JZ, JNE, JE and other "conditional jumps" to JMP (an unconditional jump) I could alter the way the game operated and remove the required code wheel. This was of course prior to the DCMA. :) But the excitement only started there, I soon learned I could alter the code that took away my characters hit point, guarantee a successful attack every time and otherwise cheat my way to victory. My love for assembly coding was born.

The CSAW challenges are fun and educational. The skills you learn go beyond protecting Zelda's lifepoints! Going through the exercises will help you with analyzing malware, understanding software bugs and developing exploits.

So check out the exercises HERE

I haven't had a chance to go through all of them, but here are some video's with an overview of using OllyDbg of the first few. Thanks the Matasano and NYU and everyone at the CSAW for sharing them. If you like these challenges there are some similar training exercises on Bright Shadow and Crackmes.

Solution Exercises 1 & 2

Exercise 1 and 2 from PaulDotCom on Vimeo.

Solution Exercise 3

Exercise 3 from PaulDotCom on Vimeo.

Solution Exercises 4 & 5

Exercise 4 and 5 from PaulDotCom on Vimeo.


I will be teaching SANS 504 Incident Handling and Hacker Techniques in Raleigh Durham, NC June 21 through the 26. Register here!

January 29, 2010

Pauldotcom 1-28 Technical Segment - Here's what you missed!

Did you miss last night's live broadcast of Pauldotcom? If so you missed a great technical segment by Carlos Perez that demonstrated the new Metasploit java signed applet exploit. This exploit is a great example of how an attacker can gain access to systems that have no vulnerabilities by taking advantage of inherent weaknesses in the way products such as java applet signing are implemented.

Before you can use this exploit you will need to install a the java developers kit and the rjb ruby gem. Carlos explains how to do that in the show notes.

*Note: In this video I misspoke and said that LPORT is not being used. In fact, it is used by the meterpreter payload for its command and control communications channel.

Pauldotcom Episode 185 from PaulDotCom on Vimeo.

For detailed instructions check out Carlos' description in the show notes from last night. Join us every Thursday night at 7:30 at http://www.pauldotcom.com/live

I will be teaching SANS 504 Incident Handling and Hacker Techniques in Raleigh Durham NC Monday, June 21, 2010 - Saturday, June 26, 2010. Sign up today.

January 28, 2010

Episode 185 recording notice - Thursday Jan 28 - 19:30 EST

Please join us for an interview with David Maman, CTO of GreenSQL, a company creating an Open Source database firewall used to protect databases from SQL injection attacks.. Watch us live at 19:30 EST, Thursday January 28th for Episode 185 of PaulDotCom Security Weekly!

greensql.jpg
GreenSQL - an open source firewall, or a tasty Shepherd's Pie?



Please join the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

PaulDotCom Livestream - All new with Video and Chat! You can access the streaming videos at any time by visiting http://pauldotcom.com/live/

PaulDotCom Icecast Radio

Break out your adult beverage of choice and join us, enjoy the show live, and thanks for listening!

- Paul, Larry, Carlos, Darren, John & Mick

January 27, 2010

PaulDotCom Security Weekly - Episode 184 Part 1 - January 21, 2010

The PaulDotCom crew go one on one with an FBI agent, no handcuffs this time!

coorssucks.jpg
No really, it sucks.

Full Show Notes

Direct Audio Download

Hosts: Larry "HaxorTheMatrix" Pesce, Paul "PaulDotCom" Asadoorian, John Strand, Mick Douglas, Carlos "Dark0perator" Perez

Audio Feeds:

January 25, 2010

PaulDotCom Security Weekly - Episode 183 Part 2 - January 14, 2010

Google/China/Auora crapola, security stuff, fixing the real problems.

f09a5_fud.jpg
This week we all rode the FUD train

Full Show Notes

Direct Audio Download

Hosts: Larry "HaxorTheMatrix" Pesce, Paul "PaulDotCom" Asadoorian, John Strand, Mick Douglas, Carlos "Dark0perator" Perez

Audio Feeds:

January 22, 2010

PaulDotCom Security Weekly - Episode 183 Part 1 - January 14, 2010

Didier Stevens comes on the show to talk about PDF hacking!

fantastic chick corn.jpg
Chicken Corn Noodles are a valid PDF document

Full Show Notes

Direct Audio Download

Hosts: Larry "HaxorTheMatrix" Pesce, Paul "PaulDotCom" Asadoorian, John Strand, Mick Douglas, Carlos "Dark0perator" Perez

Audio Feeds: