Main

May 29, 2008

PaulDotCom Security Weekly - Episode 109 - May 22, 2008

Live from the PaulDotCom studios...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

Gone Fishin'

No, not permanently! We're just taking the week off.

It has been a hack of a week since we recorded Episode 109 (to be released later today)! There have been additions to family, remembrances of those lost, and time with loved ones. Needless to say this week has been about family.

We haven't forgotten about you all, our extended family of faithful podcast listeners and blog readers. We'll be back on track with a fantastic show next week.

Thanks for all of your continued support.

- Larry & Paul

May 23, 2008

PaulDotCom Security Weekly - Episode 108 Part II - May 15, 2008

Live from the PaulDotCom studios, Larry via Skype, and JJ comes on the show to talk about FreeBSD security, open-source tools for scheduling Nessus scans, Debian not-so-randomness, and more!...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

May 22, 2008

Recording and Stream Notice - Episode 109

The live stream should be active about 6:45 PM EDT, Thursday, May 22nd. We should begin recording the live show at about 7:00 PM EDT. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

Ustream: http://ustream.tv/channel/pauldotcom-security-weekly

Icecast: http://radio.oshean.org:8000

Please join us, and thanks for listening!

psw-simpsons.jpg

- Larry & Paul

May 12, 2008

PaulDotCom Security Weekly - Episode 107 - May 9, 2008

Live from the PaulDotCom studios...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

May 09, 2008

Recording & Stream Notice - Episode 107

The live stream should be active about 6:45 PM EDT, Friday, May 9th. We should begin recording the live show at about 7:00 PM EDT. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

Ustream: http://ustream.tv/channel/pauldotcom-security-weekly

Icecast: http://radio.oshean.org:8000

Please join us, and thanks for listening!

pdcskin.jpg

- Larry & Paul

May 07, 2008

Late-Breaking Computer Attack Vectors - April 2008

The media for the April 2008 Late-Breaking Computer Attack Vectors webcast is ready to be released:

LBCAV April 2008 - Audio

LBCAV April 2008 - Slides

This is a 45 minute presentation on the latest happenings in computer security, vulnerabilities, and methods in use by attackers. I've also included several recommendations for defensive measures, so enjoy! If you want to listen live this webcast is done on the last Wednesday of every month at 2:00PM EST.

I hope to create a podcast feed for the audio sometime in the near future as well.

Mission-impossible1.jpg

PaulDotCom

May 06, 2008

PaulDotCom TV: The Making Of The Shmooball Cannon

Larry did a fantastic job with the Shmooball Cannon, it was featured on Make Magazine and Hack A Day. It was such a huge success that we produced a video detailing how it was made, including several takes of Paul getting shot:


This video will also be added to our video feed and our YouTube channel:

Video Feeds:


YouTube: PaulDotCom YouTube Channel.

Look for more videos to come!

PaulDotCom

May 05, 2008

PaulDotCom Security Weekly - Episode 106 - May 1, 2008

Live from the PaulDotCom studios...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

May 01, 2008

Recording & Stream Notice - Episode 106

The live stream should be active about 6:15-6:30 PM EDT, Thursday, May 1st. We should begin recording the live show at about 6:30 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

Ustream: http://ustream.tv/channel/pauldotcom-security-weekly

Icecast: http://radio.oshean.org:8000

Please join us, and thanks for listening!

pdcskin.jpg

- Larry & Paul

April 30, 2008

Network Security Podcast - Episode 103 Appearance

All:

It was my pleasure to make and appearance on the Network Security Podcast with Martin McKeay and Rich Mogull. We had some interesting conversations about SQL Injection, how we got started in computer security, thoughts on the CISSP certification, PCI and its usefullness, and general security banter.

You can download the Network Security Podcast episode 103 here.

Enjoy!

PaulDotCom

April 29, 2008

April Late-Breaking Computer Attack Vectors Webcast

All:

The April Late-Breaking Computer Attack Vectors webcast this month will be held on:

Wednesday, April 30, 2008 2:00 pm EDT (GMT -04:00, New York)

Register Here For This Webcast

This month we I will discuss some of the latest attacks, including hacking kiosks, attacking your desk, and darkets for defense. Hope to see you there...

PaulDotCom

April 28, 2008

Appearing On Network Security Podcast

At 9:00PM EST tonight I will be chatting with Rich & Martin from the Network Security Podcast. Should be fun, we will bat around PCI, SQL injection, and hopefully a few other topics of interest.

You can see and hear it all on our live Ustream channel here.

Cheers,

PaulDotCom

PaulDotCom Security Weekly - Episode 105 - April 25, 2008

Live from the PaulDotCom studios...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

April 25, 2008

Recording & Stream Notice - Episode 105

NOTE: Our streaming method has changed as of episode 100, and is reflected in the links below.

The live stream should be active about 6:15-6:30 PM EDT, Friday April 25th. We should begin recording the live show at about 6:30 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

Ustream: http://ustream.tv/channel/pauldotcom-security-weekly

Icecast: http://radio.oshean.org:8000

Please join us, and thanks for listening!

mrtpdc.jpg

- Larry & Paul

April 22, 2008

Scamming Social Networks

Social networks have become a very popular usage of so-called "Web 2.0" technology. Web sites, such as Facebook and LinkedIn, have begun to move towards targeting working professionals, in addition to the traditional younger college and/or high school crowd. Myself, and others, have been doing extensive research into the security (and insecurity) present in social networking web sites. You may now be wondering, "Just how have you been doing your research?". Well, we decided to register ourselves on several social networking web sites to see just how they work, and just how ourselves and others could break them and abuse the security present in these web sites. What we've found has been very interesting, and useful for providing the community with information about the risks, and tips to protect themselves:

The “Evil Twin” attack was an experiment we performed, and turned out to be wildly successful. We registered a Facebook account as someone else, using an email address we controlled, pictures we downloaded from the Internet, and information we gathered from various publicly available sources. Our attack was very successful, several people believed that the person we faked was real and started to add them as a friend. The best defense here is to register yourself on social networking web sites to prevent others from doing so. We did a segment about this which you can read about and listen to here.

If you use social networking sites regularly you might say, “only people in my network can see my information or my pictures”. This may be true, however XSS vulnerabilities have exposed that information. For example, millions of pictures marked “private” on the popular social network site MySpace, and subsequently Facebook, were suddenly public due to a vulnerability. Once something is “public” on the Internet, there is no going back, its archived in cyberspace forever. Even without vulnerabilities there are groups on sites such as Facebook, and to a certain extent LinkedIn, that automatically allow others in your group to see your profile. For example, I was placed in the group “Providence, RI”, a group anyone can join, and now thousands of people can see my profile. You should always treat information on the Internet as public, whether marked "private" or not.

Recently there has been an unknown exploit of Facebook that is hijacking people’s Facebook accounts and putting up grotesque images, a social network “Rick Roll” attack with a bizarre twist. Reportedly there was a vulnerability in Facebook that allowed this to happen. However, recently I got the following email:

facebookemail.jpg

Looking at the link highlighted in red closely you see that it does not go to Facebook at all, but to some other site, which looks exactly like the Facebook login page, but really is an attacker collecting your username and password. Why would someone launch a phishing attack against Facebook? I'm still not certain why this information is so valuable that it is being targeted by attackers? If nothing else it proves that social networking sites are not only more popular, but represent an area that potentially could be profitable for attackers - as soon as I figure out how, I will let you know :).

Social networks are all about sharing information, however they’re a great way to distribute attacks. Attackers are not looking to use social networks to distribute links to a trusted audience, not just for fun, but profit! Use extreme caution when using social networks and try to think how attackers could use this information and technology against you.

There is no spoon...

Recently I taught a 2-day hacking course titled "Cutting-Edge Hacking Techniques", writen by Ed Skoudis, and offered by The SANS Institute. The students learned a lot, and as always when I teach, so did I. I summarized my thoughts and experiences on a guest blog posting I wrote for my friends over at GNUCITIZEN:

Read the full posting here.

Enjoy!

Cheers,
Paul

April 14, 2008

PaulDotCom Security Weekly - Episode 104 - April 11, 2008

Live from the PaulDotCom studios with special guest Wesley McGrew talking about memory analysis tools.

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

April 12, 2008

PaulDotCom Security Weekly - Episode 103 Part II - April 3, 2008

Live from the PaulDotCom studios with special guest Kevin "The Hacker Princess" Johnson! In the second part of this episode we wrap up the discussion on web app testing and cover the stories for the week.

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

April 11, 2008

Recording & Stream Notice - Episode 104

NOTE: Our streaming method has changed as of episode 100, and is reflected in the links below.

The live stream should be active about 6:15-6:30 PM EDT, Friday April 11th. We should begin recording the live show at about 6:30 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

Ustream: http://ustream.tv/channel/pauldotcom-security-weekly

Icecast: http://radio.oshean.org:8000

Please join us, and thanks for listening!

make-the-switch.jpg

- Larry & Paul

April 06, 2008

PaulDotCom Security Weekly - Episode 103 Part I - April 3, 2008

Live from the PaulDotCom studios with special guest Kevin "The Hacker Princess" Johnson!

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

April 03, 2008

Recording & Stream Notice - Episode 103

NOTE: Our streaming method has changed as of episode 100, and is reflected in the links below.

The live stream should be active about 6:15-6:30 PM EDT, Thursday April 3rd. We should begin recording the live show at about 6:30 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

Ustream: http://ustream.tv/channel/pauldotcom-security-weekly

Icecast: http://radio.oshean.org:8000

Please join us, and thanks for listening!

make-the-switch.jpg

- Larry & Paul

March 28, 2008

My Latest Presentations

All:

Recently I've done some webcasts on various security topics in a few different venues (webcasts and the like). I've had several requests for the presentation media, so I've updated our presentations section with the following:

I really enjoy doing the monthly threat summary and try to include as many "bleeding edge" threats as I can. Most I pull from my hundreds of security news feeds, and some I pull from my twisted imagination. The webcast had over 200 people listening live, so we are very pleased with the level of interest and thank all those who have attended. If you enjoyed the webcast please share it with all of your friends.

Thanks for listening!

PaulDotCom

March 23, 2008

Press Release: PaulDotCom and Haxorthematrix Blogs Merge

As we move forward building PaulDotCom Enterprises we will be working to consolidate some of our other efforts under one umbrelss. As such Larry and myself have agreed that the Haxorthematrix blog will be moved to PaulDotCom. The domain will redirect to this site and Larry will begin posting all his fantastic content to pauldotcom (So if you really like the content, you can click the donate button on the left :).

Some of the latest postings from Haxorthematrix will be moved over to pauldotcom, so look for some good stuff coming soon!

Happy Easter to all those who celebrate it!


pdcbanner2.jpg

haxorthematrix.jpg

Cheers,

PaulDotCom

March 22, 2008

Shmooball Launcher Teaser Trailier

All:

Coming soon, we'll be showing you how the 2008 Shmooball launcher goes together and operates. We even get to fire it a few times. Here's a tease of how we made out.

This video has also been added to our video feed and our YouTube channel

Video Feeds:

YouTube: PaulDotCom YouTube Channel.

Look for more videos to come!

- Larry aka haxorthematrix

March 21, 2008

PaulDotCom Security Weekly - Episode 102 - March 20, 2008

Live from the PaulDotCom studios...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

March Late-Breaking Computer Attack Vectors Webcast

All:

The March Late-Breaking Computer Attack Vectors webcast this month will be held on:

Wednesday, March 26, 2008 2:00 pm EDT (GMT -04:00, New York)

Register Here For This Webcast

This month we are sponsored by Mu Security, makers of a security analyzer series of products (aka automated fuzzing). Very cool devices! I will discuss some of the latest attacks, including RFID, attacking SIM cards, and more! Hope to see you there...

PaulDotCom

March 19, 2008

PaulDotCom Security Weekly - Episode 101 - March 13, 2008

Live from the PaulDotCom studios...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

Recording & Stream Notice - Episode 102

NOTE: Our streaming method has changed as of episode 100, and is reflected in the links below.

The live stream should be active about 6:30-6:45 PM EDT, Thursday March 20th. We should begin recording the live show at about 6:45 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

Ustream: http://ustream.tv/channel/pauldotcom-security-weekly

Icecast: http://radio.oshean.org:8000

Please join us, and thanks for listening!

l33t_odo_sm.jpg

- Larry & Paul

March 14, 2008

PaulDotCom Security Weekly - Special Edition - Interview with GNUCITIZEN Part II - March 7th, 2008

Live from the PaulDotCom Security Weekly Studio, the fine folks from GNUCITIZEN (Petko D. Petkov and Adrian P.) join us for discussion on more of their projects including MDNS and others. Part two of two.

There is s slight, barely audible echo in a few places as an artifact from Skype! We apologize!

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

March 11, 2008

Recording & Stream Notice - Episode 101

NOTE: Our streaming method has changed as of episode 100, and is reflected in the links below.

The live stream should be active about 5:45-6:00 PM EST, Thursday March 13th. We should begin recording the live show at about 6:15 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

Ustream: http://ustream.tv/channel/pauldotcom-security-weekly

Icecast: http://radio.oshean.org:8000

Please join us, and thanks for listening!

larryeatswrt-sm.jpg

- Larry & Paul

March 10, 2008

PaulDotCom Security Weekly - Special Edition - Interview with GNUCITIZEN Part I - March 7th, 2008

Live from the PaulDotCom Security Weekly Studio, the fine folks from GNUCITIZEN (Petko D. Petkov and Adrian P.) join us for discussion on how they got started, and who they are all about and delve into some of their projects in this episode. Part one of two.

There is s slight, barely audible echo in a few places as an artifact from Skype! We apologize!

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds: add to my PodNova

March 09, 2008

PaulDotCom TV - Video Feed Update

The PaulDotCom TV video feed lives on! I just know that everyone was dying to have the latest videos from PaulDotCom available on your iPods and iPhones, so I've updated the feed with the latest four spectacular videos from the PaulDotCom crew. They include:

  • Make the Switch: Danny - Larry and I were talking one day last week about the number of listeners that have given us much of the same feedback. They all stated something along the lines of, "I used to listen to Security Now!, but now I listen to PaulDotCom Security Weekly". So, on the last podcast we asked real listeners to record their own switch commercials (audio only). I've added a bit of flavor (thanks to iMovie) and created this video of our first submission (Thanks Danny!).
  • Set Your Router On Fire! SANS SEC 535 - We have created a promotion video for the SANS course I authored called "SEC535 - Network Security Projects Using Hacked Wireless Routers". Sign up for this course today!
  • The Destruction Files - Paul & Larry have some fun busting up some old computer equipment. Sun monitor, take 2, network sniffer, and a Cisco switch all fall victim to Paul's new sledge...
  • Where's Twitchy? - So many of you have written to ask us the age old question, "Where's Twitchy?". This video provides you with the answer...

Video Feeds:

All of these videos are also available on our PaulDotCom YouTube Site. Look for more videos to come!

PaulDotCom

March 07, 2008

Recording and Stream Notice - GNUCITIZEN

NOTE: Our streaming method has changed as of episode 100, and is reflected in the links below.

The live stream should be active about 5:45-6:00 PM EST, Friday March 7th. We should begin recording the live show at about 6:15 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

Ustream: http://ustream.tv/channel/pauldotcom-security-weekly

Icecast: http://radio.oshean.org:8000

Please join us, and thanks for listening!

- Larry & Paul

March 03, 2008

Rhode Island Linux Installfest

All:

In collabortation with SNENUG (The Southern New England Network Users Group), OSHEAN, and PaulDotCom, we are proud to bring you a good 'ole fashion Linux installfest! Got an old PC hanging around? Bring it by! Got a dusty old ipod or wireless router? Come get help with installing Linux, a free operating system that is fun to learn and hack with.

Members of PaulDotCom (Larry and Myself), in addition to some other Linux "gurus" will be at OSHEAN for a full day on Saturday April 5, 2008 to assist people installing Linux.

For more information and to register for this event click here.

I hope to see you all there (however seating is limited so be certain to register at the link above).

Cheers,

Paul

PaulDotCom's Penetration Testing Dojo: Core IMPACT Style

This is going to be another neat webcast in collaboration with SANS and Core Security. Below is the description and sign-up information:

"When beginning a security process at a consortium of non-profits, senior network security engineer, Paul Asadoorian of Pauldotcom began looking for a penetration testing tool that did network, web application and social engineering tests. The tool he purchased is low on manpower use, mostly self-maintaining and reliably proves the existence of network vulnerabilities. Please attend this webcast to find out why Paul selected CORE IMPACT and learn how it can help you safely perform network, web application and end-user penetration testing."

When: Tuesday, March 18 at 1:00 PM EDT (1700 UTC/GMT)
Where: Sign-up here
Who: Allen Paller & Paul Asadoorian

This webcast will give listeners some insight into why I have used Core IMPACT in many different organizations, its benefits, and some of the more creative uses for the product.

Sign-up Today!

PaulDotCom

PaulDotCom Security Weekly - Episode 100 Part II - February 28, 2008

Live from the PaulDotCom Security Weekly Studio for Episode 100! Special guest appearnces from listeners across the world, Black Dragon offers listeners a special treat, and Paul & Larry profess their love for each other...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds: add to my PodNova

PaulDotCom Security Weekly - Episode 100 Part I - February 28, 2008

Live from the PaulDotCom Security Weekly Studio for Episode 100! Special guest appearnces from Ed Skoudis, Ron Gula, the British Royal Family, and Bob's true identity revealed!

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds: add to my PodNova

February 28, 2008

Recording and Stream Notice - The Big 100!

NOTE: Our streaming method has changed as of episode, and is reflected in the links below.

The 100th episode of PaulDotCom Security Weekly, W00t! There will be much rejoicing, the Skype lines will be open, we have multiple audio clips to play, and this just in, Bob's true identity revealed!

The live stream should be active about 6:30-7:00 PM EST, Thursday February 28th. We should begin recording the live show at about 7:00 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

Don't forget, this is a call in type event! We will have Skype active (id "pauldotcom"), or call in to 401-626-4636!

We using Ustream.tv for this and future episodes (now with video!). We understand the importance of this monumental event, and we will be attempting to make both audio streams available for this episode.

When active, the live stream(s) can be found at:

Ustream: http://ustream.tv/channel/pauldotcom-security-weekly

Icecast: http://radio.oshean.org:8000

Please join us, and thanks for listening!

- Larry & Paul

February 22, 2008

Late Breaking Computer Attack Vectors - Registration Information

This is the first webcast in a monthly webcast series that we are putting on, so bear with us while we work out all of the logistics. I wanted to share the direct registration link:

Late Breaking Computer Attack Vectors - Feb 27 2:00PM EST

I am very excited about this new opportunity and hope you are able to listen in!

Cheers,

PaulDotCom

February 21, 2008

Announcing A New Monthly Webcast: "Late-Breaking Computer Attack Vectors"

PaulDotCom has teamed up with White Hat World to bring you a monthly 30-40 minute webcast titled "Late-Breacking Computer Attack Vectors". I will be hosting the technical discussions where I will b covering the trends happening in security for that month and defensive strategies. Details below:

When: February 27th 2:00PM EST (They will all occur on the last Wednesday of each month at 2:00PM EST,with the exception of November 25, 2008 and December 23, 2008)

Who: Hosted by Paul Asadoorian from PaulDotCom Security Weekly

What Is It? This lively session will discuss recent and anticipated computer and network attack vectors, highlighting the current trends in information security and hacking. Understand some of the most powerful tools and methods in the bad guys' arsenal today, most importantly how to defend your network against them. For each attack vector, we will look at practical, real-world solutions for stemming the tide and keeping your network a safer place.

Registration: Please visit http://www.whitehatworld.com for more information.

We are very excited about this opportunity and I also hope to release these as a podcast as well.

PaulDotCom

February 20, 2008

Episode 99 Problems

All:

If you are experiencing problems with episode 99, please delete the podcast from iTunes and re-add it. It seems that Libsyn and iTunes got stuck indexing only the first 9 seconds of the podcast. I think this is because I ran out of space on my Libsyn account, which I have since upgraded. Please contact us if you hasve any problems.

Thank You,

PaulDotCom

February 18, 2008

PaulDotCom Security Weekly - Episode 99 - February 16, 2008

Paul is live from the PaulDotCom Security Weekly Studio, and Larry is live from Shmoocon! Get the latest information from the hottest security conference this year!

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds: add to my PodNova

February 14, 2008

Shmoocon and Recording notice.

Just as a reminder Larry will be at Shmoocon this weekend in chilly Washington DC. Don't forget to check our the podcasters meet up Friday night. It is our understang that we'll be doing a video cast, and streaming live courtesy of the geeks at Hak.5. Stay tuned for more details as they unfold.

Larry has a limited supply of some shwag, but plenty of stickers!

Additionally, the PaulDotCom crew will be recording an episode on Saturday Feb, 16 at about 6:30 PM.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream can be found at:

http://radio.oshean.org:8000

Please join us, and thanks for listening!

February 11, 2008

SEC535 - "Set Your Router On Fire" Video

All:

We have created a promotion video for the SANS course I authored called "SEC535 - Network Security Projects Using Hacked Wireless Routers":

Sign up for this course today:

SANS Orlando (Comes with your very own copy of Linksys WRT54G Ultimate Hacking by Paul Asadoorian and Larry Pesce!

If you are interested in this course and cannot attend the Orlando conference please contact me (paul /at/ pauldotcom.com) for more information.

PaulDotCom

PaulDotCom Mailing List

All:

Larry and myself have many conversations about how to best communicate with our listeners, send/receive feedback, and generally what our presence on the Internet should be. We've created a mailing list with the following intentions:

  • General Questions/Feedback - Please do still send email to psw /at/ pauldotcom.com, however Larry and I are sometimes busy and do not get a chance to respond to all emails. This mailing list can serve as a place to post questions, feedback, or general comments and the hope is that if Larry or myself can't respond, someone else will.
  • Announcements - Yes, we have a blog, podcast, and multiple RSS feeds. However, some just prefer to have a mailing list that keeps them current. We intend to use the list to announce episodes, locations where we are recording live, contests, and everything related to PaulDotCom!
  • Technical Discussion - We hope that the discussions on the mailing list will be as technical and informative as the podcast and to a certain extent the IRC channel. Our goal is to keep everyone educated and allow you to learn about computer security and hacking, and hopefully the mailing list helps you do that

So come join now!

PaulDotCom

February 08, 2008

PaulDotCom Security Weekly - Episode 98 Part II - January 31, 2008

Live from the PaulDotCom Security Weekly Studio with our very own "reverse engineering specialist", the baby maker from Canada himself, Justin Seitz!

In part II of this episode we first have an awesome discussion about how broken the information security industry is right now and offer some advice on how to fix it, then cover the stories for the week.

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds: add to my PodNova

February 03, 2008

./PaulDotCom &

Just a quick notice to all listeners that we will not be recording the week of February 4, 2008. Our short little hiatus will be just that, short. We are releasing episode 98 in two parts as it was a two hour show, full of glorious security karma. Also filling the the gaps is my keynote presentation on hacking embedded devices which is always a treat.

Looking ahead we are planning a special 100th episode where we hope to have participation from many of our dedicated and wonderful listeners and collaborators on the show. We may take a week off in order to prepare for this show as I believe that 100 episodes is quite a landmark achievement for PaulDotCom Security Weekly. Still to this day I am astonished at what we have created. Don't worry we have plenty of new, exciting, entertaining, and informative inititives up our sleeves so stay tuned! Along with a new web site in the works there may be some special annoucements regarding PaulDotCom as we move forward to reach out to new audiences and continue to grow.

As always, thank you for listening...

PaulDotCom

PaulDotCom Security Weekly - Episode 98 Part I - January 31, 2008

Live from the PaulDotCom Security Weekly Studio with our very own "reverse engineering specialist", the baby maker from Canada himself, Justin Seitz!

In part I of this episode we cover two technical segments, one by Justin on DLL injection, and one by PaulDotCom on hacking mDNS/Bonjour/Zeroconf.

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds: add to my PodNova

January 31, 2008

Recording and Stream Notice - Episode 98

NOTE: Our Streaming server has changed as of episode 94, and is reflected in the link below.

The live stream should be active about 7:00-7:30 PM EST, Thursday January 31st. We should begin recording the live show at about 7:30 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream can be found at:

http://radio.oshean.org:8000

Please join us, and thanks for listening!

- Larry & Paul

January 29, 2008

PaulDotCom Switch Commercial - Danny

Larry and I were talking one day last week about the number of listeners that have given us much of the same feedback. They all stated something along the lines of, "I used to listen to Security Now!, but now I listen to PaulDotCom Security Weekly". So, on the last podcast we asked real listeners to record their own switch commercials (audio only). I've added a bit of flavor (thanks to iMovie) and created a YouTube video of our first submission (Thanks Danny!):

Enjoy! And keep those submissions coming as we reward with fabulous prizes!

PaulDotCom

January 28, 2008

Where's My iPhone? - A Lesson In Incident Response

Introduction

Security incidents come in many forms, from attackers breaking into computers, unauthorized attempts to sniff wireless networks and collect information, and stolen laptops or phones. This example is the latter, a stolen smartphone. What follows is the incident response procedure that I followed once I found out my phone had been stolen. Its not a comfortable feeling to know that someone else has control over a device containing your information. However, you must remain calm and follow some sort of incident response procedure. Sometimes this is not as easy as it sounds (as you will see below). Once the incident is over the most important thing you must do is learn from it. Hopefully you can learn from my experience.

Some Days Are Better Than Others

This all started with one of the things I enjoy most in this world, and thats sushi (In fact Josh just pointed out that I was the one who introduced him to sushi, and now he has an entire site named after this fabulous food!). I was going out to eat with my family and was talking on my iPhone on the way. I pulled into a spot in the parking lot, got out of the car and went into the restaurant where I draped my long trenchcoat over the chair on the table behind me. After feasting on some sushi ("slammin' salmon" roll was awesome) we paid the bill and I all of a sudden realized I did not have my phone. I searched my pockets, no iPhone. I thought, "well, I must have left it in my coat". I searched my coat, no iPhone. I searched around the table and the table behind us where my coat had been, no iPhone. I then thought, "well, it must be in the car". I searched the car, making everyone get out all while I cursed aloud, and no iPhone. I went back into the restaurant and searched the tables again, no iPhone. The conclusion, someone had stolen my iPhone when I either dropped it getting our of the car or when it fell out of my coat pocket.

Incident Response 101: Don't Panic

So I called my wife in a panic, explaining to her how someone else now has possession of my phone, which not only contained countless pictures of our last vacation and family (mostly pictures of the dog), but also had access to ALL of my email accounts. I was on my way to a family members house to get a flashlight to do a more thorough search of the car, as I was still in disbelief that someone stole my phone. Human instinct is a funny thing, even though I have training in computer incident response (even worked a few cases of data theft) I was still in great disbelief that someone would actually steal my phone. Another search through the car, guess what no iPhone. My only saving grace was that I left my home phone number with the restaurant in case the phone magically appeared. On my way home I still thought there would be a chance that they found my phone and called the house to tell me. I got home, no phone call and still no iPhone.

When you can't prevent or detect, react

I picked up my wife's phone as soon as I got home and dialed 611, the number for direct access to AT&T customer service. I waded my way through the options and discovered that I could report the other phone line, and associated phone, lost or stolen right through the menu, after of course being prompted for the billing zip code. Thats right, the only authentication you need to cancel the other line is the billing zip code. This means you can use anyone's AT&T phone to disconnect the other line on that account, and all you need is access to that phone and the billing zip code (most people put their address on the phone in case its lost, how ironic). If you are a smart phone thief, you can disable the other line when you steal a phone.

My iPhone had access to all of my email via passwords stored on the phone itself. My first step was to change all of my email passwords immediately. Once that was done I also changed the pin number to my voicemail. There was nothing sensitive in my email lately (i.e. a password emailed from a credit card or bank account), but I wanted to be certain that no one used the phone to check my email. I checked the email logs on one of the email servers I controlled and it showed that no one had used it to access my email. I started feeling a little better. Calls to the phone were going directly to voicemail while the phone was missing, and my guess is that the thief turned the phone off and removed the SIM card, or the battery died. In either case I wanted to be certain there we no calls made from the phone, so we activated our account online with AT&T and checked the call logs, which showed calls to my voicemail (which was normal as my voicemail forwards to YouMail, which is a great service). Now I feel slightly better, and my wife, as always, puts things in perspective and points out that it was not my car or laptop that was stolen, and that no one was hurt (however, the thought of having the opportunity to defend my iPhone appealed to me, if ever so briefly).

I did call the police, who weren't much help and told me that I need to go back to the scene of the crime or come to the station to file a report. Since the damage was done, I did not follow through with a police report. However, had I not been in such disbelief, I would have most likely called the police on the spot.

Lessons Learned

I try to look at all incidents, especially ones that have financial impact, as a learning experience. What could I have done better? Also, what can I do better/different in the future to have a positive impact on the outcome? Below is a list that I hope we can all learn from:


  • Make it easy to change passwords and access your account - Have instructions on how/where you change your email/voicemail passwords so you can do it quickly. Also, have your online account setup and easy to access so you can check your statement and/or de-activate accounts online. This could be as easy as keeping a list of local bookmarks in your browser or in a text file.
  • Report your phone stolen immediately - There were reports online about stolen phones being used to rack up $20,000+ worth of charges. Its hard to overcome the disbelief that your phone has been stolen, however better safe than sorry. It is best to report your phone stolen ASAP.
  • Get insurance - Apple Care protection extends your warranty (Which I had), and is not insurance. Supposedly Apple offers some kind of insurance (according to the AT&T representative), but I am unable to find more information. Also, you may want to follow up with your home insurance provider to see if its covered ($400 may slide under your deductible though).
  • Use a keypad/passcode lock - I did not set the passcode on the iPhone. I know, I know...silly me. However, this passcode is easily bypassed thanks to a vulnerability described here. This has to do with the "Emergency Call" feature in the iPhone, which could be used to not only make a call even though the phone is locked (which is still the case in the latest firmware) but launch applications as well. The only other method available to get around the passcode is to restore the iPhone, which would wipe all the data off of it, but still give an attacker access to your cell service if it has not already been de-activated.
  • Don't store your email passwords on your phone - This is a hard one. On the one hand we tell everyone to use good, if not great, passwords. But, imagine trying to enter a 12 character passwords, mixing upper/lower case, letters, numbers, and symbols on your iPhone? To quote someone from the #pauldotcom IRC chat room, "Ugh.". If you do store passwords on your phone, make sure they are not used anywhere else.
  • Use security software on your phone - This is an interesting dilema, if you hack your iPhone it most likely prevents you from applying security updates from Apple (which fix things such as the passcode bypass). These updates will break all of the modifications made to your iPhone, including the hack to change providers. However, hacking your iPhone allows you to install 3rd party applications, such as iphonelockbox, which lets you encrypt your passwords and other information on your iPhone. Apple is supposed to make available the ability to install 3rd party applications on your iPhone sometime in February 2008, so this may be a wait and see situation.
  • Smart phone, careless user - I can't live without my phone. Aside from providing the ability to send and receive phone calls, I use my phone to store contact information, check my email, send/receive text messages, take pictures, listen to music, watch TV shows/Movies, and browse the web. I should have been more careful, just as with your laptop, never let your phone out of your sight. Always be mindful of where your phone is at all times. For me, I may chain it to my belt from now on!

Conclusion

I hope that you read the above and learned something about how to protect your information. I hope that you use this information to make changes to your security strategy, whether it be protecting your personal information, or your organization's secrets.

PaulDotCom


January 27, 2008

PaulDotCom Security Weekly - Episode 97 - January 24, 2008

Live from the PaulDotCom Security Weekly Studio with a cast of special guests, including:

The authors of SANS SEC610 Reverse-Engineering Malware: Malware Analysis Tools and Techniques including Lenny Zeltser, Mike Murr and Bojan Zdrnja.

Of course, our "reverse engineering specialist", the baby maker from Canada himself, Justin Seitz!

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds: add to my PodNova

PaulDotCom Security Weekly - Special Edition - "Things That Go Bump In The Network: Embedded Device (In)Security"

All:

This is a recorded session from my SANS Webcast called "Things That Go Bump In The Network: Embedded Device (In)Security". Information, the accompanying presentation, and resources can be found below:

Direct Audio Download

Description: Embedded devices come into your network and appear in many different forms, including printers, iPhones, wireless routers and network-based cameras. What you might not realize is that these devices offer unique opportunities for attackers to do damage and gain access to your network - and to the information it contains. This webcast will review known embedded device vulnerabilities and cover how these vulnerabilities can be used to gain control of devices, networks, and data - and, more importantly, what can be done about it.

Presentation: Things That Go Bump In The Network: Embedded Device (In)Security

Resources: I have collected a number of articles and papers that are relevent to embedded device security. You can find them on my del.icio.us links tag AttackingEmbeddedDevices.

Learning More: We do cover many of these same topics, while at the same time learning how embedded devices can be hacked and used for various things, in my SANS course titled SEC535: Network Security Projects Using Hacked Wireless Routers.

Audio Feeds: add to my PodNova

January 24, 2008

Recording and Stream Notice - Episode 97

NOTE: Our Streaming server has changed as of episode 94, and is reflected in the link below.

The live stream should be active about 6:30-7:00 PM EST, Thursday January 24th. We should begin recording the live show at about 7:00 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream can be found at:

http://radio.oshean.org:8000

Please join us, and thanks for listening!

- Larry & Paul

"Drive-By Pharming" - My SANS Keynote & Webcast

All:

There has been a lot of buzz this week about so-called "Drive-By Pharming", which is interesting because you don't need a motorized vehicle of any sort to accomplish this attack. My SANS keynote covers these attacks in great detail, which those that attended my keynote in New Orleans are well aware of. You can find my slides here:

Things That Go Bump In The Network: Embedded Device Security

I will also be giving this presentation today! The SANS webcast, with the same title, can be found here:

Webcast: Things That Go Bump In The Network: Embedded Device Security

So come listen today and learn why "Drive-By Pharming" does not require a car, how to protect yourself and others against these attacks, and how to start hunting for these vulnerabilities in embedded devices.

PaulDotCom

January 22, 2008

PaulDotCom Security Weekly - Episode 96 - January 17, 2008

Live from the PaulDotCom Security Weekly Studio with special guest Matt Jonkman!

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds: add to my PodNova

January 17, 2008

Recording and Stream Notice - Episode 96

NOTE: Our Streaming server has changed as of episode 94, and is reflected in the link below.

The live stream should be active about 7:30-8:00 PM EST, Thursday January 17th. We should begin recording the live show at about 8:00 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream can be found at:

http://radio.oshean.org:8000

Please join us, and thanks for listening!

- Larry & Paul

January 13, 2008

PaulDotCom Security Weekly - Episode 95 - January 11, 2008

Live from the PaulDotCom Security Weekly Studio!

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds: add to my PodNova

January 11, 2008

Recording and Stream Notice - Episode 95

NOTE: Our Streaming server has changed as of episode 94, and is reflected in the link below.

The live stream should be active about 7:30-8:00 PM EST, Friday January 11th. We should begin recording the live show at about 8:00 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream can be found at:

http://radio.oshean.org:8000

Please join us, and thanks for listening!

- Larry & Paul

January 08, 2008

PaulDotCom Security Weekly - Episode 94 - January 4, 2008

Live from the PaulDotCom Security Weekly Studio!

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds: add to my PodNova

January 03, 2008

Recording and Stream Notice - Episode 94

NOTE: Our Streaming server has changed, and is reflected in the link below.

The live stream should be active about 7:30-8:00 PM EST, Friday January 4th. We should begin recording the live show at about 8:00 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream can be found at:

http://radio.oshean.org:8000

Please join us, and thanks for listening!

- Larry & Paul

January 01, 2008

PaulDotCom Security Weekly - Episode 93 - December 28, 2007

Live from the PaulDotCom Security Weekly Studio!

Please note that our download server has changed to http://media.libsyn.com/media/pauldotcom/. Our file format remains the same, however we have chosen to move all downloads to Libsyn for better tracking and atchiving. All previous podcasts will remain on the old server for now.

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds: add to my PodNova

December 22, 2007

Recording and Stream Notice - Episode 93

Larry and I will return after the holiday to bring you another fun filled and informative episode of PaulDotCom Security Weekly. In the mean time have a happy and safe holiday.

The live stream should be active about 7:30-8:00 PM EST, Friday December 28th. We should begin recording the live show at about 8:00 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry & Paul

PaulDotCom Security Weekly - Episode 92 - December 14, 2007 - Part II

Live from the PaulDotCom Security Weekly Studio, this is the second part in a two-part episode. Larry and I created a two-hour podcast marathon this week and have decided to release it in two parts.

Larry and I weigh in on the Mogul/Hoff demonstration of hacking SCADA systems, but its a day late and a dollar short for that one as its come out that it was a "Set up". :)

Happy Holidays!

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

December 18, 2007

Tune Into My SANS Webcast - "Things That Go Bump In The Network: Embedded Device Security"

All:

I am excited to present my keynote presentation via a SANS Webcast. I will be speaking about why embedded devices pose a threat to your organizations, how attackers can use them to gain unauthorized access to your information, and what you can do to defend your networks. I will cover iPhone hacking, attacking web cameras, and of course wireless routers. So, go sign up today!

Who: Me (Paul Asadoorian)
When: January 24, 2007 - 1:00 PM EST (1800 UTC/GMT)
Where: https://www.sans.org/webcasts/show.php?webcastid=91511
Cost: FREE!

Embedded devices come into your network and appear in many different forms, including printers, iPhones, wireless routers and network-based cameras. What you might not realize is that these devices offer unique opportunities for attackers to do damage and gain access to your network - and to the information it contains. This webcast will review known embedded device vulnerabilities and cover how these vulnerabilities can be used to gain control of devices, networks, and data - and, more importantly, what can be done about it.

Register For The Webcast Here

December 17, 2007

Merry Christmas Video From PaulDotCom

I had to go deep into the archives for this one! This video was lost for some time, until I found a copy of it on my Lacie portable USB/Firewire drive :) It was shot in 2005, just shortly after Larry and I started the podcast. I want to release it again here to get everyone in the holiday spirit, this time its uploaded to YouTube so it doesn't get lost :)

Happy Holidays!

The PaulDotCom Crew

December 16, 2007

PaulDotCom Security Weekly - Episode 92 - December 14, 2007 - Part I

Live from the PaulDotCom Security Weekly Studio, this is the first part in a two-part episode. Larry and I created a two-hour podcast marathon this week and have decided to release it in two parts. Part II will be released next week, and we will resume regularly scheduled broadcasting the week after Christmas.

Happy Holidays!

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

December 14, 2007

"The Benefits Of Hacking Embedded Devices" - Paul's InformIT Article

Hot off the press is an article I wrote titled "The Benefits of Hacking Embedded Devices" and was posted today on the informit.com web site. The abstract reads:

"Embedded devices can often perform the same tasks as workstations and servers while consuming less space and power, generating less heat, and being more cost-effective. Paul Asadoorian describes why you'd want to "hack" (install new firmware on) embedded devices, and which hardware and firmware choices are the best, so you can make your $40 router do things typically found in a $600 device!"

Not only do I cover many reasons why embedded devices are so much fun to hack, but I answer the question that we get so many times, "What device should I buy if I want to hack and play with third-party firmware and/or embedded Linux?". So, enjoy and let me know if you have questions or feedback (You can use our new contact page!).

PaulDotCom

Contact Us, New Web Site, and Why I "Dislike" Voicemail

I first wanted to mention that we finally have put up a contact page, so you can Contact Us and tell us that we are doing a good job, just day "Hi!” tell us that we suck (be certain to accompany that with suggestions on how we can get better), or provide suggestions for the show. I've listed out Larry, myself, and the general podcast email separately. We love to hear from our listeners! I promise that I read every email that comes to me directly or the podcast. If we don't respond, its just because we are busy and it can be difficult to respond to each and every email, but we try, I promise!

Just a quick note on the web site, we are planning to get a new web site. This means a complete face-lift, better organization, more content, etc.. If you have suggestions, please send them along.

I also just configured my voicemail on my new iPhone. I am using a service called YouMail (www.youmail.com), which I like very much. However, after some travel, I realized that I hate, okay hate is a strong word, "dislike" voicemail. Many of the reasons are security related, so I thought I would share them here:

1) There is no way to identify the caller - I could call you up and leave voicemail and state that I am your credit card company and you should call me right away at the following number. Since there is no way for you to prove that, some users may panic and call the number that I leave on your voicemail. This happens to me a lot, many people have called me and left voicemail stating that "I have seen malicious traffic coming from your network, please call me at once". Why should I call you back and answer questions about my network?

2) Most Voicemail systems rely on called-id for authentication - This is just wrong. Lets start with caller-id information can be spoofed VERY easily! Why would you rely on such a crude authentication mechanism? This would allow you to access a person's voicemail, which could potentially contain sensitive information (such as some random person calling you up and leaving a message that states, "Hey, your web server at IP address x.x.x.x is compromised and they used a PHP flaw to do it"). Great, thanks. (and yes, that it just an example).

3) It goes in clear-text - With VoIP becoming more and more popular, using voicemail to retrieve any kind of sensitive information is just plain silly. RTP (Real-Time Protocol) can be easily sniffed off the network, and so can DTMF. This means if I am listening, not only do I get to listen to you check your voicemail, but I get your pin number so I can go back and listen later. This is scary given that you may not control what information is left on your voicemail because someone else is exposing the information for you.

4) It is difficult to store voicemail for long periods of time - I like to have a record of all email so I can go back and prove who said what. Such as, "Yes, we were hacked due to a weak password, here is a copy of the email where I suggested a password policy". It’s hard to do this with voicemail, unless you have a system that will email you a WAV or MP3 file (Such as YouMail).

5) You can't respond to voicemail - With an email, I can take it right off my to do list by simply replying to it. With voicemail, I have to try to call the person back, and then leave them a voicemail. But, if they are not around, we play phone tag. Then I have to leave my phone number on their voicemail, so now my information is held in someone else's voicemail box!

6) Its easy to mis-interprate voicemail - I always get voicemail that I cannot understand, and its always the company name, person's name, or phone number that goes missing. At least with email, I can read the phone number and not have to listen for it and play it back 8 times before I get the phone number.

7) Its one more thing to check and receive to do's in - Its bad enough that I have email, instant messenger, and IRC to deal with, but voicemail too. I hope that as time goes on we will move away from voicemail as a communications mechanism. I like systems that will take the voicemail, do the speech-to-text conversion, and email it to me. However, that still does not let me respond to it via email :-(

8) The best protection that you get is a four-digit pin - We've talked about this before, why are we, in today's day and age, limited to a four-digit pin number for authentication!?!? A four-digit pin is easy to guess, brute force, and just plain should not be used.

Now, I'm off to check my voicemail...

PaulDotCom

Recording and Stream Notice - Episode 92

The live stream should be active about 7:30-8:00 PM EST, Friday December 14th. We should begin recording the live show at about 8:00 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry & Paul

December 13, 2007

Recording and Stream Notice - Episode 91

The live stream should be active about 6:30 PM EDT, Friday December 14th. We should begin recording the live show at about 7:00 PM EDT. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry & Paul

Paul & Larry Interviewed By Linux Reality Podcast

All:

We'd like to thank Chess Griffin of the Linux Reality Podcast, especially since he proclaimed us as the "best security podcast", w00t! We did an hour interview and talked security, Linux, how PaulDotCom got started, and of course our book, embedded stuff, the SANS class, and more! Listen here:

Linux Reality - Episode 89 - Interview with Paul Asadoorian and Larry Pesce

Enjoy!

Cheers,

PaulDotCom

December 09, 2007

PaulDotCom Security Weekly - Episode 91 - December 6, 2007

Live from the PaulDotCom Security Weekly Studio...

Special Guest, Joel Esler!

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

December 06, 2007

Recording and Stream Notice - Episode 91 & Special Events

The live stream should be active about 5:30 PM EST, Thursday December 6th. We should begin recording the live show at about 6:00 PM EST. We have a special guest host this week too! Tune in to find out who!

Immediately following the show you will be able to tune in to a live interview of Larry and myself by Chess Griffin from the Linux Reality podcast. So don't miss this weeks live stream!

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry & Paul

December 02, 2007

PaulDotCom Security Weekly - Episode 0x90 - November 29, 2007

Live from the PaulDotCom Security Weekly Studio...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

November 26, 2007

Recording and Stream Notice - Episode 90

The live stream should be active about 6:30 PM EDT, Thursday November 29th. We should begin recording the live show at about 4:30 PM EDT. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry & Paul

PaulDotCom Security Weekly - Episode 89 - November 23, 2007

Live from the PaulDotCom Security Weekly Studio...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

November 21, 2007

Recording and Stream Notice - Episode 89

Note: Updated times!

The live stream should be active about 7:30 - 8:00 PM EDT, Friday November 23rd. We should begin recording the live show at about 8:30 PM EDT. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry & Paul

November 17, 2007

PaulDotCom Security Weekly - Episode 88 - November 15, 2007

Live from the PaulDotCom Security Weekly Studio...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

November 15, 2007

Recording and Stream Notice - Episode 88

The live stream should be active about 6:30 PM EDT, Thursday November 8th. We should begin recording the live show at about 7:00 PM EDT. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry & Paul

November 09, 2007

PaulDotCom Security Weekly - Episode 87 - November 8, 2007

Live from the PaulDotCom Security Weekly Studio...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

November 08, 2007

Recording and Stream Notice - Episode 87

The live stream should be active about 6:30 PM EST, Thursday November 8th. We should begin recording the live show at about 7:00 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can. Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom. When active, the live stream can be found at: http://hydrogen.oshean.org:8000 Please join us, and thanks for listening! - Larry

November 02, 2007

PaulDotCom Security Weekly - Episode 86 - November 1, 2007

Live from the PaulDotCom Security Weekly Studio...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

October 31, 2007

PaulDotCom Security Weekly - Special Edition - Interview with Sensepost - Part II

Recorded on October 18, 2007 in the PaulDotCom Security Weekly studios via Skype:

This first part primarily covers some of the tools offered by Sensepost for free, what they do, and how to use them. Part II will cover the new tool they released called "Squeeza" and a very interesting discussion about penetration testing and web application security.

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

October 30, 2007

Sensepost Interview & Recording Notice

Part II of the Sensepost interview is in the works. I've had some problems, the intial export of the audio gets cut off at the end. I checked the original and its all there, but now I need to re-export the original recording and run it through the entire post-production process. I hope to have that done before the end of the week.

The live stream should be active about 6:30 PM EDT, Thursday November 1st. We should begin recording the live show at about 7:00 PM EDT. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

PaulDotCom

October 21, 2007

PaulDotCom Security Weekly - Special Edition - Interview with Sensepost - Part I

Recorded on October 18, 2007 in the PaulDotCom Security Weekly studios via Skype:

This first part primarily covers some of the tools offered by Sensepost for free, what they do, and how to use them. Part II will cover the new tool they released called "Squeeza" and a very interesting discussion about penetration testing and web application security.

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

October 11, 2007

CANCELLED - Recording and Stream Notice - Episode 86

Our apologies!

Due to unfortunate circumstances beyond our control, we need to cancel this week's stream and podcast. we apologize to our faithful listeners - we promise we'll have a totally rockin' show for you all next week!

In the mean time, come hang out with us in our IRC channel at irc.freenode.net #pauldotcom.

- Larry

October 08, 2007

PaulDotCom Security Weekly - ICE Games Coverage - SANS NS2007

This is a really fun time! Larry, Dave "Cool", and myself hosted a live hacking event. There were real networks to defend and real exploits coming at them. It was great fun! I took about 4+ hours of audio and condensed it into 36 minutes, so its just the highlights. What will you take away from this? The blue and red team experiences carry through into our real working worlds and it is interesting to hear the mock press interviews, red team updates, and most importantly the end briefings.

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

PaulDotCom Security Weekly - Episode 85 - October 4, 2007

Live from the PaulDotCom Security Weekly Studio...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

October 04, 2007

Recording and Stream Notice - Episode 85

The live stream should be active about 6:30 PM EST, Thursday October 4th. We should begin recording the live show at about 7:00 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry

September 30, 2007

PaulDotCom Security Weekly - Episode 84 - September 27, 2007

Live from SANS Las Vegas Network Security 2007!

I'd like to thank SANS for having us back, Dave Cool, Rich Mogull for helping out, props to Mike Poor (C.E.O Chief Entertainment Officer), and Eliot from Hack A Day for hanging out and providing t-shirts. Also, our sponsors gave us TONS of free stuff to give away, such as iPod Nanos, Amex and Starbucks Gift cards, t-shirts, and a really cool light saber.

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

September 29, 2007

Recording and Stream Notice - ICE Games! Part 2- Live from Vegas

The Live stream is active NOW! 9 AM to Noon PST, September 29th 2007 Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! we're not sure exactly how this will work during the live show, but let's experiment. Find us on IRC at irc.freenode.net #pauldotcom. When active, the live stream can be found at: http://hydrogen.oshean.org:8000 Please join us, and thanks for listening! - Larry

September 28, 2007

Recording and Stream Notice - ICE Games! - Live from Vegas

The Live stream is active NOW! 5 PM to Midnight PST, September 28, 2007 Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! we're not sure exactly how this will work during the live show, but let's experiment. Find us on IRC at irc.freenode.net #pauldotcom. When active, the live stream can be found at: http://hydrogen.oshean.org:8000 Please join us, and thanks for listening! - Larry

September 26, 2007

Recording and Stream Notice - Episode 84 - Live from Vegas!

The live stream should be active about 8:30 PM EST (5:30 PST), Thursday September 27th. We should begin recording the live show at about 5:45 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can. Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! we're not sure exactly how this will work during the live show, but let's experiment. Find us on IRC at irc.freenode.net #pauldotcom. We're also trying to stream some additional content later this week, and we'll be sure to let you know! When active, the live stream can be found at: http://hydrogen.oshean.org:8000 Please join us, and thanks for listening! - Larry

September 17, 2007

PaulDotCom Security Weekly - Episode 83 - September 13, 2007

Live from the PaulDotCom Security Weekly Studios...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

September 11, 2007

Recording and Stream Notice - Episode 83

The live stream should be active about 6:30 PM EST, Thursday September 13th. We should begin recording the live show at about 7:00 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can. Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom. When active, the live stream can be found at: http://hydrogen.oshean.org:8000 Please join us, and thanks for listening! - Larry

September 10, 2007

PaulDotCom Security Weekly - Episode 82 - September 6, 2007

Live from the PaulDotCom Security Weekly Studios...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

September 05, 2007

Recording and Stream Notice - Episode 82

The the live stream should be active about 6:30 PM EST, Thursday September 6th. We should begin recording the live show at about 7:00 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry

September 04, 2007

PaulDotCom Security Weekly - Episode 81 - August 31, 2007

Live from the PaulDotCom Security Weekly Studios...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

August 28, 2007

Recording and Stream Notice - Episode 81

The the live stream should be active about 6:30 PM EST, Friday August 31st. We should begin recording the live show at about 7:00 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry

August 27, 2007

PaulDotCom Security Weekly - Interview with Intelguardians - Escaping The Virtual Cave - August 23, 2007

I did my best to improve the audio quality on this one, and spent way too much time doing it (so no complaining! :)

I wanted to thank Ed, Tom, and Matt from Intelguardians, it was a fun episode with tons of useful information!

  • Want to register for any SANS conference? Please visit http://www.pauldotcom.com/sans/ for our referral program.
  • Sponsored by Core Security, listen for the new customer discount code at the end of the show
  • Sponsored by Tenable Network Security, creators of Nessus and makers of the Tenable Security Center, software that extends the power of Nessus through sophisticated reporting, remediation workflow, IDS event correlation and much more.
  • Want some cool PaulDotCom Gear? Do you hack naked? Check out our Cafepress Store!
  • Full Show Notes

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

August 21, 2007

PaulDotCom Security Weekly - Episode 80 - August 16, 2007

The audio quality on this one may be a bit off, Skype and Gizmo gave us problems during the interview. However, there is some great content, thanks in large part to Tim and Dwight from White Wolf Security!

  • Want to register for any SANS conference? Please visit http://www.pauldotcom.com/sans/ for our referral program.
  • Sponsored by Core Security, listen for the new customer discount code at the end of the show
  • Sponsored by Tenable Network Security, creators of Nessus and makers of the Tenable Security Center, software that extends the power of Nessus through sophisticated reporting, remediation workflow, IDS event correlation and much more.
  • Want some cool PaulDotCom Gear? Do you hack naked? Check out our Cafepress Store!
  • Full Show Notes

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

August 12, 2007

Upcoming PaulDotCom Interviews

All:

We would like to announce that the next two weeks we will be conducting two interviews with some very special guests:

August 16, 2007, 7:00PM EST (Streaming Link) - Interview with Tim Rosenberg and Dwight Hobbs from www.whitewolfsecurity.com, who will be providing the tecnical "arena" for the upcoming ICE games

August 23, 2007, 7:00PM EST (Streaming Link) - Interview with Ed Skoudis, Tom Liston, and Mathew Carpenter from Intelguardians to talk about VM Escaping and the research that they have been doing on this topic.

The above two recordings will serve as the podcasts for those weeks. Moving into September, we will be discussing the happenings at Black Hat and Defcon hopefully in some more detail, discussing current events, and providing you with even more fantastic technical segments (we have a great one we are working on called "Just Plane Fun")!

PaulDotCom

August 07, 2007

PaulDotCom Security Weekly - Episode 79 - August 3, 2007

"Not Your Typical Episode"

I apologize we were light on the show notes, a bit light on the content, and there were no technical segments. We will return in the coming weeks to bring you feature packed episodes, and some awesome interviews!

  • Want to register for any SANS conference? Please visit http://www.pauldotcom.com/sans/ for our referral program.
  • Sponsored by Core Security, listen for the new customer discount code at the end of the show
  • Sponsored by Tenable Network Security, creators of Nessus and makers of the Tenable Security Center, software that extends the power of Nessus through sophisticated reporting, remediation workflow, IDS event correlation and much more.
  • Want some cool PaulDotCom Gear? Do you hack naked? Check out our Cafepress Store!
  • Full Show Notes

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Joe "Mr. C" Conlin, Tyler, and Martin Mckeay

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

July 31, 2007

Escaping From The Virtualization Cave

On Friday, July 27, 2007 a very tired member of the PaulDotCom crew sat in a standing room only room ar SANSFIRE 2007 to hear about the latest research in VMWare escaping (or really any other virtualization technology). VMWare escaping you say? What's that? Ed Skoudis, SANS Instructor and co-founder of Intelguardians, true to form gave the perfect ananlogy (and it didn't have anything to do with the Matrix!). Think of virtualization as a cave, and you are trapped inside (just like the "guest" OS). Outside the cave there is a giagantic monster. Everytime you try to escape from the cave, you get squashed, pushed back in, or even have your legs cut off and re-attached facing the opposite way. No matter what you do, you can't escape the cave, unless of course your name is Tom Liston...

Tom and Ed went on to describe all of their attempts to escape from the cave. Spawned from this were many attempts and tools that start with "VM", including VMChat, VMftp, VMcat, and my favorite VM-Drag-N-Sploit. All of these tools allow for some communications between the guest and the host, or between two guests running on the host (Fool Moon Blog has a good write-up on all the tools, located here). While these tools are interesting, they are not a "true" escape, as they only allow file transfer and/or require end-user interaction.

But with Ed calling Tom everyday for a year and asking, "Do you have a VM escape yet?", Tom was motivated to break out from the cave. The first, and most obvious method, was to exploit a known vulnerability in the form of a directory traversal. While this close to a full escape, it is still a directory traversal at its core. This directory traversal was disclosed by iDefense, reportedly from an anonymous source. You can find a full write-up here (CVE-2007-1744). Apparently, Ed and Tom and his team aren't the only ones interested in VM escaping. This also became apparent when another Intelguardians member, Jay Beale (he's a genius right?), saw a presentation at the most recent CANSECWEST on VM escaping using QEMU. It was interesting to see how many of the vulnerabilities in that research were applied to all of the other VM products, many of which centered around the ne2000 network driver and video card emulation. You can find the research in this area from a Google employee named Tavis Ormandy here, titled, "An Empirical Study into the Security Exposure to Hosts of Hostile Virtualized Environments" They stressed that these emulation drivers were important, and especially the video one...

So, enough already, get to the escaping! Ed and Tom had to get special permission to give the talk and release the details, which is why the next section was light on details, and answers were vague. Tom demonstrated a program running on the guest, which took a minute or so to run, then crashed the guest and ran a program on the host. W00t! VM escape by blowing up the cave. I asked Tom if that works with a fully patched version of VMware and got an answer of "portions of it", and couldn't get any more information, and for good reasons I'm sure.

The bottom line is that you cannot trust virtualization products to provide security. You should keep up-to-date on all the patches and design your security architecture such that you do not espose sensative data in the case of a guest breaking out of the cave.

What is interesting is that just after this presentation, more vulnerabilities for VMware were released!

http://www.milw0rm.com/exploits/4245
http://www.milw0rm.com/exploits/4244
http://www.milw0rm.com/exploits/4240

While these may not lead to escaping (exploit was non-specific on this topic), they are interesting none the less.

Cheers,

Paul "PaulDotCom" Asadoorian

Resources:

http://handlers.sans.org/tliston/ThwartingVMDetection_Liston_Skoudis.pdf - Tom and Ed's presentation from 2006, before they could release many of the details.

http://www.cutawaysecurity.com/blog/archives/170 - Cutaway's blog posting on the subject.

July 28, 2007

PaulDotCom Security Weekly - Episode 78 - July 27, 2007

Recorded at SANSFIRE in the noisy vendor expo, where there was "Banging"....

  • Want to register for any SANS conference? Please visit http://www.pauldotcom.com/sans/ for our referral program.
  • Sponsored by Core Security, listen for the new customer discount code at the end of the show
  • Sponsored by Tenable Network Security, creators of Nessus and makers of the Tenable Security Center, software that extends the power of Nessus through sophisticated reporting, remediation workflow, IDS event correlation and much more.
  • Want some cool PaulDotCom Gear? Do you hack naked? Check out our Cafepress Store!
  • Full Show Notes

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Luiz Eduardo, "Anthony From Core"

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

July 23, 2007

PaulDotCom Security Weekly - Episode 77 - July 20, 2007

Live from the PaulDotCom Security Weekly Studio....

  • Want to register for any SANS conference? Please visit http://www.pauldotcom.com/sans/ for our referral program.
  • Sponsored by Core Security, listen for the new customer discount code at the end of the show
  • Sponsored by Tenable Network Security, creators of Nessus and makers of the Tenable Security Center, software that extends the power of Nessus through sophisticated reporting, remediation workflow, IDS event correlation and much more.
  • Want some cool PaulDotCom Gear? Do you hack naked? Check out our Cafepress Store!
  • Full Show Notes

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Andy Lockhart

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

July 16, 2007

PaulDotCom Security Weekly - Episode 76 - July 13, 2007

Live from the PaulDotCom Security Weekly Studio....

  • Want to register for any SANS conference? Please visit http://www.pauldotcom.com/sans/ for our referral program.
  • Sponsored by Core Security, listen for the new customer discount code at the end of the show
  • Sponsored by Tenable Network Security, creators of Nessus and makers of the Tenable Security Center, software that extends the power of Nessus through sophisticated reporting, remediation workflow, IDS event correlation and much more.
  • Want some cool PaulDotCom Gear? Do you hack naked? Check out our Cafepress Store!
  • Full Show Notes

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Andy Lockhart

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

July 09, 2007

PaulDotCom Security Weekly - Episode 75 - July 5, 2007

Live from the PaulDotCom Security Weekly Studio....

  • Want to register for any SANS conference? Please visit http://www.pauldotcom.com/sans/ for our referral program.
  • Sponsored by Core Security, listen for the new customer discount code at the end of the show
  • Sponsored by Tenable Network Security, creators of Nessus and makers of the Tenable Security Center, software that extends the power of Nessus through sophisticated reporting, remediation workflow, IDS event correlation and much more.
  • Want some cool PaulDotCom Gear? Do you hack naked? Check out our Cafepress Store!
  • Full Show Notes

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Andy Lockhart

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

July 02, 2007

PaulDotCom Security Weekly - Episode 74 - June 28, 2007

Live from the PaulDotCom Security Weekly Studio....

  • Want to register for any SANS conference? Please visit http://www.pauldotcom.com/sans/ for our referral program.
  • Sponsored by Core Security, listen for the new customer discount code at the end of the show
  • Sponsored by Tenable Network Security, creators of Nessus and makers of the Tenable Security Center, software that extends the power of Nessus through sophisticated reporting, remediation workflow, IDS event correlation and much more.
  • Want some cool PaulDotCom Gear? Do you hack naked? Check out our Cafepress Store!
  • Full Show Notes

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Andy Lockhart

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

June 24, 2007

PaulDotCom Security Weekly - Episode 73 - June 21, 2007

Live from the PaulDotCom Security Weekly Studio....
  • Want to register for any SANS conference? Please visit http://www.pauldotcom.com/sans/ for our referral program.
  • Sponsored by Core Security, listen for the new customer discount code at the end of the show
  • Sponsored by Tenable Network Security, creators of Nessus and makers of the Tenable Security Center, software that extends the power of Nessus through sophisticated reporting, remediation workflow, IDS event correlation and much more.
  • Want some cool PaulDotCom Gear? Do you hack naked? Check out our Cafepress Store!
  • Full Show Notes
Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Andy Lockhart
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

June 17, 2007

PaulDotCom Security Weekly - Episode 72 - June 14, 2007

Live from the PaulDotCom Security Weekly Studio....
  • Want to register for any SANS conference? Please visit http://www.pauldotcom.com/sans/ for our referral program.
  • Sponsored by Core Security, listen for the new customer discount code at the end of the show
  • Sponsored by Tenable Network Security, creators of Nessus and makers of the Tenable Security Center, software that extends the power of Nessus through sophisticated reporting, remediation workflow, IDS event correlation and much more.
  • Want some cool PaulDotCom Gear? Do you hack naked? Check out our Cafepress Store!
  • Full Show Notes
Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Andy Lockhart
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

June 11, 2007

PaulDotCom Security Weekly - Episode 71 - June 7, 2007

Live from the PaulDotCom Security Weekly Studio....

  • Want to register for any SANS conference? Please visit http://www.pauldotcom.com/sans/ for our referral program.
  • Sponsored by Core Security, listen for the new customer discount code at the end of the show
  • Sponsored by Tenable Network Security, creators of Nessus and makers of the Tenable Security Center, software that extends the power of Nessus through sophisticated reporting, remediation workflow, IDS event correlation and much more.
  • Want some cool PaulDotCom Gear? D o you hack naked? Check out our Cafepress Store!
  • Full Show Notes

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Andy Lockhart

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

June 04, 2007

PaulDotCom Security Weekly - Episode 70 - May 31, 2007

Live from the PaulDotCom Security Weekly Studio....

  • Want to register for any SANS conference? Please visit http://www.pauldotcom.com/sans/ for our referral program.
  • Sponsored by Core Security, listen for the new customer discount code at the end of the show
  • Sponsored by Tenable Network Security, creators of Nessus and makers of the Tenable Security Center, software that extends the power of Nessus through sophisticated reporting, remediation workflow, IDS event correlation and much more.
  • Want some cool PaulDotCom Gear? D o you hack naked? Check out our Cafepress Store!
  • Full Show Notes

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Andy Lockhart

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

May 29, 2007

Ultimate WRT54G Hacking: The Sample Chapter

All:

After almost a year from when we had the first spark of an idea to do something with a WRT54G and hacking, we are very proud to announce the release of the sample chapter and table of contents:

Table Of Contents

Chapter 3: Using Third-Party Firmware

The complete book will be available for purchase after June 15th. We are in the process of scheduling and booking appearances on various podcasts and interviews, so if you would like to have us on your show, just drop us a line and we will put you on the book reviewer list.

The official WRT54G Hacking book web site will feature errata, new projects, pictures, and updates to any/all of the projects in the book. It is still under development and will be released with the book in June. The link will be:

http://wrt54ghacks.com

Look for some updates in the coming weeks.

Cheers,

Paul & Larry

May 23, 2007

Yes, another week off...

We are terribly sorry.

Due to life affecting circumstances beyond the control of 3 members of the podcast this week, we will not be recording Episode 70 as originally planned. We apologize for the inconvenience.

Please, tune in next week for the quality show that you have come to expect! - Larry

May 20, 2007

PaulDotCom Security Weekly - Episode 69 - May 10, 2007

Live from the PaulDotCom Security Weekly Studio....

  • Want to register for any SANS conference? Please visit http://www.pauldotcom.com/sans/ for our referral program.
  • Sponsored by Core Security, listen for the new customer discount code at the end of the show
  • Sponsored by Tenable Network Security, creators of Nessus and makers of the Tenable Security Center, software that extends the power of Nessus through sophisticated reporting, remediation workflow, IDS event correlation and much more.
  • Want some cool PaulDotCom Gear? D o you hack naked? Check out our Cafepress Store!
  • Full Show Notes

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Andy Lockhart

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

May 14, 2007

PaulDotCom Security Weekly - Special Edition - Interview with "Futo" & Ivan Arce

Live from the Core Security Technology Offices.... (aka, film location for the movie "The Departed")

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

May 03, 2007

Vacation? Hardly.

It has been a week of new beginnings, and the wrapping up of others for the PaulDotCom Security Weekly Family. Needless to say, we are swamped.

So, we're taking the week off this week. We want to continue to deliver high quality content to you, our listeners, and we didn't think that it was fair to you all to have a show that was not up to par.

We do have a few exciting weeks coming with some special stuff. We'll make it up to you, we promise!

In the mean time, please stop by the #pauldotcom IRC channel at irc.freenode.net and have a chat with a bunch of our other friendly listeners. We don't bite!

Stay tuned, and thanks for listening!

April 28, 2007

PaulDotCom Security Weekly - Special Edition - Interview with "Renderman"

Live from the PaulDotCom Security Weekly Studio....


Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

April 23, 2007

Episode 68 Feed Problem

Whoops! During the post-production process which occured late last night I included the wrong filename in the rss feed (so the entry for episode 68 had an enclosure tag that pointed to episode 67's mp3 file).

iTunes is pretty braindead, so you may have to remove the feed and re-add it.

Sorry for the confusion, if you have any questions just drop us a line at psw /at/ pauldotcom.com

Cheers,

PaulDotCom

April 22, 2007

PaulDotCom Security Weekly - Episode 68 - April 19, 2007

Live from the PaulDotCom Security Weekly Studio....

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Andy Lockhart

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

April 19, 2007

Recording and Stream Notice - Episode 68

The the live stream should be active about 7:00 PM EST, Thursday April 19th. We should begin recording the live show at about 7:30 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry

April 15, 2007

PaulDotCom Security Weekly - Episode 67 - April 12, 2007

Live from the PaulDotCom Security Weekly Studio....



  • Want to register for any SANS conference? Please visit http://www.pauldotcom.com/sans/ for our referral program.

  • Sponsored by Core Security, listen for the new customer discount code at the end of the show

  • Sponsored by Syngress, be the first to post the answer to the question at the end of the show and win a free book!

  • Want some cool PaulDotCom Gear? Do you hack naked? Check out our Cafepress Store!

  • Full Show Notes

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

April 12, 2007

Recording and Stream Notice - Episode 67

The the live stream should be active about 7:00 PM EST, Thursday April 12th. We should begin recording the live show at about 7:30 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry

April 08, 2007

PaulDotCom Security Weekly - Episode 66 - April 5, 2007

Live from SANS San Diego 2007....


Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin
, Special Guest Kevin Amorin

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

April 01, 2007

PaulDotCom Live From SANS San Diego 2007 - Streaming Notice

We tried this from Shmoocon 2007 with an EVDO connection and learned a great deal :) Now we have a good Internet connection and plan to stream the live show from SANS to the Internet in near real-time.

Come hear us entertain the SANS students, talk to audience members, and present some of the cool WRT54G projects from our book.

The the live stream should be active about 5:30 PM PST, Wednesday April 4, 2007.



When active, the live stream can be found at:


http://hydrogen.oshean.org:8000


We have found that VLC is the best program to use when listening to the stream (ogg). It runs on Linux, Windows, and OS X. Please join us, and thanks for listening! Tell all your friends!


The PaulDotCom Security Weekly Crew

March 31, 2007

PaulDotCom Security Weekly - Episode 65 - March 29, 2007

Live from the PaulDotCom Security Weekly Studio....

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

PaulDotCom Security Weekly - Special Edition - Interview with Seth Fogie

Live from the PaulDotCom Security Weekly Studio....


Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

March 29, 2007

Recording and Stream Notice - Episode 65 and Seth Fogie Interview

The the live stream should be active about 7:00 PM EST, Thursday March 29th. We should begin recording the live show at about 7:30 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

We'll also be interviewing Seth Fogie at 9:30 PM EST, who recently made swiss cheese out of Windows Mobile at Shmoocon.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry

March 27, 2007

PaulDotCom Security Weekly - Episode 64 - March 24, 2007

Live from Shmoocon!

WARNING: This show was recorded in front of a live audience. There are audio anomalies and stronger then usual language.

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

March 17, 2007

PaulDotCom Security Weekly - Episode 63 - March 15, 2007

Live from the PaulDotCom Security Weekly Studio....

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

March 15, 2007

Recording and Stream Notice - Episode 63

The the live stream should be active about 7:00 PM EST, Thursday March 15th. We should begin recording the live show at about 7:30 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry

March 11, 2007

PaulDotCom Security Weekly - Episode 62 - March 8, 2007

Live from the PaulDotCom Security Weekly Studio....

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

March 08, 2007

Recording and Stream Notice - Episode 62

The the live stream should be active about 7:00 PM EST, Thursday January 25th. We should begin recording the live show at about 7:30 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry

March 07, 2007

WRT54G Presentation for SNENUG

As we have suggested on the podcast previously, it is a good idea to get involved with your local computer/security user groups. We have a few in the local Rhode Island area, one of them being SNENUG (Southern New England Network Users Group). I will be presenting the following:

Title: "Embedded Device Hacking With The Linksys WRT54G"

Where: Katherine Gibbs School, Cranston, RI

When: March 21, 2006 7:00PM-9:00PM

This is the first time that content from our book, Ultimate WRT54G Hacking, will be released to the general public in a formal fashion. I will cover some of the details on the WRT54G platform, firmware installation, and a few select projects. Of course, I will have demonstrations as well. For those who may not yet have a Hack Naked T-Shirt, I will bring some of those as well, along with Hack Naked Stickers.

If you are in the area, swing by, I even think there will be free food!

PaulDotCom

March 03, 2007

PaulDotCom Security Weekly - Episode 61 - March 1, 2007

Live from the PaulDotCom Security Weekly Studio....

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

February 23, 2007

PaulDotCom Security Weekly - Listener Feedback - Episode 5 Part 2

Live from the PaulDotCom Security Weekly Studio....

Paul, Larry, and Twitchy take on listener questions and feedback. We had so much awesome feedback that we wanted to cover, we're splitting this one into two parts. As promised, here is part two. Be certain to send us your questions!

Skype: pauldotcom Phone: 401.369.9820

Listener Feedback Episode 5 Show Notes

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" DePetrillo
Email: psw@pauldotcom.com

Direct Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

SANS Article About PaulDotCom Security Weekly

SANS has published an article about PaulDotcom that covers how we got started and where we are going in the future. You can read it here:

Introducing: Podcasts from PaulDotCom Security Weekly

Don't forget to sign up for SANS training at http://pauldotcom.com/sans/ (Yes, that was an obvious plug, but hey, you scratch our back...).

PaulDotCom

February 17, 2007

PaulDotCom Security Weekly - Listener Feedback - Episode 5 Part 1

Live from the PaulDotCom Security Weekly Studio....

Paul, Larry, and Twitchy take on listener questions and feedback. We had so much awesome feedback that we wanted to cover, we're splitting this one into two parts. Be certain to send us your questions!

Skype: pauldotcom Phone: 401.369.9820

Listener Feedback Episode 5 Show Notes

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" DePetrillo
Email: psw@pauldotcom.com

Direct Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

February 15, 2007

Recording and Stream Notice - Listener Feedback double header!

The the live stream should be active about 5:00 PM EST, Thursday February 8th. We should begin recording the live show at about 5:30 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry

February 09, 2007

PaulDotCom Security Weekly - Episode 60 - February 8, 2007

Live from the PaulDotCom Security Weekly Studio....

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

February 08, 2007

Recording and Stream Notice - Episode 60

The the live stream should be active about 6:45 PM EST, Thursday February 8th. We should begin recording the live show at about 7:00 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry

February 04, 2007

PaulDotCom - Special Edition - Interview with Ron Gula

On this episode, we had the pleasure of interviewing Ron Gula, Founder and CEO of Tenable Security and creator of Dragon IDS. We talked with Ron about:
  • How Ron got started in the security space
  • Dragon IDS
  • Nessus and Nmap
  • Tenable Security's products
  • Getting started in security
  • ...and much more!
Full Show Notes Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Joe "Mr. C" Conlin
Email: psw@pauldotcom.com

Direct Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

February 01, 2007

Recording and Stream Notice - Interview with Ron Gula

The the live stream should be active about 5:45-ish PM EST, Thursday February 1st. We should begin recording the live show at about 6:00 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

We are doing something a bit different this week. We are interviewing Ron Gula from Tenable instead of our regular format.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry

January 28, 2007

PaulDotCom Security Weekly - Episode 59 - January 25, 2007

Live from the PaulDotCom Security Weekly Studio....

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

January 25, 2007

Recording and Stream Notice - Episode 59

The the live stream should be active about 6:30 PM EST, Thursday January 25th. We should begin recording the live show at about 6:45 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry

January 21, 2007

PaulDotCom Security Weekly - Episode 58 - January 18, 2007

Live from the PaulDotCom Security Weekly Studio....

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

January 13, 2007

PaulDotCom Security Weekly - Episode 57 - January 11, 2007

Live from the PaulDotCom Security Weekly Studio....

  • Want to register for any SANS conference? Please visit http://www.pauldotcom.com/sans/ for our referral program.
  • Sponsored by Core Security, listen for the discount code at the end of the show
  • Sponsored by Syngress, be the first to post the answer to the question at the end of the show and win a free book!
  • Sponsored by Astaro, Astaro Security Gateway line of network security appliances. Listen to the show for a special offer!
  • Please go update our frapper map!
  • Want some cool PaulDotCom Gear? Do you hack naked? Check out our Cafepress Store!
  • Full Show Notes
Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

PaulDotCom Security Weekly TV - RFID Implant

In this episode of PaulDotCom Security Weekly TV, we show the implantation of Larry's RFID chip.

This video may be disturbing to some viewers, due to the implantation procedure. Please, don;t try this at home (even though we did). We are trained professionals!

Direct Video Download At this time there are no Show Notes for this episode

Video Feeds: Enjoy! - Larry

January 11, 2007

Recording and Stream Notice - Episode 57

The the live stream should be active about 7:00 PM EST, Thursday January 11th. We should begin recording the live show at about 7:15 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry

January 07, 2007

PaulDotCom Security Weekly - Episode 56 - January 4, 2007

Live from the PaulDotCom Security Weekly Studio....

  • Want to register for any SANS conference? Please visit http://www.pauldotcom.com/sans/ for our referral program.
  • Sponsored by Core Security, listen for the discount code at the end of the show
  • Sponsored by Syngress, be the first to post the answer to the question at the end of the show and win a free book!
  • Sponsored by Astaro, Astaro Security Gateway line of network security appliances. Listen to the show for a special offer!
  • Please go update our frapper map!
  • Want some cool PaulDotCom Gear? Do you hack naked? Check out our Cafepress Store!
  • Full Show Notes
Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

January 02, 2007

Recording and Stream Notice - Episode 56

The the live stream should be active about 6:00 PM EST, Thursday January 4th. We should begin recording the live show at about 6:15 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry

December 23, 2006

PaulDotCom Security Weekly - Episode 55 - December 21, 2006

Live from the PaulDotCom Security Weekly Studio....

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

December 21, 2006

Recording and Stream Notice

The the live stream should be active about 7:00 PM EST, today, Thursday December 21st. We should begin recording the live show at about 7:15 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

We will attempt to start the stream earlier while we prepare with some music, or something equally as entertaining.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry

December 16, 2006

PaulDotCom Security Weekly - Listener Feedback - Episode 4

Live from the PaulDotCom Security Weekly Studio....

Paul, Larry, Joe, and Twitchy and our special guest Mr_T take on listener questions and feedback. Be certain to send us your questions!

Skype: pauldotcom Phone: 401.369.9820

Listener Feedback Episode 4 Show Notes

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" DePetrillo, Joe "Mr C" Conlin
Email: psw@pauldotcom.com

Direct Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

December 08, 2006

PaulDotCom Security Weekly - Episode 54 - December 7, 2006

Live from the PaulDotCom Security Weekly Studio....

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

December 07, 2006

Recording and Stream Notice

The the live stream should be active about 6:00 PM EST, today, Thursday December 7th. We should begin recording the live show at about 6:15 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Last week we were also to tired to do the Listener Feedback episode as well, and we are going to see how we feel. I suspect that it may be next week.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry

December 01, 2006

PaulDotCom Security Weekly - Episode 53 - November 30, 2006

Live from the PaulDotCom Security Weekly Studio....

Update: Oops, my bad. First time with the new blogging client which has comments set to off by default. They should be on, and we will accept the Syngress answers from the other blog entries, just this once. Also, I made an error with the RSS feed for about 3 minutes last night, and episode 52 was linked to the entry instead of episode 53. - Larry

  • Sponsored by The SANS Institute, get schooled at Bootcamp 2007 in Orlando, FL January 13-19! Now drop and give me 20 exploits!
  • Sponsored by Core Security, listen for the discount code at the end of the show
  • Sponsored by Syngress, be the first to post the answer to the question at the end of the show and win a free book!
  • Sponsored by Astaro, Astaro Security Gateway line of network security appliances. Listen to the show for a special offer!
  • Please go update our frapper map!
  • Want some cool PaulDotCom Gear? Do you hack naked? Check out our Cafepress Store!
  • Full Show Notes
Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

November 30, 2006

Recording and Stream notice

The the live stream should be active about 7:00 PM EST, today, Thursday November 30th. We should begin recording the live show at about 7:15 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Please note that today we may also be attempting to record an Listener Feedback episode in addition to the regular episode

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry

November 25, 2006

PaulDotCom Security Weekly - Episode 52 - November 25th, 2006

Live from the Brand New PaulDotCom Security Weekly Studio.
  • Sponsored by The SANS Institute, get schooled at Bootcamp 2007 in Orlando, FL January 13-19! Now drop and give me 20 exploits!
  • Sponsored by Core Security, listen for the discount code at the end of the show
  • Sponsored by Syngress, be the first to post the answer to the question at the end of the show and win a free book!
  • Sponsored by Astaro, Astaro Security Gateway line of network security appliances. Listen to the show for a special offer!
  • Please go update our frapper map!
  • Want some cool PaulDotCom Gear? Do you hack naked? Check out our Cafepress Store!
  • Full Show Notes
Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

November 19, 2006

PaulDotCom Security Weekly - Episode 51 Part II - Nov 9, 2006


Live from the Brand New PaulDotCom Security Weekly Studio where we were celebrating the one year anniversary of our show! Happy Birthday PaulDotCom Security Weekly!

In the studio to help us celebrate is Andrew Lockhart, creator of Snort Wireless, and author of Network Security Hacks.

Spinning for us live in the studio for this episode is DJ Jackalope! If you like the sounds, make sure you go buy stuff from her Cafepress store! She is also the proud owner of the only autographed pair of twitchy thongs :)

  • Sponsored by The SANS Institute, get schooled at Bootcamp 2007 in Orlando, FL January 13-19! Now drop and give me 20 exploits!
  • Sponsored by Core Security, listen for the discount code at the end of the show
  • Sponsored by Syngress, be the first to post the answer to the question at the end of the show and win a free book!
  • Sponsored by Astaro, Astaro Security Gateway line of network security appliances. Listen to the show for a special offer!
  • Please go update our frapper map!
  • Want some cool PaulDotCom Gear? Do you hack naked? Check out our Cafepress Store!
  • Full Show Notes

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

November 13, 2006

PaulDotCom Security Weekly - Episode 51 Part I - Nov 9, 2006

Live from the Brand New PaulDotCom Security Weekly Studio where we were celebrating the one year anniversary of our show! Happy Birthday PaulDotCom Security Weekly!

In the studio to help us celebrate is Andrew Lockhart, creator of Snort Wireless, and author of Network Security Hacks.

Spinning for us live in the studio for this episode is DJ Jackalope! If you like the sounds, make sure you go buy stuff from her Cafepress store! She is also the proud owner of the only autographed pair of twitchy thongs :)

  • Sponsored by The SANS Institute, get schooled at Bootcamp 2007 in Orlando, FL January 13-19! Now drop and give me 20 exploits!
  • Sponsored by Core Security, listen for the discount code at the end of the show
  • Sponsored by Syngress, be the first to post the answer to the question at the end of the show and win a free book!
  • Sponsored by Astaro, Astaro Security Gateway line of network security appliances. Listen to the show for a special offer!
  • Please go update our frapper map!
  • Want some cool PaulDotCom Gear? Do you hack naked? Check out our Cafepress Store!
  • Full Show Notes

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

November 09, 2006

1 Year Anniversary Blowout - Recording and Stream

The the live stream should be active about 7:00 PM EST, today, Thursday November 9th. We should begin recording the live show at about 8:00 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

You may be asking what is so special about today, and why is the stream up so early before they record? Here's why:

We have made this our 1 year anniversary show. It was close enough and we had something special. In the studio will be:

Andrew Lockhart of many fames, including Snort-wireless
DJ Jackalope, spinning live for your listening pleasure!

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us for our "special day" and thanks for listening!

- Larry

November 05, 2006

PaulDotCom Security Weekly - Episode 50 - Nov 2, 2006

Live from the Brand New PaulDotCom Security Weekly Studio....

  • Sponsored by Core Security, listen for the discount code at the end of the show
  • Sponsored by Syngress, be the first to post the answer to the question at the end of the show and win a free book!
  • Sponsored by Astaro, Astaro Security Gateway line of network security appliances. Listen to the show for a special offer!
  • Please go update our frapper map!
  • Want some cool PaulDotCom Gear? Do you hack naked? Check out our Cafepress Store!
  • Full Show Notes

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

November 02, 2006

Unknown Stream status for this week.

We are still sorting out internet connectivity issues at the new studio location, so it may not be possible to have the live stream this week. We'll make every reasonable effort, but we're not sure if it will be an option this week.

If we are able to get the stream active it would be up around 7:30 EST, November 2nd. We're not making any promises other than, "we'll try".

If active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Thanks for your understanding while we make the transition to our new studios.

- Larry

October 27, 2006

PaulDotCom Moving...

Those of you out there who have ever moved know that it isn't always the most fun experience, but one of those things you just gotta do in life. Some may also know that it doesn't always go so well :) We are experiencing "technical difficulties" with our moving process to say the least.

So, how does this relate to computer security? It doesn't really, but I feel better "blogging" about it :) Also, the podcast, TV show, and consulting business won't be operational until sometime late next week as myself and the rest of the crew tackle life, wiring/networking, and racking servers. This only affects our labs and podcast studio, all web pages, audio, and video content will be available.

We are looking forward to getting back to business in our new location, both my family, the entire podcast team, and those that help out with the consulting business. We have so much good stuff still to come, such as our one-year podcast anniversary special, special articles, two more TV show episodes in the works, a new web site hosting company complete with many new web site upgrades, and more!

Speaking of which, if you are a web developer and have experience with CSS and Movable type please drop us a note, we are interesting in speaking with you (psw /at/ pauldotcom.com).

For now, enjoy the latest AirPwn video and stay tuned!

.com

PaulDotCom Security Weekly TV - AirPwN

We are proud to annouce the latest episode of PaulDotCom Security Weekly TV. This is a special edition devoted entirely to Airpwn, a wireless HTTP injection tool.

Direct Video Download

Airpwn Show Notes

Video Feeds:

Enjoy!

.com

October 21, 2006

PaulDotCom Security Weekly - Episode 49 - October 19, 2006

Live from the PaulDotCom Security Weekly Studio....

  • Sponsored by Core Security, listen for the discount code at the end of the show
  • Sponsored by Syngress, be the first to post the answer to the question at the end of the show and win a free book!
  • Sponsored by Astaro, Astaro Security Gateway line of network security appliances. Listen to the show for a special offer!
  • Please go update our frapper map!
  • Want some cool PaulDotCom Gear? Do you hack naked? Check out our Cafepress Store!
  • Full Show Notes

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

October 19, 2006

Recording and Stream Notice

The the live stream should be active about 6:00 PM EST, today, Thursday October 17th. We should begin recording the live show at about 7:00 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Before we record the show (while we prepare), we will put some music on the stream. This week, we'll be playing some more of our favorite DJ, DJ Jackalope

Please join us, and thanks for listening!

- Larry

October 14, 2006

PaulDotCom Security Weekly - Listener Feedback - Episode 3

Live from the PaulDotCom Security Weekly Studio....

Paul, Larry, Joe, and Twitchy take on listener questions and feedback. Be certain to send us your questions!

Skype: pauldotcom Phone: 401.369.9820

Listener Feedback Episode 3 Show Notes

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" DePetrillo, Joe "Mr C" Conlin
Email: psw@pauldotcom.com

Direct Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

October 13, 2006

PaulDotCom Security Weekly - Episode 48 - October 12, 2006

Live from the PaulDotCom Security Weekly Studio....
  • Sponsored by Core Security, listen for the discount code at the end of the show
  • Sponsored by Syngress, be the first to post the answer to the question at the end of the show and win a free book!
  • Sponsored by Astaro, Astaro Security Gateway line of network security appliances. Listen to the show for a special offer!
  • Please go update our frapper map!
  • Want some cool PaulDotCom Gear? Do you hack naked? Check out our Cafepress Store!
  • Full Show Notes
Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

October 12, 2006

Recording and Live Stream Notice

The the live stream should be active about 5:30 PM EST, today, Thursday October 12th. We should begin recording the live show at about 6:30 PM EST, and we should then move into our listener feedback show (with a possible break for dinner0. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Before we record the show (while we prepare), we will put some music on the stream. This week, we'll be playing the club and lounge mixes from TAO in Las Vegas. If we need to put some music on during dinner, we will move on to more albums from TAO as well.

Please join us, and thanks for listening!

- Larry

October 05, 2006

PaulDotCom Security Weekly - Episode 47 - Oct 3, 2006

Live from Las Vegas, SANS Network Security 2006!

Thank you to all those who attended, we had a blast!

Special thanks to BlackDrag0n for coming out to help and hang out! We would also like to thank Steve, Alyson, and the entire SANS staff. Everyone was truly awesome...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" DePetrillo, "The Mason"
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

September 29, 2006

PaulDotCom Security Weekly - Episode 46 - Sept 28, 2006

Live from the PaulDotCom Security Weekly Studio....

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

September 28, 2006

Recording and Steam notice

The the live stream should be active about 5:30 PM EST, today, Thursday September 26th. We should begin recording the live show at about 6:30 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Before we record the show, we will put some music on the stream. This week, Larry was a moron and forgot his CDs. But never fail, this week we will have Nervous Wreck from DJ Jackalope, as featured on the DEFCON 14 DVD. If there is additional time, we'll move into her DEFCON 14 B&W ball performance.

Please join us, and thanks for listening!

- Larry

September 23, 2006

PaulDotCom Security Weekly - Episode 45 - Sept 21, 2006

Live from the PaulDotCom Security Weekly Studio....

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

September 17, 2006

PaulDotCom Security Weekly - Episode 44 - Sept 15, 2006

Live from the PaulDotCom Security Weekly Studio....

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin
Email: psw@pauldotcom.com

Direct Audio Download
No Video This Week, we are very close to releasing the next episode, which is almost done with the editing.

(Bandwidth provided by OSHEAN)

Audio Feeds:

September 13, 2006

PaulDotCom Security Weekly TV - Judicious Karma

We are proud to annouce the latest episode of PaulDotCom Security Weekly TV. This is a special edition devoted entirely to Karma. Karma is a fantastic wireless assessment tool that we felt everyone should know more about (Thanks Dino!).

Direct Video Download

Here are some supplemental links:

Karma Home Page
Larry's Guide to Karma on Ubuntu
dnsspoof (Dsniff)

Video Feeds:

Enjoy!

.com

September 12, 2006

Recording Notice - Live stream info for 9/15/06

The the live stream should be active about 5:30 PM EST on this friday, September 15th. We should begin recording the live show at about 7:00PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Before we record the show, we will put some music on the stream. This week, we've gone old school, and even more old school! The first album is Robert Miles Dreamland, and if time allows, Emergency Broadcast Network Telecommunication Breakdown.

Please join us, and thanks for listening!

- Larry

PaulDotCom - Special Edition - Interview with Chris Hurley AKA "Roamer"

We had the pleasure of interviewing Chris Hurley, founder of the World Wide Wireless War Drive, and author of many computer security books, including "War Driving & Wireless Penetration Testing". We talked with Chris about:

  • War Driving & Wireless War Driving Setups
  • Wireless Driver Vulnerabilities
  • Municipal WiFi, California Wireless Legislation
  • Identity Theft
  • Information Security Careers
  • Wireless Penetration Testing

Full Show Notes

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian
Email: psw@pauldotcom.com

Direct Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

September 10, 2006

Hi, I'm a Mac...

Many of us are aware of the current situation with wireless driver vulnerabilities. We wanted to be certain that our thoughts and beliefs were conveyed in a manner that exemplifies what we are al about here at PaulDotCom Security Weekly. So, we made our own Mac "Make the switch" commercial for your viewing pleasure:

New - Digg This Video

iPod Video Format (10Mb)

Quicktime Video Format (399Mb) - Offline

Google Video - Offline

You Tube - Offline

DivX Video Format - Offline

We have also updated our video feeds:

Video Feeds:

Enjoy!

The PaulDotCom Security Weekly Crew

September 09, 2006

PaulDotCom Security Weekly - Listener Feedback - Episode 2

Live from the PaulDotCom Security Weekly Studio....

Paul, Larry, Joe, and Twitchy take on listener questions and feedback. Be certain to send us your questions!

Skype: pauldotcom
Phone: 401.369.9820

Listener Feedback Episode 2 Show Notes

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" DePetrillo, Joe "Mr C" Conlin
Email: psw@pauldotcom.com

Direct Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

PaulDotCom Security Weekly - Episode 43 - Sept 9, 2006

Live from the PaulDotCom Security Weekly Studio....

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin
Email: psw@pauldotcom.com

Direct Audio Download
No Video This Week, we are very close to releasing the next episode, which is almost done with the editing.

(Bandwidth provided by OSHEAN)

Audio Feeds:

September 08, 2006

Live Stream active!

The the live stream is now active!

http://hydrogen,oshean.org:8000

Before we start, we will be featuring a new CD each week. This week is one of Larry's favorites: United DJs of America Volume 6, Frankie Bones.

We should begin about 7:30 PM with the live show.

September 01, 2006

PaulDotCom Security Weekly - Episode 42 - August 31, 2006

Live from the PaulDotCom Security Weekly Studio....

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy", Joe Conlin
Email: psw@pauldotcom.com

Direct Audio Download
No Video This Week, we are working on the next episode, hoping for a September release. We are done shooting and plan to release three new episodes in the coming weeks.

(Bandwidth provided by OSHEAN)

Audio Feeds:

August 29, 2006

Want schwag....er, Merchandise!?

We've got plenty of swag for you at our new Cafepress store!

We've got shirts for the guys and the ladies, coffee mugs for those late night hacking sessions, and of course, beer steins (mmm, beer)! There are even a few special treat for your pets, and maybe for that special lady in your life.

Now, we do make a little money on each item (very little actually), so that we can support buying new and special swag for giveaways. Yes, we will continue to give away great swag, and usually they will NOT be available on the store.

Please go check it out, and help us give back to you.

For a direct link, the url is: http://www.cafepress.com/psw

- Larry

August 25, 2006

PaulDotCom Security Weekly - Episode 41 - August 24, 2006

Live from the PaulDotCom Security Weekly Studio....

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy", Joe Conlin
Email: psw@pauldotcom.com

Direct Audio Download
No Video This Week, we are working on the next episode, hoping for a September release.

(Bandwidth provided by OSHEAN)

Audio Feeds:

August 21, 2006

PaulDotCom Security Weekly - Episode 40 - Aug 18, 2006

Live from the PaulDotCom Security Weekly Studio....

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy"
Email: psw@pauldotcom.com

Direct Audio Download
No Video This Week, we are working on the next episode, hoping for an August/September release.

(Bandwidth provided by OSHEAN)

Audio Feeds:

August 13, 2006

PaulDotCom Security Weekly - Episode 39 - Aug 11, 2006

Live from the PaulDotCom Security Weekly Studio....

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy"
Email: psw@pauldotcom.com

Direct Audio Download
No Video This Week, we are working on the next episode, hoping for an August/September release.

(Bandwidth provided by OSHEAN)

Audio Feeds:

August 04, 2006

PaulDotCom Security Weekly - Episode 38 - August 3, 2006

Live from the PaulDotCom Security Weekly Studio....

This episode was also broadcast over our Icecast server. Details will be announced in our IRC chatroom #pauldotcom on Freenode (irc.freenode.net) and on the PaulDotcom blog.

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy"
Email: psw@pauldotcom.com

Direct Audio Download
No Video This Week, we are working on the next episode, hoping for an August release.

(Bandwidth provided by OSHEAN)

Audio Feeds:

July 30, 2006

PaulDotCom Security Weekly - Special Edition - Interview with Ivan Arce

Live from the Core Security Technologies offices in Boston, MA. we are proud to bring you an exclusive interview with CTO and co-founder Ivan Arce.

Paul and Larry discuss many topics with Ivan:

  • How Ivan got started in computers and computer security
  • Vulnerability disclosure
  • The future of penetration testing
  • Exploiting the client, and new research in this area
  • New features in Core Impact, a penetration testing framework
  • And much more!
corelogo.png

Hosts: Larry Pesce, Paul Asadoorian
Email: psw@pauldotcom.com

Direct Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

PaulDotCom Security Weekly - Listener Feedback - Episode 1

Live from the PaulDotCom Security Weekly Studio....

In this first episode Paul, Larry, and Twitchy take on listener questions and feedback. Be certain to send us your questions!

Skype: pauldotcom
Phone: 401.369.9820

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy"
Email: psw@pauldotcom.com

Direct Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

July 29, 2006

PaulDotCom Security Weekly - Episode 37 - July 27, 2006

Live from the PaulDotCom Security Weekly Studio....

This episode was also broadcast over our Icecast server. Details will be announced in our IRC chatroom #pauldotcom on Freenode (irc.freenode.net) and on the PaulDotcom blog.

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy"
Email: psw@pauldotcom.com

Direct Audio Download
No Video This Week, we are working on the next episode, hoping for an August release.

(Bandwidth provided by OSHEAN)

Audio Feeds:

July 26, 2006

PaulDotCom Security Weekly - Live From Las Vegas!

We are so excited to be able to put this event together for our listeners! We will be doing a live recording of PaulDotCom Security weekly, here are the details:

Where: SANS Network Security 2006, Las Vegas, Nevada
When: October 3, 2006 5:30PM-7:00PM
Who: Paul, Larry, and.....TWITCHY!

We are still working out the details, but you can check the official SANS conference web page for updates. We plan to have beer, an open mic, and a good time! So, if you are in the area or going to SANS make sure that you come check us out.

We will have boatloads of free stuff, including the new Official PaulDotCom Security Weekly T-Shirts. Here is a sneak preview:

Official PaulDotCom Security Weekly T-Shirt - Front
Official PaulDotCom Security Weekly T-Shirt - Back

Hope to see you there!

Paul.com

July 20, 2006

Podcast This Week - Cancelled

With everyone on vacation or at conferences we finally decided to take a week off. Many people in general also seem to be on vacation and enjoying the summer, so we thought we would too!

We will be back next week in full force, anticipating some cool stuff coming out at HOPE, Blackhat, and Defcon.

In the mean time, please send us your feedback/questions/comments to psw@pauldotcom.com. We have decided to start devoting entire shows to answering listener questions and topics for discussion, so send them along!

Also, feel free to leave us some voice mail at our Skype account "pauldotcom" or calling 401.369.9820.

See you all next week!

PaulDotCom Security Weekly Crew

July 16, 2006

PaulDotCom Security Weekly - Episode 36 - July 14, 2006

Live from the PaulDotCom Security Weekly Studio....

This episode was also broadcast over our Icecast server. Details will be announced in our IRC chatroom #pauldotcom on Freenode (irc.freenode.net) and on the PaulDotcom blog.

Hosts: Larry Pesce, Paul Asadoorian
Email: psw@pauldotcom.com

Direct Audio Download
No Video This Week, we are working on the next episode, hoping for a July release.

(Bandwidth provided by OSHEAN)

Audio Feeds:

July 07, 2006

PaulDotCom Security Weekly - Episode 35 - July 6, 2006

Live from the PaulDotCom Security Weekly Studio....

This episode was also broadcast over SkypeCast, so look for us each week when we record. It will also be announced in our IRC chatroom #pauldotcom on Freenode (irc.freenode.net).

Hosts: Larry Pesce, Paul Asadoorian
Email: psw@pauldotcom.com

Direct Audio Download
No Video This Week, we are working on the next episode, hoping for a July release.

(Bandwidth provided by OSHEAN)

Audio Feeds:

July 06, 2006

Two announcements: Skypecast and SANSFIRE

Ok, first off Skypecast today!  We should be starting about 6:00 PM EST. Want to listen live? Go to http://skypecasts.skype.com and search for "PaulDotCom" (without the quotes). It may not show up untill we start, so check back in at the time listed above.

Second, Twitchy Nick is at SANSFIRE this week. So, if you are there look him up!  He's got PauldotCom Stickers, shwag from Core Security Technologies, and free books from Syngress!  We're leaving it up to Nick to come up with (legal) means of acquiring said items - most, just ask.

How do you find Nick?  He's taking Security 504 - Hacker techniques, Exploits & Incident Handling with Ed Skoudis.  He also looks almost like a younger version of Professor Severus Snape.

- Larry

 

   

June 30, 2006

PaulDotCom Security Weekly - Episode 34 - June 29, 2006

Live from the PaulDotCom Security Weekly Studio....

This episode was also broadcast over SkypeCast, so look for us each week when we record. It will also be announced in our IRC chatroom #pauldotcom on Freenode (irc.freenode.net).

Hosts: Larry Pesce, Paul Asadoorian
Email: psw@pauldotcom.com

Direct Audio Download
No Video This Week, we are working on the next episode, hoping for a July release.

(Bandwidth provided by OSHEAN)

Audio Feeds:

June 29, 2006

Podcast day!

Today is the day. We are all back in the studio, and we will be resuming our Skype cast.


We should be starting about 6:00 PM EST. Want to listen live? Go to http://skypecasts.skype.com and search for "PaulDotCom" (without the quotes). It may not show up untill we start, so check back in at the time listed above.


Hope to see you all there!

- Larry

June 26, 2006

Feed "bug"

Well, I'd like to call it a bug, but it was just my stupidity.

Apparently the XML feed never referenced the enclosure for episode 33, but it pointed to episode 32 instead. I don't know how I missed it, but I did. Never the less, the feed has been updated.

Hopefully this won't screw up iTunes too badly.

My sincere apologies.

- Larry

[UPDATE] - I just checked my iTunes, and it downloaded the correct podcast. Now I have two entries for episode 33.

June 24, 2006

PaulDotCom Security Weekly - Episode 33 - June 22, 2006

Live via Skype from the Casa del Pesce....

This episode was unfortunatley not broadcast over SkypeCast. Paul is off on his honeymoon this week...so the audio is not the greatest, but not all that bad. Do look for us next week in our IRC chatroom #pauldotcom on Freenode (irc.freenode.net).

Hosts: Larry Pesce, "Twitchy", Kevin Devin
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN They are smooth, like peanut butter.

Audio Feeds:

June 15, 2006

PaulDotCom Security Weekly - Episode 32 - June 14, 2006

Live via Skype from the PaulDotCom Security Weekly Studio and Casa del Pesce....

This episode was unfortunatley not broadcast over SkypeCast. Craziness this week With Paul's wedding and all! However, do look for us in our IRC chatroom #pauldotcom on Freenode (irc.freenode.net).

Hosts: Larry Pesce, Paul Asadoorian
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN

Audio Feeds:

June 13, 2006

PaulDotCom - Version 2.0 and beyond

Before I depart for a much needed vacation I would like to communicate our mission, goals, and intentions to all of the loyal PaulDotCom fans/listeners/subscribers.

The original idea for this podcast was based on a monthly presentation I used to do which covered the month's security vulnerabilities, research, news, how topics, etc... When that died on the vine, I felt this void, like I needed a vehicle to carry my message. I spend a great deal of time keeping up with events in the security world and take great pleasure in sharing it with anyone who will listen. Then I heard about podcasting and thought, "Hey, that sounds like a great medium for the content that I have, and it could be great fun!". Yes, podcasting is a buzz term, but in looking at the underlying technologies, it just made sense. Record a show each week that covers security news, then people can listen to it anytime (I think that on the commute to work is the most popular).

So we set off to SANS LA to record our first podcast. Through some magic and stroke of luck, we also managed a very timely interview with Marty Roesch. I flew home on the plane loaded with raw Audacity files for episode 1 and the interview, and nothing else. No real blog, no RSS feed, no wiki, no recording equipment, no headphones (I had ear buds), zero audio engineering knowledge, and only the beginnings of a team (not certain if Larry had even made the commitment at that point yet).

Fast forward to today, and we have a very successful blog, wiki to hold show notes, interviews with some of the best and brightest in the field, 30+ shows under our belt, a full recording studio, a TV show, a frappr map with globe listeners, and a full team of people who make this all possible (Thanks to Larry, Nick, Andy, Mason, Dave, Jennifer, Snort/Sourcefire, OSHEAN, Syngress, Core, and all the FiT members, especially George). We've also gone through a lot of changes, very fast (okay lightening speed). We've tried numerous show formats, had our bad shows, and our good shows. The one thing that we have kept constant throughout is that we are true to ourselves and don't pretend to be anything else. Other than that, we never really thought people would listen, and never took a step back and thought about what we want to accomplish.

So here we are today, a show that features security professionals hanging out, drinking beer, talking shop, and having fun. We have found our niche being the entertaining and informative podcast. We've pushed the envelope with hacking stories, burping, farting, porn references, nipple shows, and all sorts of stuff that just wouldn't fly in a professional environment. If you asked any of us why, you'd get the same response as you would when as asking a mountain climber why they chose to climb the mountain, because it was there. For us, its because, well, we could. From this point on, it stops, and we get back down to business.

The new PaulDotCom will be more professional. We will continue to be entertaining, but not grotesque. Its easy to be entertaining when there are no rules, unfortunately this leads to offensive material. We want to reach a larger audience and serve more if the community. In order to do that we're turning down the raunchy from 11 to 3. Our new challenge will be to maintain a funny and entertaining podcast while upholding a higher standard of professionalism. This means that we will need to put more thought and effort into our show, which we believe is a worth while effort. We are not selling out, but merely looking to better ourselves and our show as a whole. So, we would now like to announce the official PaulDotCom Security Weekly mission statement:

"PaulDotCom Security weekly's mission is to provide free content within the subject matter of IT security news, vulnerabilities, and research. We strive to use new technologies to reach a wider audience across the globe. The mixture of technical content and entertainment will continue to set a new standard for podcasting and Internet TV."

In closing, I would like to thank the most important people of all, YOU, the listeners! Without you we'd just be a bunch geeks drinkin' beer (yes, we will still drink beer) and geekin' out. Thank you for listening.

Look for even better things to come....

PaulDotCom Security Weekly Crew

Paul.com, Larry, "Twitchy", & "The Mason"

June 09, 2006

PaulDotCom Security Weekly - Episode 31 - June 8, 2006

Live from the PaulDotCom Security Weekly Studio....

This episode was also broadcast over SkypeCast, so look for us each week when we record. It will also be announced in our IRC chatroom #pauldotcom on Freenode (irc.freenode.net).

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy"
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN

Audio Feeds:

PaulDotCom Security Weekly - Episode 30 - June 1, 2006

Live from the PaulDotCom Security Weekly Studio....

This episode was also broadcast over SkypeCast, so look for us each week when we record. It will also be announced in our IRC chatroom #pauldotcom on Freenode (irc.freenode.net).

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy"
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN

Audio Feeds:

May 29, 2006

PaulDotCom Security Weekly - Episode 29 - May 26, 2006

Live from the PaulDotCom Security Weekly Studio....

This episode was also broadcast over SkypeCast, so look for us each week when we record. It will also be announced in our IRC chatroom #pauldotcom on Freenode (irc.freenode.net).

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy"
Email: psw@pauldotcom.com

Direct Audio Download
There really is no video this week :)

(Bandwidth provided by OSHEAN, Don't mess with them, they have a spray bottle)

Audio Feeds:

May 26, 2006

PaulDotCom Security Weekly TV - "Videocast Kills The Podcast Star"

We promise to get back to some real technical content in the next episode. We've hired a video producer/camera man named Dave "Cool". He did some awesome work on the episode 28 video, and this one that I am calling "Videocast Kills The Podcast Star".

Direct Video Download

More good stuff coming, such as WRT54G hacking, more wireless tutorials, hacking, exploiting, and penetration testing caught on tape!

Video Feeds:

Enjoy!

.com

May 22, 2006

PaulDotCom Security Weekly TV - Episode 28 - Behind The Scenes

All:

We are continuing to experiment with our video feed and are working hard to improve this medium all around (we actually hired like a real film person to help).

This is a short, edited, video version of episode 28. It contains footage of us doing the introduction, some announcements, and you get to see Storytime With Twitchy....Live!

Let us know what you think of this format. We plan to change it up, so sometimes we will feature storytime with twitchy, the news, or other segments from the show. I think the goal will be to keep it under 30 minutes (this one is ~10 minutes), and not let the video run the full hour.

Props to Larry, his video editing kung foo is improving :)

Direct Video Download

Video Feeds:

May 19, 2006

PaulDotCom Security Weekly - Episode 28 - May 18, 2006

Live from the PaulDotCom Security Weekly Studio....

This episode was also broadcast over SkypeCast, so look for us each week when we record. It will also be announced in our IRC chatroom #pauldotcom on Freenode (irc.freenode.net).

  • Sponsored by Core Security, listen for the discount code at the end of the show
  • Sponsored by Syngress, be the first to post the answer to the question at the end of the show and win a free book!
  • Sponsored by The SANS Institute, listen to the discount code for SANSFIRE this summer for 5% off this conference
  • Please go update our frapper map!
  • Help us get a cool logo and slogan! Go to our contest page and read all about how you can win free Snort gear and a one-year subscription to VRT rules. Sponsored by Sourcefire
  • Full Show Notes

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy"
Email: psw@pauldotcom.com

Direct Audio Download
Direct Video Download - Okay, so I lied, there is video this week!

(Bandwidth provided by OSHEAN, Look out for the broadsword!)

Audio Feeds:

Video Feeds:

May 18, 2006

Listen to PaulDotCom Security Weekly Live - Skypecast

All:

We did some experimenting last week and decided that Skypecasting is a great way for people to listen to the show live. You can find all of the details at the following link:

https://skypecasts.skype.com/skypecasts/skypecast/detailed.html?id_talk=5717

(We will be podcasting today, May 18, 2006 at 6:00PM EST)

In essence, you place a skype-skype call (free) to a conference number which lets you listen to our show. For the duration of the show you can only listen. After the show (if there is still time) we open up the lines for general discussion.

Hope to see you all there!

PaulDotCom Security Weekly Crew

psw-logo-7.jpg

May 12, 2006

PaulDotCom Security Weekly - Episode 27 - May 11, 2006

Live from the PaulDotCom Security Weekly Studio....

We had two special guests on the show, Kevin Amorin from Harvard and co-deveoper of Packet Fence, and Martin Mckeay of the Network Security Podcast.

This episode was also broadcast over SkypeCast, so look for us each week when we record. It will also be announced in our IRC chatroom #pauldotcom on Freenode (irc.freenode.net).

  • Sponsored by Core Security, listen for the discount code at the end of the show
  • Sponsored by Syngress, be the first to post the answer to the question at the end of the show and win a free book!
  • Sponsored by The SANS Institute, listen to the discount code for SANSFIRE this summer for 5% off this conference
  • Please go update our frapper map!
  • Help us get a cool logo and slogan! Go to our contest page and read all about how you can win free Snort gear and a one-year subscription to VRT rules. Sponsored by Sourcefire
  • Full Show Notes

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy"
Email: psw@pauldotcom.com

Direct Audio Download
No video this week...

(Bandwidth provided by OSHEAN, Rockin' in the free world)

Audio Feeds:

May 08, 2006

PaulDotCom Security Weekly IRC - #pauldotcom

All:

If you'd like to come hang out with Larry, Twitchy, myself, and the PaulDotCom crew come to Freenode (irc.freenode.net) #pauldotcom. We will try to hang out there as much as possible for general show discussion, questions, comments, and security geek talk.

Also, we will try to hang out there during the show (usually recorded thursday nights, 5:30PM EST).

Hope to see you all there!!!

psw-logo-2.jpg

Paul.com

May 05, 2006

PaulDotCom Security Weekly - Episode 26 - May 4, 2006

Live from the PaulDotCom Security Weekly Studio....

  • Sponsored by Core Security, listen for the discount code at the end of the show
  • Sponsored by Syngress, be the first to post the answer to the question at the end of the show and win a free book!
  • Sponsored by The SANS Institute, listen to the discount code for SANSFIRE this summer for 5% off this conference
  • Please go update our frapper map!
  • Help us get a cool logo and slogan! Go to our contest page and read all about how you can win free Snort gear and a one-year subscription to VRT rules. Sponsored by Sourcefire
  • Full Show Notes

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy"
Email: psw@pauldotcom.com

Direct Audio Download
No video this week...

(Bandwidth provided by OSHEAN, They don't sniff panties either)

Audio Feeds:

May 01, 2006

PaulDotCom TV - Episode X

What do you get when you take:

- A potato cannon
- An axe
- An old Sun monitor
- Some old laptops
- A lame Kung Fu master

PaulDotCom Security Weekly TV - Episode X!

Warning: Do not try this at home, if you do, we don't know you.

Paul.com (Yes, I do all my own stunts)

Direct Video Download

Video Feeds:

April 29, 2006

Thank You For Listening

Just wanted to take this opportunity to thank all you listeners out there. All you guys and gals totally rock and we thank you for listening to our show. We've reached new heights thanks to you:

1) We now have 249 members on our frappr map. Keep up the good work! This is also fun for us to see where all of our listeners are from. Next time we travel we may look you up :)

2) We are now technology podcast #89 in the top 100 technology podcasts listed in the iTunes music store! Holy crap Batman, people are listening! All I can say is that is so cool. I also noticed that some other security podcast I had never heard of was ahead of us for a while. Hmmmmmm. So, to move up in the iTunes store we need more listeners, and of course iTunes feedback helps too. So head on over to our iTunes site and let us know what you think!

3) Your feedback lately has been totally awesome. I just received some audio feedback (from out friends at Tech News Radio) that was very insightful, in addition to the awesome questions and often entertaining commentary that comes through our email box daily. The latest one was a parallel between the Bunny Ranch and IT Security. Simply awesome! (Thanks to cutaway, see his blog posting on the subject here)

Everyone also deserves props for putting up with Twitchy, while his technical content is spot on, that comes with well, twitchyness. However, I found the perfect birthday gift for him while reading the latest copy of 2600 and Blacklisted 411 (my two all-time favorite magazines). Send me some email if you want in on it :)

"Hacking is not a crime"

Cheers,

Paul.com

April 28, 2006

PaulDotCom Security Weekly - Episode 25 - April 27, 2006

Live from the PaulDotCom Security Weekly Studio....

  • Sponsored by Core Security, listen for the discount code at the end of the show
  • Sponsored by Syngress, be the first to post the answer to the question at the end of the show and win a free book!
  • Sponsored by The SANS Institute, listen to the discount code for SANSFIRE this summer for 5% off this conference
  • Please go update our frapper map!
  • Help us get a cool logo and slogan! Go to our contest page and read all about how you can win free Snort gear and a one-year subscription to VRT rules. Sponsored by Sourcefire
  • Full Show Notes

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy"
Email: psw@pauldotcom.com

Direct Audio Download
Direct Video Download - War Driving

(Bandwidth provided by OSHEAN, Give your ISP a good spanking, they might like it)

Audio Feeds:

April 21, 2006

PaulDotCom Security Weekly - Episode 24 - April 20, 2006

Live from the PaulDotCom Security Weekly Studio....

WARNING: Twitchy did not take his meds for this episode. Listen at your own risk!

  • Sponsored by Core Security, listen for the discount code at the end of the show
  • Sponsored by Syngress, be the first to post the answer to the question at the end of the show and win a free book!
  • Sponsored by The SANS Institute, listen to the discount code for SANSFIRE this summer for 5% off this conference
  • Please go update our frapper map!
  • Help us get a cool logo and slogan! Go to our contest page and read all about how you can win free Snort gear and a one-year subscription to VRT rules. Sponsored by Sourcefire
  • Full Show Notes

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy"
Email: psw@pauldotcom.com

Direct Audio Download
Direct Video Download - We put together a very short promotional video this week. We will resume next with with actual technical content.

(Bandwidth provided by OSHEAN, They take their meds)
Audio Feeds:

April 17, 2006

PaulDotCom Logo & Slogan Contest (Sponsored by Sourcefire)

It is not too often that we call upon the listeners for much, I mean we ask you to of course keep listening to the show, provide us with some feedback, and put some pins on our frappr map. I would like to say "Thank You!" to everyone for all of those things. We appreciate the time you take to listen to our crazy show, send us email (even if its flame mail), and put pins on the map.

I had really no idea that this would take off like it has. We went to SANS 2005 in LA with the intent of giving this whole podcasting thing a try. We had tried to speak our minds and convey our thoughts through other mediums, and mostly that just got us in trouble :) Such was born PaulDotCom Security Weekly. So when we created the logo and such it was just a quick kind of thing, not too much thought was put into it. We are committed to our listeners and the show and we are here to stay. So, why not have a super cool logo and slogan! And who better to ask than our beloved listeners!

Your mission young grasshoppers is to create a logo and come up with a slogan for PaulDotCom Security Weekly. The winner gets a free subscription to the Snort VRT rules and a $50.00 gift certificate to the snort store.

You can find out about all the contest details HERE.

We are not looking for a super, wizbang, extravagant logo, the winner will be the one who comes up with a logo that best represents our show (please try to keep it PG-13).

(Special thanks to Sourcefire for organizing and sponsoring this contest. You guys rock!)

Thank You!

The PaulDotCom Security Weekly Crew

April 14, 2006

PaulDotCom Security Weekly - Episode 23 - April 13, 2006

Live from the PaulDotCom Security Weekly Studio....

  • Sponsored by Core Security, listen for the discount code at the end of the show
  • Sponsored by Syngress, be the first to post the answer to the question at the end of the show and win a free book!
  • Sponsored by The SANS Institute, listen to the discount code for SANSFIRE this summer for 5% off this conference
  • Please go update our frapper map!
  • Please leave us feedback in the iTunes Store!
  • Full Show Notes

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy", "The Mason"
Email: psw@pauldotcom.com

Direct Audio Download
Direct Video Download - There is no video this week. We hope to continue our wireless series next week.

(Bandwidth provided by OSHEAN, Host me baby!)
Audio Feeds:

April 12, 2006

PaulDotCom Security Weekly - Special Edition - Interview with Johnny Long

We are very proud to bring you the exclusive interview with Johnny Long. I would like everyone to go out and buy two copies of his Google hacking book from Johnny's web site because 100% of the proceed go to charity, and everyone should have a copy for work and a copy for home :) Here are the links to purchase:

Purchase the book here - All proceeds benefit the Compassion International Children's Fund.

NOTE: There was some lag on this call, we're sorry, hoping to upgrading bandwith or replace Skype with something better.

  • How Johnny set a new world record for employment (well sorta)
  • The history of "Google Hacking"
  • How johnny.ihackstuff.com came to be the wonderful Google hacking source
  • Johnny discuss an assortment of Google hacking tools, such as BiDiHBLAH, bile, Wikto, and AdvancedDork
  • Hear the "behind the scenes" of Johnny's "Hacking Hollywood" presentation he gave at Schmoocon
  • Johnny discusses some of his other books, including "OS X for the Hackers Heart" and the Stealing the Network Series
  • Ethics, religion, and being yourself
  • Good advice for life, Kung Fu, and being a penetration tester

Hosts: Larry Pesce, Paul Asadoorian
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN, Google them, they like)

Audio Feeds:

April 07, 2006

PaulDotCom Security Weekly - Episode 22 - April 6, 2006

Live from the PaulDotCom Security Weekly Studio....

  • Sponsored by Core Security, listen for the discount code at the end of the show
  • Sponsored by Syngress, be the first to post the answer to the question at the end of the show and win a free book!
  • Sponsored by The SANS Institute, listen to the discount code for SANSFIRE this summer for 5% off this conference
  • Please go update our frapper map!
  • Please leave us feedback in the iTunes Store!
  • Full Show Notes

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy"
Email: psw@pauldotcom.com

Direct Audio Download
Direct Video Download - "Using Netstumbler and Ministumbler"

(Bandwidth provided by OSHEAN, If they were a botnet, they'd be a good botnet, yeeees, a good botnet)

Video Feeds:

Audio Feeds:

April 02, 2006

PaulDotCom Security Weekly - Special Edition - Open Show - "Wireless Piggybacking"

This was a very fun experiment that was a resounding success. I would like to extend a personal thanks to everyone who participated. We had some awesome commentary, and some fantastic guests that called into the show:

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy"
Email: psw@pauldotcom.com

Direct Audio Download - Part I
Direct Audio Download - Part II

(Bandwidth provided by OSHEAN, Cooler than a 0day sploit with polymorphic shell code)

Audio Feeds:

April 01, 2006

PaulDotCom Security Weekly - Episode 21 - March 30, 2006

Live from the PaulDotCom Security Weekly Studio....

  • Come join our very first "open show" on March 30, 2006 5:30PM EST you can Skype into our show and participate on our show! The first topic will be "Piggybacking Wireless Networks: Is it legal? Moral? Ethical? Cool? Not Cool?". Come join us and let us know what you think!
  • Sponsored by Core Security, listen for the discount code at the end of the show
  • Sponsored by Syngress, be the first to post the answer to the question at the end of the show and win a free book!
  • Please go update our frapper map!
  • If you are in the Providence, RI area the week of April 1st you can come to ACUTA to hear Twitchy and I give presentations (separate ones)
  • Please leave us feedback in the iTunes Store!
  • Full Show Notes

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy"
Email: psw@pauldotcom.com

Direct Audio Download
Direct Video Download - "WRT54G Secure Wireless Setups"

(Bandwidth provided by OSHEAN, We Digg them)

Video Feeds:

Audio Feeds:

March 31, 2006

PaulDotCom Security Weekly - Special Edition - Interview with Joshua Wright - Part II

Part II of our exclusive interview with Joshua Wright of Aruba Networks. In part II we discuss:

  • The current state of wireless intrusion detection
  • Josh talks about wireless client insecurities, such as flaws in wireless drivers
  • WifiPedia - a free source of WLAN-related information initially brought to you by the Secure Programming Group at University of Oulu.
  • LORCON - Loss Of Radio Connectivity - A wireless driver abstraction layer
  • Hottspot insecurity, and dangers of Karma, hotspotter, Airpwn, and Raw Glue AP
  • "I am Your Malicious Web Site"
  • Wireless defense measures for your client
  • Oracle Security, or lack thereof
  • Josh's trick or treat Oracle application
  • Oracle Password Hashing Algorithm
  • The hazards of teaching your children how to start counting from 0
  • Josh talks (er, well, sorta) about the awesome cool stuff he's working on at Aruba
  • Josh still teaches the wireless track for The SANS Institute, check out the Virginia conference, and SANSFIRE.
  • Be certain to check out Kismet

Hosts: Larry Pesce, Paul Asadoorian
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN, They have good Karma)

Audio Feeds:

March 28, 2006

PaulDotCom Security Weekly - Open Show Announcement - "Piggybacking Wireless Networks"

Dear listeners,

Some of you have written in and stated that you want to be more involved with the show, and we think thats great! Also, we've had some heavy debating (via email) on various topics. So, Larry and I, being the crazy podcasters that we are, came up with this idea for an "Open Show":

When: March 30, 2006 - 5:30PM - 7:00PM EST
Where: Skype - Skypeid: "pauldotcom", phone: 401.369.9820

Here's how it will work:

  • If you wish to participate please be ready to discuss the topic for the show (opinions, facts, its all good) Before you come on the show you will need to use Skype chat to speak with the moderator. The moderator will ask you a few questions (name, where you are from, etc...)
  • Once you are approved we will accept your Skype call
  • You will be given 10 or so minutes maximum to participate in the show

Here are some ground rules:

  • Please keep it clean, children could be listening! PG-13 is the general rule...
  • Be polite, do not talk over anyone else
  • Do not over-shamelessly plug, I mean you can shamelessly plug a thing or two, but if you are interested in advertising on the show we'd be happy to talk offline :-)

Hope to see you all there!

.com

March 27, 2006

PaulDotCom Security Weekly - Special Edition - Interview with Joshua Wright - Part 1

We are excited to bring you this exclusive interview with Joshua Wright of Aruba Networks. Josh is a good friend of ours and sits live in the PaulDotCom Security Weekly studio to discuss everything from wireless security to fingerprinting microwaves.

In part I we discuss:

  • How Josh got an "A" on an assignment in College and landed his first IT security job
  • His interested in wireless network security, or lack thereof, and the "hacking opportunities" they present
  • The story behind the weaknesses in LEAP and how the Asleap tool came to be
  • Bluetooth vulnerabilities and testing tools, research from the Trifinite group, a tool called bluepinning
  • Challenges associated with auditing bluetooth wireless networks
  • How CoWPAtty came to be and risks associated with WPA
  • Suggestions from Josh on what works today to protect wireless networks
  • WySpy - How it works and Josh's experiences with fingerprinting microwaves

Hosts: Larry Pesce, Paul Asadoorian
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN, Because we're poor and can't afford it)

Audio Feeds:

March 24, 2006

PaulDotCom Security Weekly - Episode 20 - March 23, 2006

Live from the PaulDotCom Security Weekly Studio....

  • Come join our very first "open show" on March 30, 2006 5:30PM EST you can Skype into our show and participate on our show! The first topic will be "Piggybacking Wireless Networks: Is it legal? Moral? Ethical? Cool? Not Cool?". Come join us and let us know what you think!
  • Sponsored by Core Security, listen for the discount code at the end of the show
  • Sponsored by Syngress, be the first to post the answer to the question at the end of the show and win a free book!
  • Please go update our frapper map!
  • If you are in the Providence, RI area the week of April 1st you can come to ACUTA to hear Twitchy and I give presentations (separate ones)
  • Please leave us feedback in the iTunes Store!
  • Full Show Notes

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy"
Email: psw@pauldotcom.com

Direct Audio Download
Direct Video Download - There will be no video release this week. Stay tuned for more wireless hacking in future episodes!

(Bandwidth provided by OSHEAN, Hmmmmmm, Their Kung Fu is strong.....)

Video Feeds:

Audio Feeds:

March 18, 2006

PaulDotCom Security Weekly - Episode 19 - March 16, 2006

Live from the PaulDotCom Security Weekly Studio....

(Video version has been posted, check it out!)

  • Sponsored by Core Security, listen for the discount code at the end of the show
  • Sponsored by Syngress, be the first to post the answer to the question at the end of the show and win a free book!
  • Please go update our frapper map!
  • If you are in the Providence, RI area the week of April 1st you can come to ACUTA to hear Twitchy and I give presentations (separate ones)
  • Please leave us feedback in the iTunes Store!
  • Full Show Notes

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy"
Email: psw@pauldotcom.com

Direct Audio Download
Direct Video Download - Wireless Hacking - Part I

(Bandwidth provided by OSHEAN, They bring us good luck, like lepricons)

Video Feeds:

Audio Feeds:

March 10, 2006

PaulDotCom Security Weekly - Episode 18 - March 9, 2006

Live from the PaulDotCom Security Weekly Studio....

UPDATE: Video version has been added. NEW RULE: No more beer drinking during PaulDotCom Security Weekly TV. No really, I'm serious this time!

  • Sponsored by Core Security, listen for the discount code at the end of the show
  • Sponsored by Syngress, be the first to post the answer to the question at the end of the show and win a free book!
  • Please go update our frapper map!
  • Its not Twitchy's birthday this week
  • Smurf attacks are not so sweet
  • Our first audio comment!
  • Here are some good Bluetooth Links, Thanks Christian!
  • Hacking into voice mail, using good voice mail passwords
  • Please leave us feedback in the iTunes Store!
  • Detecting botnets from Sana Security, anyone using this product?
  • Full Show Notes

Don't forget to check out Larry's Blog,HaxorTheMatrix.com for coverage on the latest security and hacking news.

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy"
Email: psw@pauldotcom.com

Direct Audio Download
Direct Video Download

(Bandwidth provided by OSHEAN, They do have supercow powers)

Video Feeds:

Audio Feeds:

March 04, 2006

PaulDotCom Security Weekly - Episode 17 - March 4, 2006

Live from the PaulDotCom Security Weekly Studio....

Note: Video has been added! Larry and I give a demo of Kismac.

  • Sponsored by Core Security, listen for the discount code at the end of the show
  • Sponsored by Syngress, be the first to post the answer to the question at the end of the show and win a free book!
  • Last weeks winner was William Day, congrats!
  • Please go update our frapper map!
  • Using Cain & Abel properly
  • mwcollectd, nepetheses, and differences between "Security Ninja" and "Ninja Fan"
  • Larry give us the update from SANS Orlando 2006
  • Full Show Notes

Don't forget to check out Larry's Blog,HaxorTheMatrix.com for coverage on the latest security and hacking news.

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy", Martin McKeay
Email: psw@pauldotcom.com

(The show is getting long again, we apologize and will try for a shorter show next week, promise)

Direct Audio Download
Direct Video Download

(Bandwidth provided by OSHEAN, They have ninjas)

Video Feeds:

Audio Feeds:

February 26, 2006

PaulDotCom Security Weekly - Episode 16 - Feb 24, 2006

Live from Paul's Dojo....

  • Sponsored by Core Security, listen for the discount code at the end of the show
  • Sponsored by Syngress, be the first to post the answer to the question at the end of the show and win a free book!
  • Last weeks winner was Steve Murawski, who is now a proud 0wner of "Penetration Testing Open Source Toolkit"
  • Please go update our frapper map!
  • Paul talks about 2 Security incidents, Dos from Japan, Smurfs
  • Larry did no work this week
  • Nick has interns
  • Listener Feedback, John Sawyer states that the Nmap option "-sV" is new since 3.4 only addition quality
  • Fred mentions the Washington Post article, "Invasion of the Computer Snatchers"
  • Almost Bricked a WRT54g, go HERE for all the processor types and flash matrix
  • Mason has is boss ping China
  • Paul plugs his company, Defensive Intuition, mentions that he can write policy, vulnerability assessments, penetration testing...
  • OS X Users should check out ClamxAV
  • Full Show Notes

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy", "The Mason"
Email: psw@pauldotcom.com

Direct Audio Download
Direct Video Download (Questionable this week, I will keep you posted)

(Bandwidth provided by OSHEAN, Ridin' the cool wave)

Video Feeds:

Audio Feeds:

February 20, 2006

PaulDotCom Security Weekly - Special Edition - Interview with Mike Poor & Ed Skoudis - Part II - Feb 12, 2006

In part II of our interview we discuss:

  • Brazilian hacker groups
  • The physical manifestation of the NOP Sled
  • OS Security/Insecurity, Shmoocon OS X Hack, OS X predictions
  • Apple's move to Intel and its impact on security
  • Bastille for Mac OS X
  • Why not to hack your attacker
  • Mike tells us a botnet story
  • Preview of Mike/Ed's current projects such as Anti-Spyware testing and VMware escaping research, "The Skoudis & Poor 50", "Counterhack: Reloaded", "Packet Wars"
nopsled.jpg

Hosts: Larry Pesce, Paul Asadoorian, "The Mason"
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN, ISP: Reloaded)

Audio Feeds:

February 19, 2006

PaulDotCom Security Weekly - Episode 15 - Feb 17, 2006

Hosts: Larry Pesce, Paul Asadoorian
Email: psw@pauldotcom.com

Direct Audio Download
Direct Video Download

(Bandwidth provided by OSHEAN, They be big pimpin')

Video Feeds:

Audio Feeds:


February 16, 2006

PaulDotCom Security Weekly - Interview with Mike Poor & Ed Skoudis - Part 1

We are very excited to present to our listeners an exclusive interview with Mike Poor & Ed Skoudis of Intelguardians and The SANS Institute. Larry, The Mason, and myself spoke with Mike and Ed about a wide range of information security topics. This is part I of a two part interview.

In part I we discuss:

  • First computers that Mike and Ed owned (NOT 0wn3d, see part II for that, kidding of course :)

  • How Mike and Ed got their start in the information technology field

  • They describe the primary courses they teach at SANS, GCIA and GCIH

  • A really good description of SANS EDU

  • Their experiences as incident handlers for The Internet Storm Center (ISC)

  • Recent security incident trends, such as more hackers going to jail

  • Botnet economics and strategies, plus ways to defend against the almighty botnet

  • Current malware trends and defense mechanisms, including Mike Poor's commentary on IDS and malware

Hosts: Larry Pesce, Paul Asadoorian, "The Mason"
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN, Because we're poor and can't afford it)

Audio Feeds:


February 10, 2006

PaulDotCom Security Weekly - Episode 14 - Feb 12, 2005

Update: The short metasploit video has been posted.

A big thanks to George Starcher of In The Trenches for helping me with some of our audio problems and teaching me how to edit with Soundtrack Pro. This is the first time that we have integrated other content into our video, so please bear with us through our "firsts".

Hosts: Larry Pesce, Paul Asadoorian
Email: psw@pauldotcom.com

Direct Audio Download
Direct Video Download

(Bandwidth provided by OSHEAN, Their cool, because they let us play in their sandbox)

Video Feeds:

Audio Feeds:

February 05, 2006

PaulDotCom Security Weekly - Episode 13 - Feb 3, 2006

For the first time we will be releasing the audio and video versions of our show at the same time! Of course, we've still got some audio issues that need to be addressed, and hopefully we will have some better video content coming soon. Got some suggestions? Send us feedback!

Hosts: Larry Pesce, Paul Asadoorian, "The Mason"
Email: psw@pauldotcom.com

Direct Audio Download
Direct Video Download

(Bandwidth provided by OSHEAN, The host with the most)

Video Feeds:

Audio Feeds:

February 01, 2006

Introducing PaulDotCom Security Weekly TV

We are to the point where we are comfortable releasing the video version of PaulDotCom Security Weekly each week. The release will lag a little behind the audio version, especially in the beginning. We are also working hard to include more exclusive video content (so you will get to see more than just Larry and I sitting with headphones on). We currently have two episodes in the feed:

Episode 11
Episode 12

Both videos are formatted for the iPod video, but you can use iTunes or Quicktime to play them on pretty much any platform. The direct download and feed links are also listed below. I am working on getting this feed into iTunes as well.

Enjoy!

Video Feeds: Direct Video Download

Send us feedback and let us know what you think!

.com

January 29, 2006

PaulDotCom Security Weekly - Episode 12 - Jan 27 2006

We didn't think that this episode would ever make it to post-preduction (two dropped Skype calls and the primary and secondary recording devices failed. Good thing we were recording video, which we had problems with too). I think this episode officially has been cursed by ninjas, so listen at your own risk!

caution-ninja.png

Hosts: Larry Pesce, Paul Asadoorian, "The Mason"
Email: psw@pauldotcom.com

Direct Audio Download (It works now, sorry for the inconvenience, damn Ninjas...)
Direct Video Download (New!)

(Bandwidth provided by OSHEAN, They have super-ninja powers)

Video Feeds: Direct Video Download

Audio Feeds: Direct Audio Download

January 25, 2006

PaulDotCom Security Weekly - Episode 11 - Video Version

For your viewing pleasure we have released the video version of Episode 11. We are still experimenting with the video and tweaking the process. We'd like your feedback so we know what works best for everyone with respects to video. So, what format should we offer the video in? Right now, we are targeting the video iPod, so its "H.264, 320 x 240, Millions AAC, Stereo (L R), 32.000 kHz". Also, should we include the video in the RSS feed? Should we have a separate feed for video?

Drop us a line at , and let us know what you think!

Direct Download Link

.com

January 23, 2006

PaulDotCom Security Weekly - Episode 11 - Jan 20, 2006

Hosts: Larry Pesce, Paul Asadoorian, "Twitchy"
Email: psw@pauldotcom.com

Direct Download Link

(Bandwidth provided by OSHEAN, they got big pipes)

January 19, 2006

PaulDotCom Security Weekly - Special Edition - Richard Bejtlich Interview

We are proud to bring you our exclusive interview with Richard Bejtlich, owner and operator of the Tao Security Blog, independent consultant, and author of Extrusion Detection.

Richard talks with us about about:

Hosts: Larry Pesce, Paul Asadoorian
Email: psw@pauldotcom.com

Direct Download Link

(Bandwidth provided by OSHEAN,They rank up their with FreeBSD)

January 15, 2006

PaulDotCom Security Weekly - Episode 10 - Jan 13, 2006

We had some audio problems on this one, of course I went home and figured out what the problems were. In any case, we are continually improving, so please bear with us. This weeks show notes (Thanks Andy!):

Hosts: Larry Pesce, Paul Asadoorian, "The Mason"
Email: psw@pauldotcom.com

Direct Download Link

(Bandwidth provided by OSHEAN, They don't smoke crack)


PaulDotCom Security Weekly - Special Edition - Schmoocon Update

Well, we are well on our way to getting this whole Skype thing figured out. Our official Schmoocon correspondent Nick gives us the scoop on the Schmoocon conference. Topics include:

  • Paul forgets Larry's introduction (Doh!)
  • Our behind the scenes guy Nick DePetrillo is at Shmoocon
  • Mike Lynn, and his lawyer Jennifer Granick make an appearance
  • Fyodor releases a new version of nmap 3.98-shmoo with realtime user feedback and corrupt tcp checksum tests. It does not appear to be on the website yet.
  • Cisco 0-day ARP flood Cisco Access Points as discussed in our last episode
  • Release of all presentation videos for free
  • Church of WiFi, Renderman presents "hotspotting"
  • DVD of presntation - quality is excellent!
  • Shmoocon attendees enjoy harassing Amway conference attendees (Note: It is only the opinion of the broadcasters that Amway may be a "pyramid scheme". Please form your own opinions regarding their business practices)
  • Lots of VoIP hacking, custom asterisk installations
  • Look for Paul's t-shirt "Bow to My Firewall!"
  • NSA Wiretaps with Jennifer Granick
  • Be sure to check out the online content when it is available. We'll be sure to let you know when it is available.
  • Thanks Nick!


Hosts: Larry Pesce, Paul Asadoorian
Email: psw@pauldotcom.com

Direct Download Link

(Bandwidth provided by OSHEAN, We bow to them)

January 06, 2006

PaulDotCom Security Weekly - Episode 9 - Jan 5, 2006

Larry and I talk about:

- Blackberry vulnerabilities, users and servers are at risk
- Beer podcast, party foul - Larry's beer is empty
- Tape runs out on video, so no video this time. Check out the Christmas video in the mean time
- Larry's blog takes on a new format
- The anti-spyware conspiracy. Check out Adarware, Microsoft Antispyware. For advanced users, try Rootkit Revealer and Hijackthis
- Centralized antispyware tools? The market looks thin. Web filtering/proxy instead via blacklists.
- AIX Heap Overflow introduction by David Litchfield
- Security news flooded with Microsoft WMF Patch release. Patch your machines NOW!
- Feeding the dog (Rocco the pug) peanutbutter
- A follow up to fwknop -
webknock. Remote access through monitoring Apache logfiles.
- What's coming: Interviews? Sponsors?

I think this is our best sounding podcast yet, but we'll let you be the judge. Send us some feedback!

Hosts: Larry Pesce, Paul Asadoorian
Email: psw@pauldotcom.com

Direct Download Link

(Bandwidth provided by OSHEAN, they got funk, and they got style)

PaulDotCom - WMF Summary Podcast - Jan 5, 2005

Even with a patch in general circulation, there are still many aspects to the this vulnerability that we felt deserved some special attention. We cover the full details of the vulnerability, remediation steps, the unofficial patch, and more!

I wanted to provide some updated information about IDS and WMF. The latest Snort signatures do detect the WMF vulnerability (more specifically the escape() function call) and are provided by the bleeding snort folks. The latest rules can be found here.

There are known false positives associated with these rules and they do not detect attacks that have been gzipped. (Thank you Frank Knobbe)

For more information, check out our WMF related blog postings:

The WMF Patch Has Landed
Beating Microsoft to the punch: Ilfak Guilfanov Interview
How Bad is WMF
WMF Vulnerability & Exploits: Just The Facts


Hosts: Larry Pesce, Paul Asadoorian
Email: psw@pauldotcom.com

Audio Direct Download Link

(Bandwidth provided by OSHEAN, they're good, like early release patches)

December 23, 2005

Happy Holidays!

Wishing everyone a happy and safe holiday season. Be certain to check out our short holiday video clip:

Short Video Clip Direct Download Link (iPod Video)

We will be taking some time off, returning the week of January 2, 2006. There are good things coming in 2006. For now, eat, drink, and be merry... (I certainly will :)

.com

PaulDotCom Security Weekly - Episode 8 - Dec 22, 2005

- Paul & Larry drink spiked egg nog
- Our Friends in Tech have put out their own "Geek Christmas Carol"
- New format of the show for the new year, keep the main show short, add-in special features- Listener feedback: John writes in and asks us to share some of our training and real life experiences, as far as training how it helped us in our jobs and sharing some more stories. We do, and we will :-)
- Check out the SANS Policy Resources
- Question of the week from Jeff - "Is there a tool you can run to catch insiders tunneling ssh over outbound 443/tcp to their home *nix box and then tunneling X back so they can surf and/or download software?" Check out the Bleeding Snort sigs for monitoring SSH on a non-std port, try a Packeteer or Netenforcer, Proxy all outbound connections (Squid perhaps), Monitor the desktop (CSA maybe?)
- Paul's conspiracy theory on Internet Week, Firefox "flaws"
- Never use IE on a Mac, Support Ending
- Guidance Software, makers on the forensic tool Encase, got hacked
- Nikon Coolpix P2 is pretty cool, supports Wi-Fi and WPA
- Oracle has partnered with Fortify Software, makers of Source Code Analysis software
- If you want to hack your Linksys, don't buy a Series 5 WRT54G- Bypassing VLANs for Fun and Profit with Yersinia
- A little history about PaulDotCom Security Weekly- Single packet authentication with fwknop, and a new version of SSH

Hosts: Larry Pesce, Paul Asadoorian
Email: psw@pauldotcom.com

Short Video Clip Direct Download Link (iPod Video)

Audio Direct Download Link

(Bandwidth provided by OSHEAN, powerful they are, like egg nog)

December 20, 2005

PaulDotCom Security Weekly - Episode 7 - Video Take 1

We have been experimenting with video lately and hope to have it become a regular thing after Christmas. You can find the video formatted for the iPod video at the following link:

iPod Video Direct Download

The audio gain levels were set too high, we will be working this week to correct this problem and hope to offer episode 8 this coming week. But, we thought we would throw this one out there just for fun (make sure you turn down the volume of your player :)

.com

December 19, 2005

PaulDotCom Security Weekly - Episode 7 - Dec 16, 2005


- Make sure you check out Friends In Tech, the two I have been listening to are In The Trenches and ChuckChat Technorama
- Thanks to Jennifer we post a short summary of each show on the Snort Blog
- MS "Black Tuesday" produces two matches, Internet Explorer Cumulative Patches (MS05-054), and MS05-055
- Microsoft Windows firewall vulnerability, patch available for download (not via Windows Update)
- Firefox users have been more savy, IE users are more likely to click on links
- Dell is including Firefox on pc's in UK
- "Return of the Land Attack" , many devices vulnerable, WRT54g, Cable Modems, Ingress filtering!! Ingress Filtering!!!, Using Linksys in layers
- Test the LAND attack with hping and NetDude ("The Hackers Choice!")
- Ironic vulnerability of the week, AppScan QA automated vulnerability testing tool buffer overflow
- Nortel SSL VPN Web Interface Input Validation, Larry shares his thoughts
- Does anyone ever look at the list of trusted sites in your browser?
- Opera - Security bug could allow for exec of code, Google was going to buy Opera?, Is it a rumor?
- Bluetooth Widcomm driver vulnerability allows remote attacker to inject audio and enable mic
- Paul Sings The Italian Christmas Donkey song
- The Do's and Don'ts of Picking up a girl in a computer lab
- Schneier's blog post on Airport Security

Software Releases:
- Nessus 3.0, faster, free not open-source, less false positives?
- Metasploit 3.0 Alpha Release 1

Tool of the week - libPJL from the Phenoelit group, also check out Paul's printer audit script

Wireless word of the week - WPA-PSK (Wi-Fi Protected Access-Pre-Shared Key) - Offers great security, GRC Password generator is great, protect your key

Hosts: Larry Pesce, Paul Asadoorian
Email: psw@pauldotcom.com

Direct Download Link

(Bandwidth provided by OSHEAN, like WuTang, they ain't nuttin' to f*** wit')

December 12, 2005

PaulDotCom Security Weekly - Episode 6 - Dec 9, 2005

This was our first podcast to use Skype. We like it. Also, the audio quality should be much better, we read the manuals to all our equipment, and watched a fantastic video on Skype podcasting from the guys at Friends In Tech, you can download it here.

- Firefox DoS Vulnerability

- Cisco IOS under attack, again

- More on podjacking, how to deal with it

- Black Tuesday is coming, previews here

- Podcasting added to Oxford dictionary

- Sober analysis from Lurhq

- Social Engineering Aim Worm

- Sharing stories about people still running windows 95/98

- Stopping filesharing in hotel networks with social engineering

- Check out Security Now!

- Sophos Threat Report was released this week

- Paul found an evil OS X site

- Paul went on a Mac rant

- Gifts for the security professional

- Syngress publishes the "How to steal an identity" book

Hosts: Paul Asadoorian, Larry Pesce, "The Mason"

Email the entire PaulDotCom Security Weekly Crew at psw@pauldotcom.com

- Tools Of The Month - New Nmap release, New MwCollect released, Rootkit revealer has been updated, and iwar war-dialer. Remote Rogue Network Detection

- Wireless Word Of The Week - Wireless Vulnerabilities and Exposures

Direct Download Link

(Bandwidth provided by OSHEAN, they're good, like beer)

December 05, 2005

PaulDotCom Security Weekly - Episode 5 - Dec 2, 2005

NOTE: By episode #227 we should have all of the audio problems worked out. Until then, please except our deepest apolgies for the audio quality. We learn more each time, but then we drink and somehow go backwards.

Also, if someone has a diagram/description of a good audio setup for a recording to a video camera and a laptop, we could use it.

- We promise not to talk about Sony DRM and IE. Okay, so we do anyway, but not as much.
- Paul is paranoid about Sony, IE PoC exploit is given birth to new trojan
- Hijack a podcast, Please don't hijack us, basically done by spoofing the feed URL of podcast and listing it on itunes and others
- Apple OS X Security Updates, Safari has bugs, Paul is lazy still on Panther, email him to harras him, No Java fixes for Panther, Hopefully Paul doesn't get rooted?
- Mozilla Firefox 1.5, Contains bug/Security fixes, GO GET IT!, Paul & Larry like the "Page not found with "Try Again" button" feature
- Cisco http cross site scripting, DO NOT manage routers using HTTP or TELNET, do use TACACS+ and SSH
- Cisco Security Agent has local privilege escelation exploit, oh the irony!
- Perl Format string exploit, Fundimental flaws in perl stemming from format string vulnerabilities in printf functions. H.D Moore has been seen posting about these issues, so look for Metalsploit updates, may cover more than just "miniserv.pl"

- Speaking of exploit frameworks, here's the top three:

- Metasploit - Perl-based, open-source exploit framework

- CANVAS - commercial, python based, exploit framwork. More features that metasploit, commercial support, etc..

- Core Impact - Commercial, Python Framework runs in windows-only, highly automated, shell code acts as a proxy to own more hosts

- Larry has a small font..
- Core Force is a new Endpoint Security Framework from Core Security. Its still in beta, and has malware prevention.
* Beer is Magic Hat #9 and tastes so much better from the Keg (party at Larry's house next week, details to follow...)
- Exploits available for MS 05-051, 05-053, get em' while their hot. Patching helps.
- Update your java, new JREs released
- What really grinds Paul's Gears - 180solutions suing Zone Labs stating they are a marketing company and not spyware
- Sobering return from Holiday weekend, 1 in 14 emails on the internet is a virus
- SANS Top 20 has been updated to clean-up language (threat vs. vulnerability), OS X called out in top 20, wake up call for OS X users. OS X is hackable, send Paul email for shellcode/exploit site.
- New Orleans launches free Wireless, is Rhode Island doing the same? (I guess it makes sense, you could cover RI with like 2 access points :)
- Wiretapping, Signaling vulnerabilities in wiretapping systems, C-Tone will fake the hang-up, read paper here
- Cracking Safes with thermal imaging, Scrambling LCD Keypads are a good defense

- Tools Of The Month, NTP OS finger printing and DHCP fake

- Wireless Word Of The Week, WRT54G, series 5 now run VxWorks, WRT54GL is the latest linux hacking version

Direct Download Link

(Bandwidth provided by OSHEAN, they got skillz)

November 27, 2005

PaulDotCom Security Weekly - Episode 4 - Nov 25, 2005

Black Friday Edition

- Another 0-day IE exploit has been released, no patch yet, but M$ has acknowledged it
- Paul put up the Frsirt version of a working POC that starts calc.exe
- Use Firefox, or go straight to the bleeding edge with Flock, integrates del.icio.us bookmarks and blogging to the web browser
- Check out Paul's Asparagus recipe collection
- Sony Bashing Round 3, Amazon calls them "Defective", $SYS$ T-Shirts, Sony has ninjas, Tape can bypass DRM, M$ Anti-Spyware will remove, Create canary file called "$sys$[something].txt" and if it goes away you have the Sony Rootkit (I call mine "$SYS$F-Sony.txt")
- Xbox360, crashing, Get metal sticks to hack
- Richard Stallman gets in trouble for wearing tin foil hats
- Lexus IS pedal sequence disables traction control
- M$ has a new security tool called "Windows Live Safety Center". Tells you about things like open ports, hard drive defrag notification, email us with feedback if you've used this tool
- New SANS Top 20 released this week
- TAOSecurity Blog, Good and Bad about the sans top 20, new book available at amazon called "Extrusion Detection", Security Awareness training not effective?
- Shadow Crew busted and pleaded guilty
- Exploiting the stack series from Security Compass
- To kill or not to kill...a pix, Remote DoS Vulnerability, Exploit Available, Workarounds available
- OSSRC, ("Open Source Snort Rules Consortium") created to make snort rules better
- Symantec to stop selling LC5 outside US, use Cain instead
- Twofish rumored to be crackable
- Sign up for Schmoocon 2006 ("Bow To My Firewall")

- Tool Of The Week - John the Ripper - Password cracking tool, run the auto on debian install for Debian auto account audit, and use the something option to generate really good password dictionaries ("-rules" option).

- Wireless word of the week - EAP-TTLS (Extensible Authentication Protocol - Tunnel Transport Layer Security) - Requires only a server certificate, uses SSL tunnel for encryption, works with OS X built-in client, Windows client available called SecureW2, CIsco ACS is bad

Direct Download Link

(Bandwidth provided by OSHEAN, they're the opposite of Sony and IE)

New Album Art:
pswlogo.png

November 21, 2005

PaulDotCom Security Weekly - Episode 3 - Nov 18 2005

Episode 3 is now available! Video should be coming early this week, so check back. Show notes:

- Paul realized creative control and started M$ IE bashing (IE sucks!)
- PC World 100 best product 2005 ! Firefox #1 Go install Firefox Now!
- Sony rootkit (DRM) madness, Amazon recalls CDs, Uninstaller ActiveX has flaws, Bleeding Snort sigs for Sony DRM
- Docs Para, Don Cominsky reverse query Sony DRM Infection Map
- Multi-vendor IPSec vulnerabilities, Cisco advisory, PaulDotCom Blog posting, Full Listing of vulnerable products from Security.nnov
- Vulnerabilities in Wifi phones, Cisco IP 7290, PaulDotCom Blog Posting, Others
- Google Bids To Give Mountain View Wi-Fi
- Everyone should register for my SANS course
- Blackhat 4 sale
- Windows RPC DoS, Originally thought you needed good credentials, apparently you may not
- From PacSec05 - "Using Neural Networks for remote OS Identification"
- MSNBC only run trusted code, CIA/KGB rant, Larry has gas
- Plain text passwords database from SCinet
- Got a Kidney to sell? Latest spam "Sell your organs online"
- WPA-PSK pass-phrase generator from Steve Gibson
- Go listen to Friends In Tech, and In The Trenches

Hosts: Larry Pesce, Paul Asadoorian
Sound/Video: Andrew Veitch, Nick DePetrillo

Direct Download Link

(Bandwidth provided by OSHEAN, they rock)

Much thanks to our sponsor:

kungfushrimp.gif

"Without Shrimp, its just Kung Fu"

November 13, 2005

PaulDotCom Security Weekly - Episode 2 - Nov 11, 2005

Our second episode has been released! We've got a whole new audio setup and sounding pretty better than ever (although that's not saying much). Here are this weeks show notes/topics:

- We beat the Sont DRM horse a few times because, well, we were the only ones who hadn't yet
- You can get a list of CD's that have the rootkit HERE
- We covered the MS05-053 exploit
- Botnets that use HTTP/HTTPS, presentation HERE
- Tracking MIT Students
- Sniffing passwords and clear text protocols, from the excellent blog by Bruce Schneier
- The overrated Linux Worm
- Fun (and profit) with Rainbow Tables

Direct Download

(Bandwidth provided by OSHEAN, they rock)


Hosts: Larry Pesce, Paul Asadoorian
Sound: Andrew Veitch

.com

November 04, 2005

PaulDotCom Security Weekly - Special Edition - Marty Roesch Interview

We are proud to bring you our second podcast, an exclusive interview from SANS 2005 in LA with Marty Roesch, creator of Snort, an open-source intrusion detection system, and co-founder/CTO of Sourcefire:

Direct Download

Marty talks about:

- The history of Snort
- Recent Back Orifice buffer overflow
- New and exciting technologies at Sourcefire
- His love for Mac (which we share)

(We apologize in advance for the poor audio quality, new equipment is on the way. If you have suggestions or comments feel free to drop me a note, paul /at/ pauldotcom.com).

Again, thanks to our sponsor OSHEAN for providing the bandwidth.

"Snort saved my bacon"

.com

October 27, 2005

PaulDotCom Security Weekly - Episode 1 - Oct 27, 2005

We recorded the first episode of "PaulDotCom Security Weekly", our new podcast. It was recorded last night at SANS LA and we talked about:

- Oracle Password vulnerabilities
- Nokia smartphone worms
- Botnets
- FBI Romanian hacking case
- Terrorism and improvised explosives
- And much more!

This episode was sponsored by Core Security - an outstanding penetration testing tool.

Direct Download

I promise future episodes will have show notes and be available via iTunes and other podcast sources. Bear with us as we put it all together :)

(Thanks to our other sponsor, OSHEAN, for providing the bandwidth)

.com

Podcast Links







401.369.9820


Home