Exploring Information Security - Exploring Information Security

Exploring Information Security - Exploring Information Security

By Timothy De BlockTechnology
Download on the App Store

Exploring Information Security - Exploring Information Security episodes

  • What is the Rural Technology Fund?

    Chris (@chrissanders88) grew up at a disadvantage. He wasn't rich or handed a great educations. He speaks of being part of the free lunch kids at school. He's managed to turn himself into a successful information security professional, with his own company and non-profit. A lot of that is due to his teachers and mentors encouraging his interest in computers. The Rural Technology Fund is a way for him to give back and give other kids an opportunity to see if they have a spark for technology.

    29 min
  • How to build your own tools - Part 2

    In this bird feeding episode of the Exploring Information Security podcast, Chris Maddalena joins me to discuss how to build your own tools.

    Chris (@cmaddalena) gave a talk at DerbyCon this past year on writing Win32 Shellcode. We've talked before on a previous podcast around why building your own tools is important. Chris has also written several tools for his day job and for public consumption. His most recent tool is ODIN, a passive recon tool for penetration testers.

    In this episode we discuss:

    • Why should someone build their own tool

    • What tool should people build?

    • How to get started building tools

    • What resources are available for building tools

    [RSS Feed] [iTunes]

    Subscribe

    Sign up with your email address to receive news and updates.

    Email Address
    Sign Up

    We respect your privacy.

    Thank you!
    19 min
  • How to build your own tools - Part 1

    In this bird feeding episode of the Exploring Information Security podcast, Chris Maddalena joins me to discuss how to build your own tools.

    Chris (@cmaddalena) gave a talk at DerbyCon this past year on writing Win32 Shellcode. We've talked before on a previous podcast around why building your own tools is important. Chris has also written several tools for his day job and for public consumption. His most recent tool is ODIN, a passive recon tool for penetration testers.

    In this episode we discuss:

    • Why should someone build their own tool

    • What tool should people build?

    • How to get started building tools

    • What resources are available for building tools

    [RSS Feed] [iTunes]

    Subscribe

    Sign up with your email address to receive news and updates.

    Email Address
    Sign Up

    We respect your privacy.

    Thank you!
    26 min
  • What is the Orange Team?

    In this colorful edition of the Exploring Information Security podcast, April Wright joins me to discuss the orange team.

    April (@aprilwright) and I met earlier this year at ShowMeCon. She shared with me the concept of the Orange Team. Which is an idea around the security (blue) team working more closely with the development (yellow) team. I loved the idea and wanted to hear more. She spoke about the topic at BlackHat and DefCamp. Unfortunately, the recordings of her session haven't been released yet. So, I decided to have her on to discuss in more detail.

    In this episode we discuss:

    • What is the orange team
    • How did the idea come about?
    • What are the activities of the orange team?
    • Who should participate

    [RSS Feed] [iTunes]

    31 min
  • How to secure NodeJS

    In this protuberance episode of the Exploring Information Security podcast, Max McCarty joins me to discuss how to secure NodeJS.

    Max (@maxrmccarty) has a great course called Securing Your Node.Js Web App available on Pluralsight. The course is five and a half-hours long, walking through the basics on security. Security for NodeJS is not unlike security for other languages and technologies. If you can secure other web apps you can secure NodeJS.

    In this episode we discuss:

    • What is NodeJS
    • How Max got started in NodeJS
    • Why it's important to secure NodeJS
    • How to secure NodeJS

    More resources:

    • OWASP
    • How to enable HTTP Strict Transport Security (HSTS) in IIS7+

    [RSS Feed] [iTunes]

    31 min
  • What is the Node Security Platform?

    In this devtastic episode of the Exploring Information Security podcast, Adam Baldwin joins me to discuss the Node Security Platform (NSP).

    Adam (@adam_baldwin) is the team lead at Lift Security and founder of the Node Security Platform. NSP is one of the simplest tools to put into a development life cycle for NodeJS. It checks for vulnerable packages in an environment during pull requests or builds. This allow developers to quickly and easily identify packages that put their applications at risk.

    In this episode we discuss:

    • What is nsp?
    • How it should be used?
    • Where it should be used?
    • How to use it.

    Resources:

    • Nodesecurity.io
    • Rising Stack

    [RSS Feed] [iTunes]

    30 min
  • Why we need to get outside the infosec echo chamber

    In this bouncy edition of the Exploring Information Security podcast, I talk about getting outside of the information security echo chamber.

    Getting outside of the infosec echo chamber is something I've wanted to do for the past year. Spending time at infosec events is important for a career. It's great for networking and knowledge sharing. We need to do those same things at non-infosec events. For me that means getting out to developer events. I am speaking at Nodevember at the end of November 2017 and also at CodeMash in early January 2018. For better security I think it's a crucial activity.

    In this episode I discuss:

    • What is the echo chamber?
    • Why it's important to get outside of it
    • Who should get outside the echo chamber
    • Where to get outside the echo chamber

    [RSS Feed] [iTunes]

    12 min
  • How to hack a car

    In this speedy episode of the Exploring Information Security podcast, Brandon Wilson joins me to discuss his adventures in hacking a car.

    Brandon (@brandonlwilson) spoke at BSides Knoxville in 2017. I had the pleasure to be in attendance for his talk. The talk was technical and very interesting. Brandon talked about how he tried to take his old 90s car and fix it himself. The was a malfunction in the anti-theft system that kept the car from running. He decided to go deeper. Unfortunately, he was unable to fix his car. He did, however, learn a lot from the experience.

    In this episode we discuss:

    • How Brandon got into car hacking?
    • What resources were available for hacking a car?
    • How long did the project take?
    • What tools are available for hacking a car?

    [RSS Feed] [iTunes]

    26 min
  • How to implement the CSF from NIST

    In this skeleton edition of the Exploring Information Security podcast, I discuss the Cybersecurity Framework (CSF) from NIST with Rick Tracy the CSO at Telos.

    Rick (@rick_tracy), is very passionate about the CSF from NIST. The framework is meant to help organizations become more mature from a security standpoint. The CSF provides guidance on implementing security controls and countermeasures. It's not meant to be a one size fits all framework, but something that each organization can cater to their organization.

    In this episode we discuss:

    • What is NIST?
    • What is the Cybersecurity Framework?
    • Why it's important
    • How organizations implement the framework

    More resources:

    • Cybersecurity Framework - Industry Resources
    • Xacta 360

    [RSS Feed] [iTunes]

    31 min
  • What is the OWASP Threat Dragon?

    In this fire-breathing edition of the Exploring Information Security podcast, I talk to Mike Goodwin the project lead of the OWASP Threat Dragon.

    Mike (@theblacklabguy) joins me to discuss his OWASP project Threat Dragon. The project is meant to give developers an easy use tool for performing threat modeling. The project is built on NodeJS and AngularJS. It has a slick easy-to-use interface and Github integration. His roadmap for the project include Bitbucket integration and a rule engine that will help with threat modeling.

    In this episode we discuss:

    • What is threat modeling?
    • What led to the idea of Threat Dragon?
    • How does someone get started with the tool?
    • What's the effort on a project like this? (mike[dot]goodwing[at]owasp[dot]org to help)

    More resources:

    • Threat Modeling: Designing for Security by Adam Shostack

    [RSS Feed] [iTunes]

    29 min

About Exploring Information Security - Exploring Information Security

From the publisher's feed

The Exploring Information Security podcast interviews a different professional each week exploring topics, ideas, and disciplines within information security. Prepare to learn, explore, and grow your…

More shows like Exploring Information Security - Exploring Information Security

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,054 Listeners