Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

By Jerry Bell and Andrew KalatNewsTechnologyBusiness NewsTech News
Download on the App Store
  • Ranking

    49th

    on Tech News

  • Favorites

    384

    Followers

  • Typical duration

    60 min

    per episode

Based on Podcast App listening data

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec episodes

  • Defensive Security Podcast Episode 10
    Feedback/comments - [email protected]
    @defensivesec

    Interesting Writeup by ESET on sink holing the zortob.b botnet http://www.welivesecurity.com/2013/03/08/sinkholing-trojan-downloader-zortob-b-reveals-fast-growing-malware-threat/
    - common phishing emails emanating from it at the rate of 80m per hour

    Ryan Naraine interviewed VUPEN CEO: http://www.securityweek.com/podcast-vupen-ceo-chaouki-bekrar-addresses-zero-day-marketplace-controversy-cansecwest
    - all browsers and all plugins have vulnerabilities

    Results of the pwn2own contest: http://nakedsecurity.sophos.com/2013/03/08/pwn2own-results-day-two-adobe-reader-and-flash-owned-java-felled-yet-again/

    Firefox - owned
    IE10 - owned
    Chrome - owned
    Flash - owned
    PDF reader - owned
    Java - owned x4

    Suggestion to limit exposure to malicious web sites: block "uncategorized" sites - will catch new sites which are often recently set up exploit distribution sites.

    Listen to the Secure Ideas podcast: http://secureideas.libsyn.com/rss

    Good stuff!

    Follow-up on Evernote breach: passwords md5 hashed and salted
    - better than others, but still not great
    - md5 was built for performance, and GPU accelerated cracking can check hundreds of millions of passwords per second
    - been some discussion about using a more expensive hash like bcrypt, but more expensive means it's easier to DOS a web app, because it is by definition more computationally intensive.
    I reject this - thousands of operations can be performed per second, and unless the app is badly designed, the server should not see anything like that - remember the hash operation will only need to happen ONCE when someone attempts a login, and ONCE when the password is reset. Certainly very busy sites may have thousands of login/password operations simultaneously, but those will generally be split across many sites, anyhow.
    But the argument is a bit of a paper tiger anyhow
    - if it's the responsible thing to do, we should do it
    - SSL takes extra CPU power too, but the infosec community seems to have little sympathy for anyone who complains about that.

    15 min
  • Defensive Security Podcast Episode 9
    Episode 9 - From Las Vegas
    Comments/questions/hate mail to [email protected]
    Follow podcast on twitter @defensivesec

    DDOS attack on Bank of the West masked a $900,000 theft from the account of Ascent Builders. http://krebsonsecurity.com/2013/02/ddos-attack-on-bank-hid-900000-cyberheist/

    Bible.org- https://isc.sans.edu/diary/When+web+sites+go+bad%3A+bible+.+org+compromise/15250
    Site compromised - serving malware, had rudimentary defense against automated analysis

    Bit9 update: https://blog.bit9.com/2013/02/25/bit9-security-incident-update/
    - kudos to bit9 for transparency and disclosure - hopefully works in their favor

    New java 0day http://www.symantec.com/connect/blogs/latest-java-zero-day-shares-connections-bit9-security-incident payload signed by stolen bit9 cert

    Meant to cover last week - Facebook, apple and Microsoft hacks tracked back to a java 0 day being served on iphonedevsdk.com - the site owners were made aware by reading a news article on All Things D about the Facebook hack http://iphonedevsdk.com/forum/site-news-announcements/111889-iphonedevsdk-compromised-what-happened-and-how-we-are-dealing-with-it.html

    Hard to say if watering hole attacks are getting more common, or if we just hear about them more in the current sensitized media.
    This does highlight, as I mentioned in the last podcast, the dangers of browsing even "legitimate" sites. At a bare minimum, everyone ought to be using a web filtering solution to block known malicious sites - it's not perfect and might not protect those who visit a site right after it is infected, but it will often prevent a lot of infections in 0 day scenarios

    Reducing surface area of vulnerability, for instance, by not having Flash, PDF reader or Java, is beneficial, but there are so many components susceptible to attack (including the browser itself).
    We should be thinking about how we isolate risky activities from key business applications and data.
    This includes email - key lesson from the Mandiant APT1 report is the prevalence of using email as an attack vector.

    A version of Mandiant's APT report was being emailed around bundled with the latest PDF reader 0 day exploit. https://isc.sans.edu/diary/Fake+Mandiant+APT+Report+Used+as+Malware+Lure/15226

    Kelihos botnet taken down live before an audience at RSA http://threatpost.com/en_us/blogs/latest-kelihos-botnet-shut-down-live-rsa-conference-2013-022613

    Miniduke http://au.news.yahoo.com/thewest/business/a/-/tech/16259582/hackers-target-european-governments-researchers/

    Phishing strategy - addressing to other addresses at the same domain - training says to not open attachments that you are not expecting, but this illicits curiosity by the recipient.

    Symantec announces a variant of stuxnet from 2005 http://news.cnet.com/8301-1009_3-57571384-83/new-stuxnet-whodunit-malware-existed-two-years-earlier-than-anyone-knew/
    Cnet seems to not be aware that the US claimed responsibility and is investigating the leak

    EverNote password database stolen - emails and salted/hashed passwords http://krebsonsecurity.com/2013/03/evernote-forces-password-reset-for-50m-users/

    If you have not gotten the hint that you should be using a different password for EVERY service and web site you use, this is for you!

    There are many great password managers, some that will sync across devices. Use them - set them to create long passwords (15-20 characters or more), since you're not going to be able to remember all of the passwords anyway. And most of the password managers will copy passwords to the clip board so you don't have to type them in, either.
    31 min
  • Defensive Security Podcast Episode 8
    News:
    Burger King & Jeep twitter accounts hacked
    Microsoft and Apple hacked with same exploit that hit Facebook
    NBC.com’s site is hacked, injecting an iframe directing visitors to a site that served an exploit kit and installed the Citadel trojan.
    Bit9 hack started in July 2012

    * Bit9 released hashes
    * Krebs search of VT turned up some malware compiled in July 2012
    * Bit9 indicates that the compromise was the result of an employee starting up an old virtual machine.  Additional details are apparently going to be released on Bit9’s blog next week.

    Risk from business partners/suppliers:

    * Zendesk hacked and leaked client info for Twitter, Pinterest & Tumblr
    * CPanel hacked and leaked root passwords for client servers

    Lessons:

    * Vendors are a risk – their vulnerabilities & security practices have a material impact on your business.

     
    APT1:

    * Focus on the tactics, not the motives
    * Entry gained via spear phishing emails
    * Implemented remote access trojans
    * Stole credentials, moved throughout victim networks and systems

    Lessons:

    * A lot can be learned through forensic investigations
    * We need to come to terms with the problems:

    * Humans are susceptible to phishing
    * We can’t control whether web sites serve up exploits
    * AV is not effective at catching serious threats
    * Constant stream of 0 days


    * What can we do to address this?  2 Main options:

    * Avoidance

    * Do not permit the things that are problematic from entering your environment:

    * Block Internet access
    * Don’t permit email
    * Force “dangerous” activities to happen on systems that do not have access to anything sensitive (this includes email)
    * Work PC becomes a terminal for interfacing with internal apps & systems only
    * Completely heretical, but effective




    * Minimization

    * Minimize the opportunity for successful attacks:

    * Application white listing
    * Strict web filtering
    * Isolation of activities into virtual machines or VDI
    * Proactive monitoring







     
    31 min
  • Defensive Security Podcast Episode 7
    defensive security episode 7Please rate the podcast on iTunes!
    Follow me on twitter @defensivesec
    Send comments to [email protected]

    News:

    Zombie attack

    EAS at a Montana TV station was hacked
    Mad rush to point fingers at systemic weaknesses in EAS gear
    Security is too hard for smaller TV stations

    PDF exploit

    Enable protected view.

    Spear phishing using recent flash vulnerability outlined by Alien Vault and FireEye

    Word doc containing a flash object
    Attachments claim to be an IEEE conference schedule and an ADP notice.

    Mcafee portal defaced

    Presidential policy directive 21 issued

    Charges the government to identify the scope of critical infrastructure organizations
    A key piece of the executive order is requires federal agencies overseeing critical infrastructure areas to identify organizations "where a cybersecurity incident could reasonably result in catastrophic regional or national effects on public health or safety, economic security, or national security."
    The order doesn't compel designated companies to comply with new standards, but it's expected that a lot of pressure will be applied to those who don't.

    Lockheed Martin describes its response to an attempted attack after the RSA breach.

    LM has a sophisticated strategy for detecting improper activity, particularly data access and exfiltration attempts.
    You are probably not LM, neither am I

    Facebook announces it was hacked

    Facebook's monitoring of DNS queries on its network showed lookups of a 'suspicious' domain
    That lookup prompted the pc which made the request to be inspected
    The pc was found to be infected with malware
    A forensic analysis of the system showed the infection came via a zero day java exploit on a mobile developer web site
    What they did right:
    Have proactive monitoring in place
    Pay attention to the proactive monitoring
    We're able to track down the offending system
    Took the infection seriously and thoroughly investigated the infection
    Had previously performed fire drills that let this activity happen more easily

    13 Security Myths Debunked
    28 min
  • Defensive Security Podcast Episode 6
    Suggestions to [email protected]
    News:

    * ISD Podcast shuts down
    * Noticeable uptick in phishing attacks recently, leading to various exploit kit web sites
    * Yet another Java update.  Oracle seems to have gotten the message.
    * Combofix, a free tool for removing certain kinds of malware, was infected with Sality

    * Do not download repackaged software from other file hosting sites.  Bad!


    * Cisco released it’s 2013 security report.

    * Legitimate sites much more likely to be malicious than traditional pornography
    * Ad networks and content delivery networks worst offenders


    * Anonymous stole information on 4600 bank executives from a Federal Reserve emergency communication application.

    * Fed seems to be downplaying the significance.



    US Sentencing Commission:

    * The US Sentencing Commission web site has been repeatedly hacked by Anonymous in protest of the suicide of Aaron Swartz. The site was defaced with a video and offered some encrypted files for download, with a threat to release the decryption keys if reforms to the CFAA are not made.
    * The site was restored Saturday, but was defaced again on Sunday – with Asteroids.
    * The site was unavailable for quite some time after the second breach.
    * Apparently the site was restored, but whatever weakness it had was restored too.
    * Is it better to get the site back up fast or spend some time to figure out what happened?

    NY Times announces it has hacked

    * The NY Times reports that its IT systems had been compromised by “Chinese attackers”.
    * When the Times became aware of the intrusion, they chose to monitor the activity, rather than try to immediately close the holes

    This has some benefits, since it allows the victim to understand the extent to which their systems have been compromised, rather than tipping off the intruder by starting to remediate systems piecemeal.

    * NYT contracted Mandiant to investigate
    * The attackers were routing traffic through compromised hosts in US universities
    * The apparent method of entry is spear phishing
    * 45 pieces of malware
    * Symantec lashed out at the Times article
    * The attackers appeared to be interested in determining who provided an NYT reporter with some salacious information about Wen Jiabao, China’s prime minister.
    * Lots of criticism about the report

    * Reference to rainbow tables shows the author isn’t a security pro
    * China APT seems to be involved in every investigation Mandiant investigates
    * Lack of details
    * Makes the attack seem highly sophisticated
    * I do agree that there is nothing spectacular about this attack – just about anyone with good knowledge of metasploit and SET could pull this style of attack



    The timing of the attack certainly is interesting, given the proximity to the story about the FBI searching for...
    29 min
  • Defensive Security Episode 2
    Episode 2 covers the State of South Carolina data breach and NASA's stolen laptop. Show notes are available here: http://www.defensivesecurity.org/defensive-security-episode-2
    15 min

About Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

From the publisher's feed

Defensive Security is a weekly information security podcast which reviews recent high profile cyber security breaches, data breaches, malware infections and intrusions to identify lessons that we can…

Best of Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

Ranked by our users in the last 21 days

More shows like Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

Hacked by Hacked

Hacked

193 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

286 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Software Engineering Daily by Software Engineering Daily

Software Engineering Daily

624 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,064 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

180 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

191 Listeners

Practical AI by Daniel Whitenack and Chris Benson

Practical AI

202 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

139 Listeners

The AI Daily Brief: Artificial Intelligence News and Analysis by Nathaniel Whittemore

The AI Daily Brief: Artificial Intelligence News and Analysis

682 Listeners