
Sign up to save your podcasts
Or


In this holiday edition of the Exploring Information Security podcast, Ed Skoudis joins me to discuss the SANS Holiday Hack Challenge.
Around this time each year the SANS Holiday Hack Challenge releases under the direction of Ed (@edskoudis) and instructor with the SANS institute. This year Santa has been kidnapped and it’s up to use to figure out who did it and save Christmas. The challenge is for new people in infosec, and for those who have been in the industry for many years. As Ed notes in the episode it is even for children. The challenge itself has been around for years and several past years are still available for people to go through.
In this episode we discuss:
What is the SANS Holiday Hack Challenge
How it got started
What preparation goes into making the challenge each year
Who can participate
[RSS Feed] [iTunes]
In this epic episode of the Exploring Information Security podcast Jayson E. Street (@jaysonstreet), Dave Chronister (@bagomojo), Johnny Xmas (@J0hnnyXm4s), April Wright (@aprilwright), Ben Brown (@ajnachakra), and surprise guests Adrian Crenshaw (@irongeek_adc) and Kevin Johnson (@secureideas)all join me to discuss various security related topics.
ShowMeCon is one of my favorite security conferences. The organizers are awesome and take care of their speakers like no other conference. The venue is fantastic. The content is mind blowing. I can't say enough good things about the even that Dave and Renee Chronister put on every year in St. Louis, Missouri. They know how to put on a conference.
Regular listeners of the podcast will note that I recorded an episode with Dave on ShowMeCon several weeks ago. After that recording he asked if I was interested in doing a recording at the conference. I said yes and thus the birth of this epic episode. This format is experimental. First, it is marked as explicit, because there is swearing. Second, It's over 90 minutes long. I didn't think breaking it up into four or five pieces would serve the recording well. Send me your feedback good or bad on this episode, because I'd like to do more of these. I would really like to hear it for this episode.
In this episode we discuss:
Certificates
Hiring
Interviewing
Where to get started
Soft skills
ShowMeCon and other conferences
Community and giving back
Imposter syndrome
Irongeeks impact on those in attendance
[RSS Feed] [iTunes]
In the refreshed edition of the Exploring Information Security (EIS) podcast, I talk to Amanda Berlin AKA @Infosystir about security awareness.
Amanda was charged with setting up a security awareness program for her company from scratch. Setting up a security awareness program is hard work, making it effective is even harder, but Amanda rose to the challenge and came up with some creative ways to help fellow employees get a better handle on security.
In this interview we cover:
What is security awareness?
How a security awareness program should be implemented.
What does an effective security program look like?
How do you measure the effectiveness of a security awareness program
[RSS Feed] [iTunes]
In this episode, Dave Chronister, founder of Parameter Security and ShowMeCon, shares valuable insights into the world of penetration testing (pentesting). Listeners will learn about the differences between vulnerability assessments and penetration tests, what red teaming is, and why organizations should lean towards white-box pentests. Dave and Tim discuss how to avoid common pitfalls when engaging with pentest companies, the importance of rules of engagement, and how to ensure you're getting a high-quality test. Dave also shares stories from his 17+ years in the field, illustrating the critical lessons organizations need to understand.
Key Topics Covered:Difference between vulnerability assessments and penetration tests.
Red teaming vs. penetration testing: When and why to use each.
How to choose the right pentest company.
The importance of setting clear rules of engagement.
Real-world examples of pentesting gone wrong.
Parameter Security
ShowMeCon
Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this timely episode of Exploring Information Security, host Timothy De Block is joined by Pieter Arntz from Malwarebytes to discuss the growing threat of election-related scams. With election season upon us, scammers are becoming more active, and this episode dives deep into how these scams work, what tactics scammers use, and how to protect yourself from falling victim.
You can check out Pieter’s article How To Avoid Election Related Scams at the Malwarebytes blog.
Key Topics:Seasonal Scams: Scams are often timed with key events, including elections, holidays, and tax season. Pieter discusses how scammers shift focus from elections to events like Black Friday or Christmas.
Common Election Scams: Scammers often target voters through text messages, social media, and robocalls, attempting to steal personal information or solicit fake donations.
Mobile Devices as a Target: With more focus on mobile devices, Android and Apple users are increasingly targeted through phishing texts and malicious links.
Social Engineering: Scammers manipulate users by pretending to represent political parties, asking for donations, or engaging in online discussions to steal information.
Detecting Scams: Pieter and Timothy offer practical advice on identifying scam messages, such as unsolicited communications, urgency in messaging, and phishing links with suspicious domains (e.g., .xyz, .top).
Who’s Behind These Scams?: The episode touches on the actors behind the scams, ranging from cybercriminal gangs to state actors, and how they profit from fraudulent activities.
Scams Beyond Elections: While elections are a prime target, natural disasters and other events are also exploited by scammers to steal donations and personal information.
Privacy Concerns: A survey revealed that 3% of people are hesitant to vote due to privacy concerns, highlighting the critical need for secure election processes.
Be Wary of Unsolicited Messages: If you receive unsolicited texts or emails, always double-check the source before acting. Election scams often use urgency to push people into making hasty decisions.
Verify Political Donations: Only donate through verified websites. Scammers frequently clone official websites to trick people into giving money to fraudulent causes.
Protect Your Personal Information: Avoid sharing personal details through unofficial or unfamiliar channels. Scammers can use this information for identity theft or phishing attacks.
Report Scams: If you suspect a scam, report it to organizations like the FTC or the FBI to help others stay safe.
Report Fraud – Federal Trade Commission’s fraud reporting site.
Do Not Call Registry – Sign up to reduce unwanted calls.
National Association of Secretaries of State – Provides resources on election security.
FBI Alerts – Stay updated on the latest scams from the FBI.
Election season raises fears for nearly a third of people who worry their vote could be leaked - MalwareBytes Labs
Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this episode, Jennifer VanAntwerp shares her journey of sobriety and how it inspired her to create the Sober in Cyber community. They discuss the challenges of navigating industry events saturated with alcohol, tips for staying sober, and how the younger generation's attitude towards alcohol is changing. Jennifer also emphasizes the importance of offering alternative options at events and how the sober community is growing in cybersecurity.
Key Topics Covered:Jennifer's personal journey of 23 years of sobriety.
The impact of alcohol at cybersecurity conferences.
Tips for avoiding pressure to drink at social events.
The role of Sober in Cyber in creating inclusive, alcohol-free spaces.
How companies can support sober individuals.
Sober in Cyber
Mental Health Hackers
Join the Sober in Cyber Discord community to connect with others in the industry who are sober or looking to reduce alcohol consumption
Follow Sober in Cyber on social media for updates on events and community resources
Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this episode, Timothy De Block chats with Renee DiResta about the role of disinformation in elections, particularly as we approach the 2024 cycle. Renee discusses her work in tracking narratives across social media, how state actors like Russia and Iran manipulate public opinion, and the growing importance of platform integrity in identifying inauthentic behavior.
Check out her book Invisible Rules: The People Who Turn Lies into Reality.
Key Topics:The Evolution of Propaganda: How modern disinformation connects to historical propaganda efforts.
State-Sponsored Disinformation: Tactics used by Russia, Iran, and China in shaping election narratives.
Platform Integrity Teams: How social media platforms now combat disinformation networks.
Disinformation Trends: Recurring themes in election-related rumors, such as false claims about voter fraud.
The Role of Social Media: How users, not just state actors, influence and spread misinformation.
Recommended Resources:
Digital Forensics Research Lab (DFR Lab)
Stanford Journal of Trust and Safety
Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this episode, Timothy De Block and Jonathan Singer dive into the challenges of modern enterprise security. The conversation covers how organizations—using McDonald's as an example—face threats from both digital and physical vectors. They explore how hackers might exploit everything from public Wi-Fi to social engineering tactics and touch on the evolving role of security leaders in dealing with both controllable and uncontrollable risks.
Key Topics:Digital & Physical Attack Vectors: Discussion on hacking tactics such as public Wi-Fi, kiosk vulnerabilities, API exploitation, and social engineering.
Security Beyond the Firewall: Why enterprise security involves more than just digital defense—physical security, insider threats, and brand manipulation also pose risks.
The Growing Complexity of Security: How new technologies, like IoT devices and AI, are adding layers of complexity to enterprise security.
Insider Threats & Social Engineering: The impact of internal threats, from disgruntled employees to social engineering attacks, on large organizations.
Rapid-Fire Hacking Vectors:
Public Wi-Fi
Self-service kiosks
Badge cloning
Typo-squatting for domains
Supply chain dependencies
Insider threats
Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this episode, Timothy De Block chats with Ben Burkert about the challenges of managing internal certificate authorities (CAs) and certificates. Ben shares his experiences working with internal CAs at major companies and how those challenges inspired the creation of Anchor.dev.
Key Topics:The Importance of Certificates: Ben explains how certificate mismanagement can lead to outages and business interruptions, and why automation is crucial.
TLS and ACME: Understanding how TLS secures communications and how ACME clients automate certificate management.
Anchor.dev: A cloud service that simplifies internal CA management and helps companies secure their internal networks with automated renewals and distribution.
LCL Host: A tool from Anchor.dev that enables HTTPS in local development environments, improving deployment workflows.
Links:
Anchor: https://anchor.dev/
lcl.host: https://lcl.host/
ACME: https://datatracker.ietf.org/doc/html/rfc8555/
Let'sEncrypt: https://letsencrypt.org/how-it-works/
mkcert: https://github.com/FiloSottile/mkcert
NIST PQ standards: https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards
Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
This is the last week to register for Tim’s class in 2024 - go to https://www.practisec.com/events/ to get signed up.
In this educational edition of the Exploring Information Security podcast, Tim Tomes joins me to discuss Practical Web Application Pentration Testing (PWAPT) training.
Tim (@LaNMaSteR53) is one of the leading names within the application security field. A former instructor for many organizations, he wanted to do more with training. He wanted to provide attendees to training with more hands on work. Get into an application, exploit it, and then provide remediation steps. He came up with the PWAPT training.
In this episode we discuss
How the idea for the training came about
Why the training is important
Who should attend the training
What makes this training unique
[RSS Feed] [iTunes]
From the publisher's feed

373 Listeners

1,029 Listeners

8,059 Listeners