Sponsored By:


www.tenablesecurity.com


http://twitter.com/pauldotcom


http://www.facebook.com/group.php?gid=6678027341


www.youtube.com/pauldotcom




Recently in Security Weekly Category

What I learned at Shmoocon 2010

|

Another successful Shmoocon! This year's conference was well run, tons of fun, and informative. As always what follows is my "What I Learned At Shmoocon" factoids:

  • The small feeling of safety I once had using GSM is completely gone. It now falls into the same category as "Wifi".
  • Mike Poor looks hot in pink (and is the proud owner of a *really* stretched out pink ladies hack naked tank top)
  • Giving the I-Hacked guys a soldering iron results in "Bad things" (depends on your perspective). Injecting audio into the A/V system during a talk and monitoring hotel radio communications are some of the things that sound fun, but were definitely NOT attempted by anyone we know (for the record).
  • Even if it is 3:00AM and I have been drinking I can still "evangelize"
  • PaulHoldingCourt.jpg
    PaulDotCom Holding "Court" In the Hotel Lounge

  • Just because your Bluetooth dongle is paired with a mouse doesn't mean it won't accept keystrokes. This changes my perspective on Bluetooth security and how I use Bluetooth devices: I won't use Bluetooth on anything that passes my data.
  • Kismet now supports passive and active Bluetooth scanning. I've been looking for a replacement to btscanner and hope this is it. By the way, make sure you give Mike Kershaw a beer and thank him for writing Kismet. (Rel1k also got a beer for his work on FastTrack and SET).
  • All nipples are not created equal
  • You can name a drink whatever you want and even call it a F%$*ing Lolipop (jagermeister and Root Beer)
  • Cigars are not as enjoyable when you are standing in the cold with snow blowing all over you
  • Being confronted with the following decision is not easy: Face dehydration (and possible resulting death) or use your credit card in the vending machine at a hacker conference.
  • Shmoo-vending.png
    Slide Your Card Here.....To Get Pwned

  • Our listeners rule and thanked us with beer (explains the dehydration eh?). We love our listeners (but not like that, well maybe). A side note, our favorite beers that we may, or may not have brought to the conference in an unmarked box, are G. Schneider & Sohn Aventinus and Westmalle Trapist Ale (Dubbel).
  • Don't let Carlos get a hold of your toothbrush, ever. And don't mention the toothbrush thing around his family (sorry Carlos!)
  • Mick is no longer allowed on the podcast sober, he is far more entertaining when is is completely drunk. He will express his undying love for Notacon and hockey and force you to love those things just as much as he does.
  • mick_and_jim.jpg
    Hockey & Notacon Bitches!

  • Lockpicking is great fun! I learned that you should check if the lock is open before trying to pick it. Nothing is worse that successfully "picking" the lock only to find out you've locked it, not opened it.
  • PaulDotCom (Larry & Mick) release details on the Cactus Project, showcasing the dangers of P2P networks with respects to data leakage. More details will be released in the coming weeks.
  • When the Shmooball launcher takes aim, run for cover. Larry, along with intern Darren, produced the most spectacular Shmooball cannon ever. While it may not have taken first place in the contest, Bruce can show you a perfectly round bruise on his rib cage as an example of its force.
  • Larry-Shmoocannon.png
    You Have 10 Seconds To Comply...

Thanks to everyone for a great time, espcially the Shmoocon staff, PaulDotCom Crew, and of course all of our fans. We hope to have the store back up and running so you can buy some PaulDotCom "Hack Naked" gear. Can't wait for next year!

PaulDotCom Security Weekly - Episode 185 Part 2 - January 28, 2010

|

PaulDotCom Security Weekly - Episode 185 Part 1 - January 28, 2010

|

PaulDotCom Security Weekly - Episode 184 Part 2 - January 21, 2010

|

PaulDotCom Security Weekly - Episode 184 Part 1 - January 21, 2010

|

The PaulDotCom crew go one on one with an FBI agent, no handcuffs this time!

coorssucks.jpg
No really, it sucks.

Full Show Notes

Direct Audio Download

Hosts: Larry "HaxorTheMatrix" Pesce, Paul "PaulDotCom" Asadoorian, John Strand, Mick Douglas, Carlos "Dark0perator" Perez

Audio Feeds:

PaulDotCom Security Weekly - Episode 183 Part 1 - January 14, 2010

|

Didier Stevens comes on the show to talk about PDF hacking!

fantastic chick corn.jpg
Chicken Corn Noodles are a valid PDF document

Full Show Notes

Direct Audio Download

Hosts: Larry "HaxorTheMatrix" Pesce, Paul "PaulDotCom" Asadoorian, John Strand, Mick Douglas, Carlos "Dark0perator" Perez

Audio Feeds:

Please join us for an interview with computer forensics expert Eric M. Fiterman to discuss his background as an FBI Special Agent, his current work at Methodvue, and his upcoming Shmoocon presentation on forensics in the Cloud. Watch us live at 19:30 EST, Thursday January 21st for Episode 184 of PaulDotCom Security Weekly!

batboyfbi.jpg
Although Eric can neither confirm nor deny... Ah heck, he pretty much flat out denied.



Please join the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

PaulDotCom Livestream - All new with Video and Chat! You can access the streaming videos at any time by visiting http://pauldotcom.com/live/

PaulDotCom Icecast Radio

Break out your adult beverage of choice and join us, enjoy the show live, and thanks for listening!

- Carlos, Larry, Mick, John, Darren, & Paul

PaulDotCom Security Weekly - Episode 182 Part 2 - January 7, 2010

|

Mick walks us through sneaky web crawling, GSM & DECT cracked, and more stories and tech news!

brewed-beer-coozie-back.jpg
Full Show Notes

Direct Audio Download

Hosts: Larry "HaxorTheMatrix" Pesce, Paul "PaulDotCom" Asadoorian, John Strand, Mick Douglas, Carlos "Dark0perator" Perez

Audio Feeds:

We'll chat with Belgium Security Blogger Didier Stevens about Google adwords, pdf readers, twitter controlled Christmas trees and his unhealthy obsession with RFID tags. Watch us live at 19:30 EST, Thursday January 14th for Episode 183 of PaulDotCom Security Weekly.

gas-detector-small.png
Sensor overloaded after being exposed to the after effects of pizza and beer with PaulDotCom



Please join the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

PaulDotCom Livestream - All new with Video and Chat! You can access the streaming videos at any time by visiting http://pauldotcom.com/live/

PaulDotCom Icecast Radio

Break out your adult beverage of choice and join us, enjoy the show live, and thanks for listening!

- John, Darren, Mick, Carlos, Paul, & Larry

PaulDotCom Security Weekly - Episode 182 Part 1 - January 7, 2010

|

Bruce Potter comes on the show to talk about the death of defense in depth, full disclosure, netflow analysis, trusted computing, and Lard.

Lard-001.jpg
Because sometimes you just need pure lard.

Full Show Notes

Direct Audio Download

Hosts: Larry "HaxorTheMatrix" Pesce, Paul "PaulDotCom" Asadoorian, John Strand, Mick Douglas, Carlos "Dark0perator" Perez

Audio Feeds: