<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2enclosuresfull.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.andrewallen.co.uk/~d/styles/itemcontent.css"?><rss xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:yt="http://gdata.youtube.com/schemas/2007" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
   <channel>
      <title>andrewallen/podroll</title>
      <description>FEED: http://feeds.andrewallen.co.uk/andrewallen/podroll</description>
      <link>http://pipes.yahoo.com/pipes/pipe.info?_id=15b6944e85f1ad306a6556d23d418502</link>
      <pubDate>Thu, 18 Mar 2010 18:34:33 -0700</pubDate>
      <generator>http://pipes.yahoo.com/pipes/</generator>
      <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.andrewallen.co.uk/andrewallen/podroll" /><feedburner:info uri="andrewallen/podroll" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><meta xmlns="http://pipes.yahoo.com" name="pipes" content="noprocess" /><item>
         <title>@2600: Off The Hook show for March 17, 2010</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/OecuNZsQxw8/</link>
         <description>&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;&lt;img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/OecuNZsQxw8" height="1" width="1"/&gt;</description>
         <author>oth@2600.com (Emmanuel Goldstein et.al.)</author>
         <guid isPermaLink="false">oth20100317-hq</guid>
         <pubDate>Wed, 17 Mar 2010 18:00:00 -0700</pubDate>
         <media:content samplingrate="22.05" url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/T-34IgCautY/off_the_hook__20100317-64.mp3">
            <media:rating>nonadult</media:rating>
            <media:title>Off The Hook show for March 17, 2010</media:title>
         </media:content>
         
      <feedburner:origLink>http://www.2600.com/offthehook/</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/T-34IgCautY/off_the_hook__20100317-64.mp3" length="28915840" type="audio/mpeg" /><feedburner:origEnclosureLink>http://www.2600.com/offthehook/mp3files/broadband/off_the_hook__20100317-64.mp3</feedburner:origEnclosureLink></item>
      <item>
         <title>@securabit: SecuraBit Episode 52: To catch a Mule with Krebs on Security!</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/ANvH4OQgVLk/</link>
         <description>Hosts:
Anthony Gartner – @anthonygartner
Christopher Mills – @thechrisam
Chris Gerling – @chrisgerling
Jason Mueller – @securabit_jay
Andrew Borel – @andrew_secbit
Guests:
Brian Krebs &amp;#8211; @briankrebs - http://www.krebsonsecurity.com/
VRT Blog Post:
http://vrt-sourcefire.blogspot.com/2010/03/apt-should-your-panties-be-in-bunch-and.html
Eric Chien, Symantec
Zeus, King of the Bots: http://www.noryak.net/papers/zeus.pdf
Chat with us on IRC at irc.freenode.net #securabit&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;</description>
         <guid isPermaLink="false">http://www.securabit.com/?p=1339</guid>
         <pubDate>Wed, 17 Mar 2010 11:47:22 -0700</pubDate>
         <content:encoded><![CDATA[<p>Hosts:<br />
Anthony Gartner – @anthonygartner<br />
Christopher Mills – @thechrisam<br />
Chris Gerling – @chrisgerling<br />
Jason Mueller – @securabit_jay<br />
Andrew Borel – @andrew_secbit</p>
<p>Guests:<br />
Brian Krebs &#8211; @briankrebs - <a rel="nofollow" target="_blank" href="http://www.krebsonsecurity.com/">http://www.krebsonsecurity.com/</a></p>
<p>VRT Blog Post:</p>
<p><a rel="nofollow" target="_blank" href="http://vrt-sourcefire.blogspot.com/2010/03/apt-should-your-panties-be-in-bunch-and.html">http://vrt-sourcefire.blogspot.com/2010/03/apt-should-your-panties-be-in-bunch-and.html</a></p>
<p>Eric Chien, Symantec<br />
Zeus, King of the Bots: <a rel="nofollow" target="_blank" href="http://www.noryak.net/papers/zeus.pdf">http://www.noryak.net/papers/zeus.pdf</a></p>
<p>Chat with us on IRC at irc.freenode.net #securabit</p><img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/ANvH4OQgVLk" height="1" width="1"/>]]></content:encoded>
         
      <feedburner:origLink>http://www.securabit.com/2010/03/17/securabit-episode-52-to-catch-a-mule-with-krebs-on-security/</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/rua6zpb2wfc/SecuraBit_EP52.mp3" length="33169370" type="audio/mpeg" /><feedburner:origEnclosureLink>http://media.libsyn.com/media/securabit/SecuraBit_EP52.mp3</feedburner:origEnclosureLink></item>
      <item>
         <title>@tenablesecurity: Tenable Network Security Podcast - Episode 26</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/EQuRjvIWnf8/tenable-network-security-podcast---episode-26.html</link>
         <description>Welcome to the Tenable Network Security Podcast - Episode 26 Announcements Two new blog posts have been released titled "The Value Of Credentialed Vulnerability Scanning and Microsoft Patch Tuesday - March 2010 - "It Won't Happen To Me" Edition. You...&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;</description>
         <guid isPermaLink="false">http://blog.tenablesecurity.com/2010/03/tenable-network-security-podcast---episode-26.html</guid>
         <pubDate>Wed, 17 Mar 2010 05:38:23 -0700</pubDate>
         <content:encoded><![CDATA[<p>Welcome to the Tenable Network Security Podcast - Episode 26</p> <h3>Announcements</h3> <ul>
<li>Two new blog posts have been released titled "<a rel="nofollow" target="_blank" href="http://blog.tenablesecurity.com/2010/03/value-of-credentialed-scanning.html">The Value Of Credentialed Vulnerability Scanning</a> and <a rel="nofollow" target="_blank" href="http://blog.tenablesecurity.com/2010/03/microsoft-patch-tuesday---march-2010---it-wont-happen-to-me-edition.html">Microsoft Patch Tuesday - March 2010 - "It Won't Happen To Me" Edition</a>. </li>
<li>You can provide feedback to this podcast and all of our social media outlets by visiting our discussions forum and adding messages to the "<a rel="nofollow" target="_blank" href="https://discussions.nessus.org/community/social">Tenable Social Media</a>" thread. I would love to hear your feedback, questions, comments and suggestions! <a rel="nofollow" target="_blank" href="https://discussions.nessus.org/thread/2018">I put up a call for ideas on new Nessus videos</a>, so please give us your feedback!</li>
<li><a rel="nofollow" target="_blank" href="http://www.nessus.org/about/index.php?view=careers">We're hiring</a>! - Visit the web site for more information about open positions, there are currently 7 open positions listed! </li>
<li>You can subscribe to the <a rel="nofollow" target="_blank" href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=329735657">Tenable Network Security Podcast on iTunes!</a></li>
<li>Tenable Tweets - You can find us on Twitter at <a rel="nofollow" target="_blank" href="http://twitter.com/tenablesecurity">http://twitter.com/tenablesecurity</a> where we make various announcements, Nessus plugin statistics and more!</li>
</ul> <p>Interview - Ron Gula - CCDC Recap</p> <div style="text-align:center;"><img src="http://tenable.typepad.com/.a/6a00d8345495f669e20120a9427862970b-pi" alt="2010_CCDC.png" border="0" width="260" height="86"/></div> <p>Ron Gula and I discuss our experiences at the 2010 Collegiate Cyber Defense Exercise held this past weekend in Columbia, MD.<br />
</p><p><br />
<h3>Stories</h3></p> <ul>
<li><a rel="nofollow" target="_blank" href="http://www.darkreading.com/security/app-security/showArticle.jhtml?articleID=223400093&cid=RSSfeed">Six Steps To "Cloud" Security - Nothing New</a> - A researcher published a paper in the International Journal of Services and Standards titled "A 'cloud-free' security model for cloud computing". In it she outlines six security considerations for cloud computing, which to me represent nothing really new. The first, resource sharing on "cloud" providers could lead to your data being accessed. This is similar to VLANs on switches, which are essentially software, which means you need to carefully design your network to be certain your most critical assets are not on the same switch as something less critical. This is a risk decision, and should be constantly evaluated, whether you are using a "cloud" provider or designing VLANs on a switch. Second, she points out that since data is held off-site, ownership may have become compromised. This is another issue which I have dealt with when I worked for an ISP/hosting provider. Physically being separate from your data means that you need to make yet even more risk-based decisions. If the data you are hosting off-site is public anyway, then there is little need for concern. However, if the data is sensitive or confidential, you may want to take extra pre-cautions to safeguard it at remote sites (encryption, physical security, etc...). How is this different than using a remote storage facility for your backup tapes? There are more, and my advice is to look at the "cloud" security information and relate it to similar security and risk decisions in your organization and I believe you will find that you are well equipped to handle securing your organization, whether its cloudy or sunny.</li>
<li><a rel="nofollow" target="_blank" href="http://blogs.23.nu/RedTeam/2010/03/security-policy-gone-wrong/">Security Policy Gone Wrong</a> - This story centers around the following quote from a client: "Ok, how about this: We take an image of your hard drive when you enter the building. When you leave in the evening, we take another image and see what data changed. This way, we know if any sensitive data leaves the company." I like coming up with creative solutions, but this one just doesn't stick!</li>
<li><a rel="nofollow" target="_blank" href="http://www.digitalbond.com/index.php/2010/03/15/network-analysis-logitech-mouse-server/">Network Analysis Of A Logitech Mouse Server</a> - While this may not sound particularly concerning, the protocol that allows you to control the keyboard and mouse of a system running this software does not authenticate the commands. This means a packet crafting tool, such as scapy, can be used to send keystrokes to the device. Most users find this type of technology convenient, but fail to realize the security risks. In your environment you have to control the installation of this type of software.</li>
</ul> <p>(Note: Please ignore the opening when I incorrectly refer to this as episode 25, whoops!)</p> <p class="asset asset-audio at-xid-6a00d8345495f669e20120a94870bb970b"><a rel="nofollow" target="_blank" href="http://tenable.typepad.com/files/tenablepodcast-episode26-2.mp3">Download Tenable Podcast Episode 26</a></p><img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/EQuRjvIWnf8" height="1" width="1"/>]]></content:encoded>
         <category>Podcast</category>
         
      <feedburner:origLink>http://blog.tenablesecurity.com/2010/03/tenable-network-security-podcast---episode-26.html</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/y3jLMNLKB7A/tenablepodcast-episode26-2.mp3" length="0" type="audio/mpeg" /><feedburner:origEnclosureLink>http://tenable.typepad.com/files/tenablepodcast-episode26-2.mp3</feedburner:origEnclosureLink></item>
      <item>
         <title>@mckeay: Network Security Podcast, Episode 189</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/6wcLCCmQJBE/</link>
         <description>We&amp;#8217;ve been hearing about the Aurora attacks on Google and a host of other companies since early January.&amp;#160; So why is it that NSS Labs is finding that the majority of the End Point Protection (aka AV) companies aren&amp;#8217;t protecting against the vulnerability yet?&amp;#160; And why is AVG upset with NSS Labs and their testing [...]&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;</description>
         <guid isPermaLink="false">http://netsecpodcast.com/?p=450</guid>
         <pubDate>Tue, 16 Mar 2010 20:32:48 -0700</pubDate>
         <content:encoded><![CDATA[<p>We&#8217;ve been hearing about the Aurora attacks on Google and a host of other companies since early January.&nbsp; So why is it that NSS Labs is finding that the majority of the End Point Protection (aka AV) companies aren&#8217;t protecting against the vulnerability yet?&nbsp; And why is AVG upset with <a rel="nofollow" target="_blank" href="http://nsslabs.com">NSS Labs</a> and their testing methods? To answer these questions and many more, Rich and Martin were joined tonight by Vikram Phatak, the CTO of NSS Labs.&nbsp; Vik gave us some of the back story on why they were testing AV products and some of the surprising discoveries they made.&nbsp; It&#8217;s not easy being an independent testing company and sometimes you&#8217;re going to annoy people despite your best efforts.&nbsp; And sometimes people are going to be annoyed with you no matter what.</p>
<p>One point Vik wanted to make that didn&#8217;t make it into the podcast is that the 0day that was used in the Aurora attack is not just being used against corporate targets.&nbsp; It&#8217;s being used against consumers as well, so it&#8217;s important that the average home user be aware that their AV product may not be protecting them at this point.&nbsp; What is part of the podcast is a discussion of how many AV vendors are trying to protect against the payload that malware is attempting to deliver, not the exploit itself.&nbsp; Both are important points people need to be aware of.</p>
<p><a rel="nofollow" target="_blank" href="http://media.libsyn.com/media/mckeay/nsp-031610-ep189.mp3">Network Security Podcast, Episode 189, March 16, 2010<br />Time:&nbsp; 39:56</a></p>
<p>Show Notes:
<ul>
<li><a rel="nofollow" target="_blank" href="http://nsslabs.com/test-reports/NSSLabs_Vulnerability-based%20Protection-Google-EPPv14.pdf">Vulnerability-based protection and the Google &#8220;Operation Aurora&#8221; attack</a></li>
<li><a rel="nofollow" target="_blank" href="http://viruslab.blog.avg.com/2010/03/nss-labs-questionable-report.html">NSS Labs&#8217; Questionable Report</a> &#8211; Note that the screen shot shown is of the Firefox browser, not IE in any form</li>
<li><a rel="nofollow" target="_blank" href="http://nsslabs.blogspot.com/2010/03/exploits-occur-in-memory.html">AVG &amp; The Aurora Exploit</a></li>
<li><a rel="nofollow" target="_blank" href="http://nsslabs.blogspot.com/2010/03/whoosh-avg-swings-and-misses.html">Questionable Questions (and some answers)</a></li>
<li><a rel="nofollow" target="_blank" href="http://www.charlotteissa.org/">7th Annual ISSA Security Conference</a></li>
<li><a rel="nofollow" target="_blank" href="http://www.surveymonkey.com/s/RGSJ6F5">Please take our short listener survey to help us create a better podcast</a>!</li>
</ul>
<div class="zemanta-pixie"><img class="zemanta-pixie-img" alt="" src="http://img.zemanta.com/pixy.gif?x-id=7be688c6-00fb-8ec1-9dba-10293172f5a5"/></div><img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/6wcLCCmQJBE" height="1" width="1"/>]]></content:encoded>
         <media:content fileSize="38348095" url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/sBSeJHRG3SY/nsp-031610-ep189.mp3" type="audio/mpeg" />
         <category>Podcast</category>
         
      <feedburner:origLink>http://netsecpodcast.com/?p=450</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/sBSeJHRG3SY/nsp-031610-ep189.mp3" length="38348095" type="audio/mpeg" /><feedburner:origEnclosureLink>http://media.libsyn.com/media/mckeay/nsp-031610-ep189.mp3</feedburner:origEnclosureLink></item>
      <item>
         <title>@pauldotcom: PaulDotCom Security Weekly - Episode 190 - March 12, 2010</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/UTK3ZZ0OooU/</link>
         <description>&lt;p&gt;Live from CCDC!&lt;/p&gt; &lt;p&gt;&lt;a rel="nofollow" target="_blank" href="http://pauldotcom.com/wiki/index.php/Episode190"&gt;Episode 190 Show Notes&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&lt;div style="text-align:center;"&gt;&lt;img src="http://pauldotcom.com//CCDCBadgeLightup.png" alt="CCDCBadgeLightup.png" border="0" width="300" height="400"/&gt;&lt;/div&gt; &lt;p&gt;Hosts: &lt;a rel="nofollow" target="_blank" href="http://www.pauldotcom.com"&gt;Larry "HaxorTheMatrix" Pesce&lt;/a&gt;, &lt;a rel="nofollow" target="_blank" href="http://pauldotcom.com"&gt;Paul "PaulDotCom" Asadoorian&lt;/a&gt;, &lt;a rel="nofollow" target="_blank" href="http://www.pauldotcom.com"&gt;John Strand&lt;/a&gt;, &lt;a rel="nofollow" target="_blank" href="http://www.pauldotcom.com"&gt;Mick Douglas&lt;/a&gt;, &lt;a rel="nofollow" target="_blank" href="http://pauldotcom.com"&gt;Carlos "Dark0perator" Perez&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Audio Feeds: &lt;a rel="nofollow" target="_blank" href="http://pauldotcom.com/podcast/psw.xml"&gt;&lt;img src="http://pauldotcom.com/images/xml.png"&gt;&lt;/a&gt; &lt;a rel="nofollow" target="_blank" href="http://www.odeo.com/channel/38062/view"&gt;&lt;img src="http://pauldotcom.com/images/badge-channel-black.gif"&gt;&lt;/a&gt;&lt;a rel="nofollow" target="_blank" href="http://phobos.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=91472687"&gt; &lt;img src="http://pauldotcom.com/images/itunes.gif"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;&lt;img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/UTK3ZZ0OooU" height="1" width="1"/&gt;</description>
         <author>psw@pauldotcom.com</author>
         <guid isPermaLink="false">pauldotcom-security-weekly-episode-190-march-1</guid>
         <pubDate>Tue, 16 Mar 2010 19:08:26 -0700</pubDate>
         
      <feedburner:origLink>http://pauldotcom.com/</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/8xv4yJ3Kg8U/pauldotcom-SW-Episode190.mp3" length="29253381" type="audio/mpeg" /><feedburner:origEnclosureLink>http://media.libsyn.com/media/pauldotcom/pauldotcom-SW-Episode190.mp3</feedburner:origEnclosureLink></item>
      <item>
         <title>@riskybusiness: Risky Business #143 -- Cloud computing and the history of electricity</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/gl_FnWvF0cc/RB143</link>
         <description>&lt;p&gt;On this week's show we're having an extended chat with our good mate Greg Shipley. &lt;/p&gt;
&lt;p&gt;Greg's best known as the CTO of Chicago-based information security consultancy Neohapsis, and he'll be joining us to talk about what was on the agenda at the RSA conference. Apparently it's cloud, cloud, cloud... but what does that actually mean, mean, mean? Greg will be along soon to discuss, he's always good.&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_blank" href="http://risky.biz/RB143"&gt;read more&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;&lt;img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/gl_FnWvF0cc" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false">http://media.risky.biz/RB143.mp3</guid>
         <pubDate>Thu, 11 Mar 2010 21:40:43 -0800</pubDate>
         
      <feedburner:origLink>http://risky.biz/RB143</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/Chntn6TnbHU/RB143.mp3" length="20720130" type="audio/mpeg" /><feedburner:origEnclosureLink>http://media.risky.biz/RB143.mp3</feedburner:origEnclosureLink></item>
      <item>
         <title>@threatpost: Robert Hansen on Privacy and Google</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/K4bGUgnsC18/robert-hansen-privacy-and-google-031110</link>
         <description>&lt;p&gt;&lt;strong&gt;Digital Underground podcast with Dennis Fisher&lt;span class="inline inline-right"&gt;&lt;img src="http://threatpost.com/sites/default/files/images/robert_hansen_0.thumbnail.jpg" alt="" title="" class="image image-thumbnail " width="100" height="100"/&gt;&lt;/span&gt;&lt;/strong&gt; &lt;/p&gt;&lt;div class="swftools-wrapper onepixelout"&gt;&lt;div class="swftools"&gt;
 
 
 
 
 
 
 
 
 
 
 
 
 
 

 
 
 
 
 
 
 
 
 
 
 
 
 

&lt;p&gt;You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.&lt;/p&gt;

 

 
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Dennis Fisher talks with security researcher Robert “Rsnake” Hansen about how online privacy became such a mess, Google’s effect on personal privacy and the virtual impossibility of using the Internet without using Google’s services.&lt;/p&gt;&lt;p&gt;
&lt;div class="image-clear"&gt;&lt;/div&gt;&lt;p&gt;&lt;a rel="nofollow" target="_blank" href="http://threatpost.com/en_us/blogs/robert-hansen-privacy-and-google-031110"&gt;read more&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;&lt;img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/K4bGUgnsC18" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false">http://threatpost.com/en_us/sites/default/files/digital_underground_50.mp3</guid>
         <pubDate>Thu, 11 Mar 2010 11:35:28 -0800</pubDate>
         
      <feedburner:origLink>http://threatpost.com/en_us/blogs/robert-hansen-privacy-and-google-031110</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/rmB-Qnl_Xak/digital_underground_50.mp3" length="39041149" type="audio/mpeg" /><feedburner:origEnclosureLink>http://threatpost.com/en_us/sites/default/files/digital_underground_50.mp3</feedburner:origEnclosureLink></item>
      <item>
         <title>@2600: Off The Hook show for March 10, 2010</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/OecuNZsQxw8/</link>
         <description>&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;&lt;img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/OecuNZsQxw8" height="1" width="1"/&gt;</description>
         <author>oth@2600.com (Emmanuel Goldstein et.al.)</author>
         <guid isPermaLink="false">oth20100310-hq</guid>
         <pubDate>Wed, 10 Mar 2010 17:00:00 -0800</pubDate>
         <media:content samplingrate="22.05" url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/j2LJVXWizcU/off_the_hook__20100310-64.mp3">
            <media:rating>nonadult</media:rating>
            <media:title>Off The Hook show for March 10, 2010</media:title>
         </media:content>
         
      <feedburner:origLink>http://www.2600.com/offthehook/</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/j2LJVXWizcU/off_the_hook__20100310-64.mp3" length="28706227" type="audio/mpeg" /><feedburner:origEnclosureLink>http://www.2600.com/offthehook/mp3files/broadband/off_the_hook__20100310-64.mp3</feedburner:origEnclosureLink></item>
      <item>
         <title>@threatpost: Paul Judge on Twitter Crime and Web Security</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/m8n9HSYip8k/paul-judge-twitter-crime-and-web-security-031010</link>
         <description>&lt;p&gt;&lt;strong&gt;Digital Underground podcast with Dennis Fisher&lt;span class="inline inline-right"&gt;&lt;img src="http://threatpost.com/sites/default/files/images/paul_judge2.jpg" alt="" title="" class="image image-_original " width="100" height="100"/&gt;&lt;/span&gt;&lt;/strong&gt; &lt;/p&gt;&lt;div class="swftools-wrapper onepixelout"&gt;&lt;div class="swftools"&gt;
 
 
 
 
 
 
 
 
 
 
 
 
 
 

 
 
 
 
 
 
 
 
 
 
 
 
 

&lt;p&gt;You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.&lt;/p&gt;

 

 
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Dennis Fisher talks with Paul Judge of Barracuda Networks about the company’s new report on Twitter phishing trends, search engine poisoning, Web security and what can be done about the spam pandemic.&lt;/p&gt;&lt;p&gt;
&lt;div class="image-clear"&gt;&lt;/div&gt;&lt;p&gt;&lt;a rel="nofollow" target="_blank" href="http://threatpost.com/en_us/blogs/paul-judge-twitter-crime-and-web-security-031010"&gt;read more&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;&lt;img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/m8n9HSYip8k" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false">http://threatpost.com/en_us/sites/default/files/digital_underground_49.mp3</guid>
         <pubDate>Wed, 10 Mar 2010 12:08:37 -0800</pubDate>
         
      <feedburner:origLink>http://threatpost.com/en_us/blogs/paul-judge-twitter-crime-and-web-security-031010</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/Y45LJr9-aTo/digital_underground_49.mp3" length="42401099" type="audio/mpeg" /><feedburner:origEnclosureLink>http://threatpost.com/en_us/sites/default/files/digital_underground_49.mp3</feedburner:origEnclosureLink></item>
      <item>
         <title>@mckeay: The Network Security Podcast, Episode 188</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/z4uWPNharOQ/</link>
         <description>Can you hear that? That&amp;#8217;s the sound of air escaping as we all finally recover from the RSA conference. Rich and Martin are back, and Zach&amp;#8230; never left (but did celebrate a birthday last week). We do a quick recap of RSA and then dig into the security news&amp;#8230; much of which had nothing to [...]&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;</description>
         <guid isPermaLink="false">http://netsecpodcast.com/?p=442</guid>
         <pubDate>Tue, 09 Mar 2010 20:10:15 -0800</pubDate>
         <content:encoded><![CDATA[<p>Can you hear that? That&#8217;s the sound of air escaping as we all finally recover from the RSA conference. Rich and Martin are back, and Zach&#8230; never left (but did celebrate a birthday last week). We do a quick recap of RSA and then dig into the security news&#8230; much of which had nothing to do with the conference. Weird.</p>
<p><a rel="nofollow" target="_blank" href="http://media.libsyn.com/media/mckeay/nsp-030910-ep188.mp3">Network Security Podcast, Episode 188, March 9, 2010<br />Time:&nbsp; 32:01</a></p>
<p>Show Notes:
<ul> <li><a rel="nofollow" target="_blank" href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1409041,00.html">Great coverage of Martin&#8217;s RSA panel on disclosure</a>. One of the first with an actual user on the panel.</li>
<p> <li>Government declassifies parts of the<a rel="nofollow" target="_blank" href="http://www.scmagazineus.com/rsa-conference-white-house-declassifies-us-cybersecurity-initiative-details/article/164955/?DCMP=EMC-SCUS_Newswire"> Comprehensive National Cybersecurity Initiative</a>.</li>
<p> <li><a rel="nofollow" target="_blank" href="http://news.cnet.com/8301-19518_3-10465117-238.html">Police get webcam pictures in school spy cases</a>.</li>
<p> <li><a rel="nofollow" target="_blank" href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1409916,00.html">Experts dismiss end to end encryption claims</a>. Bunch of gross generalizations.</li>
<p> <li><a rel="nofollow" target="_blank" href="http://www.computerworld.com/s/article/9166978/Energizer_Bunny_s_software_infects_PCs">Oops- Vodaphone distributes infected phone.</a></li>
<p> <li>&#8230; <a rel="nofollow" target="_blank" href="http://www.computerworld.com/s/article/9166978/Energizer_Bunny_s_software_infects_PCs">and Energizer distributes malware in USB battery software</a>.</li>
<p> <li>Tonight&#8217;s music:&nbsp;<a rel="nofollow" target="_blank" href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=121b2e07b150012150a0a0ea32c457c4"></a></li>
<p></ul>
<p>
<div><img src="http://img.zemanta.com/pixy.gif?x-id=2b23dbe3-05fb-8a23-a41e-29c0bcb84bc1" alt=""/></div>
<div class="zemanta-pixie"><img class="zemanta-pixie-img" alt="" src="http://img.zemanta.com/pixy.gif?x-id=29040a3f-289c-8b94-a5b3-e223e7a919fc"/></div><img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/z4uWPNharOQ" height="1" width="1"/>]]></content:encoded>
         <media:content fileSize="30743325" url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/oDtPFSLW5-c/nsp-030910-ep188.mp3" type="audio/mpeg" />
         <category>Uncategorized</category>
         
      <feedburner:origLink>http://netsecpodcast.com/?p=442</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/oDtPFSLW5-c/nsp-030910-ep188.mp3" length="30743325" type="audio/mpeg" /><feedburner:origEnclosureLink>http://media.libsyn.com/media/mckeay/nsp-030910-ep188.mp3</feedburner:origEnclosureLink></item>
      <item>
         <title>@pauldotcom: PaulDotCom Security Weekly - Episode 189 - March 5, 2010</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/UTK3ZZ0OooU/</link>
         <description>&lt;p&gt;&lt;a rel="nofollow" target="_blank" href="http://pauldotcom.com/wiki/index.php/Episode189"&gt;Episode 189 Show Notes&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&lt;div style="text-align:center;"&gt;&lt;img src="http://pauldotcom.com//SecurityCamerasFail.jpg" alt="SecurityCamerasFail.jpg" border="0" width="600" height="500"/&gt;&lt;/div&gt; &lt;p&gt;Top ten tips to socially engineer management into implementing security the right way, plus all sorts of interesting stories including the "porn detection stick"!&lt;/p&gt; &lt;p&gt;Hosts: &lt;a rel="nofollow" target="_blank" href="http://www.pauldotcom.com"&gt;Larry "HaxorTheMatrix" Pesce&lt;/a&gt;, &lt;a rel="nofollow" target="_blank" href="http://pauldotcom.com"&gt;Paul "PaulDotCom" Asadoorian&lt;/a&gt;, &lt;a rel="nofollow" target="_blank" href="http://www.pauldotcom.com"&gt;John Strand&lt;/a&gt;, &lt;a rel="nofollow" target="_blank" href="http://www.pauldotcom.com"&gt;Mick Douglas&lt;/a&gt;, &lt;a rel="nofollow" target="_blank" href="http://pauldotcom.com"&gt;Carlos "Dark0perator" Perez&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Audio Feeds: &lt;a rel="nofollow" target="_blank" href="http://pauldotcom.com/podcast/psw.xml"&gt;&lt;img src="http://pauldotcom.com/images/xml.png"&gt;&lt;/a&gt; &lt;a rel="nofollow" target="_blank" href="http://www.odeo.com/channel/38062/view"&gt;&lt;img src="http://pauldotcom.com/images/badge-channel-black.gif"&gt;&lt;/a&gt;&lt;a rel="nofollow" target="_blank" href="http://phobos.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=91472687"&gt; &lt;img src="http://pauldotcom.com/images/itunes.gif"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;&lt;img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/UTK3ZZ0OooU" height="1" width="1"/&gt;</description>
         <author>psw@pauldotcom.com</author>
         <guid isPermaLink="false">pauldotcom-security-weekly-episode-189-march-5</guid>
         <pubDate>Tue, 09 Mar 2010 04:31:59 -0800</pubDate>
         
      <feedburner:origLink>http://pauldotcom.com/</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/A5abLii_p-s/pauldotcom-SW-episode189.mp3" length="61176358" type="audio/mpeg" /><feedburner:origEnclosureLink>http://media.libsyn.com/media/pauldotcom/pauldotcom-SW-episode189.mp3</feedburner:origEnclosureLink></item>
      <item>
         <title>@mckeay: RSAC2010: Sourcefire</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/3bbh4SR_KNM/</link>
         <description>Snort was one of the first security tools I ever used.&amp;#160; When I was working in a small computer lab years ago, I set up a Snort sensor just to see what was there.&amp;#160; And there was a lot in that particular environment.&amp;#160; I&amp;#8217;ve used it many times since then and I found out at [...]&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;</description>
         <guid isPermaLink="false">http://netsecpodcast.com/?p=444</guid>
         <pubDate>Mon, 08 Mar 2010 19:20:34 -0800</pubDate>
         <content:encoded><![CDATA[<p>Snort was one of the first security tools I ever used.&nbsp; When I was working in a small computer lab years ago, I set up a Snort sensor just to see what was there.&nbsp; And there was a lot in that particular environment.&nbsp; I&#8217;ve used it many times since then and I found out at RSA that the first Sourcefire implementation I performed is still in place, basically unchanged since I left.&nbsp; This is why I always take the opportunity to talk to <a rel="nofollow" target="_blank" href="http://www.sourcefire.com">Marty Roesch at Sourcefire</a> if I can at RSAC.&nbsp; This time I got a chance to talk to him about the omnipresent APT (he prefer&#8217;s using the term APA, coined by <a rel="nofollow" target="_blank" href="http://www.twitter.com/nselby">@nselby</a> and others), the security existential crisis, the work Sourcefire is doing with <a rel="nofollow" target="_blank" href="http://immunet.com/">Immunet</a>, the Cloud and Sourcefire&#8217;s virtual appliances.&nbsp; All that noise you hear in the background is the Securosis Recovery Breakfast.&nbsp; </p>
<p><a rel="nofollow" target="_blank" href="http://media.libsyn.com/media/mckeay/NSP-RSAC2010-Sourcefire.mp3">NSP-RSAC2010-Sourcefire.mp3</a></p>
<div class="zemanta-pixie"><img class="zemanta-pixie-img" alt="" src="http://img.zemanta.com/pixy.gif?x-id=7ebfb04c-38c9-815b-aa13-5fa7a5269a56"/></div><img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/3bbh4SR_KNM" height="1" width="1"/>]]></content:encoded>
         <media:content fileSize="10755636" url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/LQizbR6SaEk/NSP-RSAC2010-Sourcefire.mp3" type="audio/mpeg" />
         <category>Podcast</category>
         
      <feedburner:origLink>http://netsecpodcast.com/?p=444</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/LQizbR6SaEk/NSP-RSAC2010-Sourcefire.mp3" length="10755636" type="audio/mpeg" /><feedburner:origEnclosureLink>http://media.libsyn.com/media/mckeay/NSP-RSAC2010-Sourcefire.mp3</feedburner:origEnclosureLink></item>
      <item>
         <title>@mckeay: RSAC2010: ISC2</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/n8pt_3CYNto/</link>
         <description>I&amp;#8217;ve been a member of the International Information Systems Security Certification Consortium [(ISC)2] for nearly a decade; I passed my CISSP test in November of 2002 and don&amp;#8217;t have to worry much about CPE&amp;#8217;s until at least 2011.&amp;#160; So when I was offered an opportunity to talk to Hord Tipton, Executive Director of the (ISC)2, [...]&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;</description>
         <guid isPermaLink="false">http://netsecpodcast.com/?p=440</guid>
         <pubDate>Mon, 08 Mar 2010 06:32:19 -0800</pubDate>
         <content:encoded><![CDATA[<p>I&#8217;ve been a member of the <a rel="nofollow" target="_blank" href="http://www.isc2.org/">International Information Systems Security Certification Consortium [(ISC)2]</a> for nearly a decade; I passed my CISSP test in November of 2002 and don&#8217;t have to worry much about CPE&#8217;s until at least 2011.&nbsp; So when I was offered an opportunity to talk to Hord Tipton, Executive Director of the (ISC)2, I didn&#8217;t hesitate to take them up on the offer.&nbsp; We started off easy, talking about what&#8217;s new at the (ISC)2, and the <a rel="nofollow" target="_blank" href="http://cyberexchange.isc2.org/volunteerIntro.aspx">Safe &amp; Secure Online Program</a>.&nbsp; Then we moved on to the harder questions, like &#8220;What have you done for me lately?&#8221; and &#8220;What are you doing about people who shouldn&#8217;t be CISSP&#8217;s in the first place?&#8221;&nbsp; The (ISC)2 is never going to make all of us who are certified happy, and that they are taking some steps to address concerns about unqualified practitioners, but it&#8217;d be nice if they were a little more public about it.&nbsp; Oh, and you&#8217;ll hear at the end that the (ISC)2 definitely accepts listening to podcasts for CPE&#8217;s.&nbsp; I forgot to ask about producing them.</p>
<p><a rel="nofollow" target="_blank" href="http://media.libsyn.com/media/mckeay/NSP-RSAC2010-ISC2.mp3">NSP-RSAC2010-ISC2.mp3</a></p>
<div class="zemanta-pixie"><img class="zemanta-pixie-img" alt="" src="http://img.zemanta.com/pixy.gif?x-id=2f7947c0-60a4-8cba-a8d5-c725845b8988"/></div><img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/n8pt_3CYNto" height="1" width="1"/>]]></content:encoded>
         <media:content fileSize="12468858" url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/Ou4pEuPD5PA/NSP-RSAC2010-ISC2.mp3" type="audio/mpeg" />
         <category>Podcast</category>
         
      <feedburner:origLink>http://netsecpodcast.com/?p=440</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/Ou4pEuPD5PA/NSP-RSAC2010-ISC2.mp3" length="12468858" type="audio/mpeg" /><feedburner:origEnclosureLink>http://media.libsyn.com/media/mckeay/NSP-RSAC2010-ISC2.mp3</feedburner:origEnclosureLink></item>
      <item>
         <title>@mckeay: RSAC2010: Kaspersky Lab</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/Tc7Q4qIRv7s/</link>
         <description>It&amp;#8217;s hard doing interviews on the showroom floor at RSAC.&amp;#160; Even the relatively quiet places are incredibly noisy when you get right down to it.&amp;#160; The good thing is it hopefully masked the worst of my mispronunciation of Roel Schouwenberg&amp;#8217;s name.&amp;#160; Roel is the Senior Anti-Virus Researcher at Kaspersky Lab and spent some time talking [...]&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;</description>
         <guid isPermaLink="false">http://netsecpodcast.com/?p=438</guid>
         <pubDate>Sun, 07 Mar 2010 17:46:34 -0800</pubDate>
         <content:encoded><![CDATA[<p>It&#8217;s hard doing interviews on the showroom floor at RSAC.&nbsp; Even the relatively quiet places are incredibly noisy when you get right down to it.&nbsp; The good thing is it hopefully masked the worst of my mispronunciation of Roel Schouwenberg&#8217;s name.&nbsp; Roel is the Senior Anti-Virus Researcher at <a rel="nofollow" target="_blank" href="http://www.kasperksy.com">Kaspersky Lab</a> and spent some time talking to me in the Threat Post booth on the showroom floor at RSA 2010.&nbsp; We started off talking about the omnipresent APT, moved into slicing apart signature-based AV and end up on organized crime and what the future may bring.&nbsp; </p>
<p><a rel="nofollow" target="_blank" href="http://media.libsyn.com/media/mckeay/NSP-RSAC2010-KasperskyLab.mp3">NSP-RSAC2010-KasperskeyLab.mp3</a></p>
<div class="zemanta-pixie"><img class="zemanta-pixie-img" alt="" src="http://img.zemanta.com/pixy.gif?x-id=8bdb2661-3bad-8edc-88c0-b66d2eaa71f9"/></div><img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/Tc7Q4qIRv7s" height="1" width="1"/>]]></content:encoded>
         <media:content fileSize="8543381" url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/LGfLqVSG4z8/NSP-RSAC2010-KasperskyLab.mp3" type="audio/mpeg" />
         <category>Podcast</category>
         
      <feedburner:origLink>http://netsecpodcast.com/?p=438</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/LGfLqVSG4z8/NSP-RSAC2010-KasperskyLab.mp3" length="8543381" type="audio/mpeg" /><feedburner:origEnclosureLink>http://media.libsyn.com/media/mckeay/NSP-RSAC2010-KasperskyLab.mp3</feedburner:origEnclosureLink></item>
      <item>
         <title>@mckeay: RSAC2010: Astaro Internet Security</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/NHjFrgNyXOI/</link>
         <description>Jan Hichert, CEO of Astaro Internet Security, and I met in one of the quieter hallways of the 2010 RSA Convention.&amp;#160; Of course, &amp;#8216;quiet&amp;#8217; is a relative term when it comes to RSA, but the audio came out acceptable in any case.&amp;#160; We talked about several of the new products Astaro is offering this year, [...]&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;</description>
         <guid isPermaLink="false">http://netsecpodcast.com/?p=436</guid>
         <pubDate>Sun, 07 Mar 2010 08:46:20 -0800</pubDate>
         <content:encoded><![CDATA[<p>Jan Hichert, CEO of <a rel="nofollow" target="_blank" href="http://www.astaro.com">Astaro Internet Security</a>, and I met in one of the quieter hallways of the 2010 RSA Convention.&nbsp; Of course, &#8216;quiet&#8217; is a relative term when it comes to RSA, but the audio came out acceptable in any case.&nbsp; We talked about several of the new products Astaro is offering this year, including Astaro Mail Archiving, Astaro Wireless Security and Astaro RED.&nbsp; We finished the conversation talking about <a rel="nofollow" target="_blank" href="http://blog.uncommonsensesecurity.com/">Jack Daniel&#8217;s</a> new position at Astaro, social media and <a rel="nofollow" target="_blank" href="http://www.securitybsides.org/BSides">Security BSides</a>.&nbsp; I think Astaro is one of the few security companies that actually get social media, in large part thanks to Jack.&nbsp; </p>
<p><a rel="nofollow" target="_blank" href="http://media.libsyn.com/media/mckeay/NSP-RSAC2010-AstaroSecurity.mp3">NSP-RSAC2010-AstaroSecurity.mp3</a></p>
<div class="zemanta-pixie"><img class="zemanta-pixie-img" alt="" src="http://img.zemanta.com/pixy.gif?x-id=71020a18-a8d4-8b53-98ac-2ef9f9a202dc"/></div><img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/NHjFrgNyXOI" height="1" width="1"/>]]></content:encoded>
         <media:content fileSize="9134941" url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/3028r2Iyjj4/NSP-RSAC2010-AstaroSecurity.mp3" type="audio/mpeg" />
         <category>Podcast</category>
         
      <feedburner:origLink>http://netsecpodcast.com/?p=436</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/3028r2Iyjj4/NSP-RSAC2010-AstaroSecurity.mp3" length="9134941" type="audio/mpeg" /><feedburner:origEnclosureLink>http://media.libsyn.com/media/mckeay/NSP-RSAC2010-AstaroSecurity.mp3</feedburner:origEnclosureLink></item>
      <item>
         <title>@mckeay: RSAC2010: F-Secure</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/ESg9J7lfLSg/</link>
         <description>While I&amp;#8217;m sure Mikko Hypponen, Chief Research Officer at F-Secure, is getting as tired as hearing the term APT* as the rest of us are, he had some insight into what&amp;#8217;s really happening with this threat and the fact that it&amp;#8217;s not something new, it&amp;#8217;s just the acknowledgment that it&amp;#8217;s happening that&amp;#8217;s new.&amp;#160; He&amp;#8217;s been [...]&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;</description>
         <guid isPermaLink="false">http://netsecpodcast.com/?p=434</guid>
         <pubDate>Sat, 06 Mar 2010 07:22:37 -0800</pubDate>
         <content:encoded><![CDATA[<p>While I&#8217;m sure Mikko Hypponen, <a rel="nofollow" target="_blank" href="http://www.f-secure.com">Chief Research Officer at F-Secure</a>, is getting as tired as hearing the term APT* as the rest of us are, he had some insight into what&#8217;s really happening with this threat and the fact that it&#8217;s not something new, it&#8217;s just the acknowledgment that it&#8217;s happening that&#8217;s new.&nbsp; He&#8217;s been seeing similar attacks going on for nearly six years, what&#8217;s changed is the recognition and public attention to the threat that&#8217;s something new.&nbsp; He believes that the organized crime component of malware will be moving to smart phones as the criminals realize that it&#8217;s easier to make money quickly and easily from phones than the complicated hoops they have to jump through to make money from computers.</p>
<p><a rel="nofollow" target="_blank" href="http://media.libsyn.com/media/mckeay/NSP-RSAC2010-FSecure.mp3">NSP-RSAC2010-FSecure.mp3</a></p>
<p>* I&#8217;m with <a rel="nofollow" target="_blank" href="http://twitter.com/csoandy">@CSOAndy</a> who believe the A in APT should stand for Adaptive, not Advance.&nbsp; It&#8217;s much more descriptive of what&#8217;s really happening.</p>
<div class="zemanta-pixie"><img class="zemanta-pixie-img" alt="" src="http://img.zemanta.com/pixy.gif?x-id=ec9d6437-04bb-812e-a7c3-ec4edc2d16cb"/></div><img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/ESg9J7lfLSg" height="1" width="1"/>]]></content:encoded>
         <media:content fileSize="8515373" url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/ovWXRfegS8Y/NSP-RSAC2010-FSecure.mp3" type="audio/mpeg" />
         <category>Podcast</category>
         
      <feedburner:origLink>http://netsecpodcast.com/?p=434</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/ovWXRfegS8Y/NSP-RSAC2010-FSecure.mp3" length="8515373" type="audio/mpeg" /><feedburner:origEnclosureLink>http://media.libsyn.com/media/mckeay/NSP-RSAC2010-FSecure.mp3</feedburner:origEnclosureLink></item>
      <item>
         <title>@mckeay: RSAC2010: Panda Security</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/84QIAWJVxJ4/</link>
         <description>I caught up with Pedro Bustamante, Senior Research Analyst from Panda Security, for a brief interview about what his company is doing in 2010.&amp;#160; Panda recently received ICSA Lab certification of their cloud AV product, which required some retooling of the ICSA processes.&amp;#160; Panda is releasing a new, free, no-registration version of their product as [...]&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;</description>
         <guid isPermaLink="false">http://netsecpodcast.com/?p=432</guid>
         <pubDate>Sat, 06 Mar 2010 06:11:52 -0800</pubDate>
         <content:encoded><![CDATA[<p>I caught up with Pedro Bustamante, Senior Research Analyst from <a rel="nofollow" target="_blank" href="http://www.pandasecurity.com/usa/">Panda Security</a>, for a brief interview about what his company is doing in 2010.&nbsp; Panda recently received ICSA Lab certification of their cloud AV product, which required some retooling of the ICSA processes.&nbsp; Panda is releasing a new, free, no-registration version of their product as well as an upgraded version of their existing anti-virus that includes many of the features that Panda customers have been asking for.&nbsp; We talked about a new USB vaccine Panda is releasing which &#8216;inoculates&#8217; a USB drive by writing an unalterable file to the drive before a virus can.&nbsp; Finally we discussed the sheer amount of data Panda is collecting and how much of it they&#8217;re able to process automatically.&nbsp; But there does, and always will, remain a small fraction of a percent of the data that has to be inspected by human beings to catch the new and the interesting that malware writers are creating.</p>
<p><a rel="nofollow" target="_blank" href="http://media.libsyn.com/media/mckeay/NSP-RSAC2010-PandaSecurity.mp3">NSP-RSAC2010-PandaSecurity.mp3</a></p>
<div class="zemanta-pixie"><img class="zemanta-pixie-img" alt="" src="http://img.zemanta.com/pixy.gif?x-id=f8e4ae75-cf68-854f-bd6b-1c18627de402"/></div><img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/84QIAWJVxJ4" height="1" width="1"/>]]></content:encoded>
         <media:content fileSize="7164536" url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/OExib36i4kE/NSP-RSAC2010-PandaSecurity.mp3" type="audio/mpeg" />
         <category>Podcast</category>
         
      <feedburner:origLink>http://netsecpodcast.com/?p=432</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/OExib36i4kE/NSP-RSAC2010-PandaSecurity.mp3" length="7164536" type="audio/mpeg" /><feedburner:origEnclosureLink>http://media.libsyn.com/media/mckeay/NSP-RSAC2010-PandaSecurity.mp3</feedburner:origEnclosureLink></item>
      <item>
         <title>@humanhacker: Using Persuasion on the Mindless Masses</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/EekoUvw8YvE/Social-EngineerPodcastEp007.mp3</link>
         <description>Join the Social-Engineer.org team as we discuss the topics of persuasion and mindlessness with Harvard psychologist and world renowned persuasion expert, Ellen Langer.&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;&lt;img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/EekoUvw8YvE" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false">http://social-engineer.solidcasts.com/xml/download/1929/audio/5780/Social-EngineerPodcastEp007.mp3</guid>
         <pubDate>Fri, 05 Mar 2010 19:18:31 -0800</pubDate>
         <category>Podcasts</category>
         
      <feedburner:origLink>http://social-engineer.solidcasts.com/xml/download/1929/audio/5780/Social-EngineerPodcastEp007.mp3</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/EekoUvw8YvE/Social-EngineerPodcastEp007.mp3" length="78949293" type="audio/mpeg" /><feedburner:origEnclosureLink>http://social-engineer.solidcasts.com/xml/download/1929/audio/5780/Social-EngineerPodcastEp007.mp3</feedburner:origEnclosureLink></item>
      <item>
         <title>@riskybusiness: Risky Business #142 -- Special guest H D Moore talks fun with NTP</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/we3sD2rKhEQ/RB142</link>
         <description>&lt;p&gt;Risky Business is hosted by the team at Virtual.Offis in Sydney but sponsored, this week, by Tenable Network Security. &lt;/p&gt;
&lt;p&gt;This week's feature guest is H D Moore, who'll be joining us to talk about some fun stuff he's been doing with NTP. Believe it or not you can use NTP to do massive recon on the Intertubez. H D has built a database of millions of hosts by querying NTP boxens. It's cool.&lt;/p&gt;
&lt;p&gt;Tenable Network Security CEO Ron Gula joins us in this week's sponsor interview, and Adam "Beardy McUNIXguy" Boileau drops in to discuss the week's news.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;&lt;img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/we3sD2rKhEQ" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false">http://media.risky.biz/RB142.mp3</guid>
         <pubDate>Thu, 04 Mar 2010 21:46:57 -0800</pubDate>
         
      <feedburner:origLink>http://risky.biz/RB142</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/0J1Sstwj3cM/RB142.mp3" length="33350208" type="audio/mpeg" /><feedburner:origEnclosureLink>http://media.risky.biz/RB142.mp3</feedburner:origEnclosureLink></item>
      <item>
         <title>@riskybusiness: RB2: SPONSOR PODCAST: Big security vendors jump into PCLM?</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/G_-TRgVUS5U/RB2-pclm</link>
         <description>&lt;p&gt;This is a sponsored podcast. Symantec sponsors the RB2 podcast so once a month we get one of their staff on the line to talk about industry trends, malware... whatever, really!&lt;/p&gt;
&lt;p&gt;And today we're speaking with Vincent Weafer, Symantec's director of security response. Regular listeners of Risky.Biz podcasts would have heard me tonking on a LOT about patch management lately, and in particular the moves by large security vendors like McAfee, Trend and Symantec into that space.&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_blank" href="http://risky.biz/RB2-pclm"&gt;read more&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;&lt;img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/G_-TRgVUS5U" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false">http://media.risky.biz/RB2-pclm.mp3</guid>
         <pubDate>Wed, 03 Mar 2010 19:35:58 -0800</pubDate>
         
      <feedburner:origLink>http://risky.biz/RB2-pclm</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/v6bm2K6OTQ4/RB2-pclm.mp3" length="6466119" type="audio/mpeg" /><feedburner:origEnclosureLink>http://media.risky.biz/RB2-pclm.mp3</feedburner:origEnclosureLink></item>
      <item>
         <title>@2600: Off The Hook show for March 3, 2010</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/OecuNZsQxw8/</link>
         <description>&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;&lt;img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/OecuNZsQxw8" height="1" width="1"/&gt;</description>
         <author>oth@2600.com (Emmanuel Goldstein et.al.)</author>
         <guid isPermaLink="false">oth20100303-hq</guid>
         <pubDate>Wed, 03 Mar 2010 17:00:00 -0800</pubDate>
         <media:content samplingrate="22.05" url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/O93qi_3ADls/off_the_hook__20100303-64.mp3">
            <media:rating>nonadult</media:rating>
            <media:title>Off The Hook show for March 3, 2010</media:title>
         </media:content>
         
      <feedburner:origLink>http://www.2600.com/offthehook/</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/O93qi_3ADls/off_the_hook__20100303-64.mp3" length="28743808" type="audio/mpeg" /><feedburner:origEnclosureLink>http://www.2600.com/offthehook/mp3files/broadband/off_the_hook__20100303-64.mp3</feedburner:origEnclosureLink></item>
      <item>
         <title>@tenablesecurity: Tenable Network Security Podcast - Episode 25</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/h3PEzaF1wcQ/tenable-network-security-podcast---episode-25.html</link>
         <description>Welcome to the Tenable Network Security Podcast - Episode 25 Announcements Two new blog posts have been released titled "Implementing Perimeter Intrusion Detection" and SecurityCenter 4 Introduction". Also, Nessus 4.2.1 was released with support for Solaris and some significant performance...&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;</description>
         <guid isPermaLink="false">http://blog.tenablesecurity.com/2010/03/tenable-network-security-podcast---episode-25.html</guid>
         <pubDate>Tue, 02 Mar 2010 12:11:57 -0800</pubDate>
         <content:encoded><![CDATA[<p>Welcome to the Tenable Network Security Podcast - Episode 25</p> <h3>Announcements</h3> <ul>
<li>Two new blog posts have been released titled "<a rel="nofollow" target="_blank" href="http://blog.tenablesecurity.com/2010/02/implementing-perimeter-intrusion-detection.html">Implementing Perimeter Intrusion Detection</a>" and <a rel="nofollow" target="_blank" href="http://blog.tenablesecurity.com/2010/02/securitycenter-4-introduction-pushing-the-envelope-for-scanning-and-event-management-products.html">SecurityCenter 4 Introduction</a>". Also, <a rel="nofollow" target="_blank" href="http://blog.tenablesecurity.com/2010/02/nessus-version-421-released.html">Nessus 4.2.1 was released </a>with support for Solaris and some significant performance enhancements.</li>
<li><a rel="nofollow" target="_blank" href="http://blog.tenablesecurity.com/2010/02/see-security-center-4-at-rsa-2010---booth-956.html">Come see us at RSA - Booth #956!</a> I, Ron Gula, Renaud Deraison and many others from Tenable will be there demonstrating SecurityCenter 4.0 along with Nessus 4.2, the latest Passive Vulnerability Scanner and the Log Correlation Engine. </li>
<li>The webinar performed on February 25, 2010 titled, "<a rel="nofollow" target="_blank" href="http://blog.tenablesecurity.com/2010/01/finding-and-stopping-advanced-persistent-threats-webinar.html">Finding and Stopping Advanced Persistent Threats</a>" in which Tenable CEO Ron Gula and Tenable CSO Marcus Ranum discussed strategies for preventing, finding and eliminating advanced persistent threats in enterprise networks is <a rel="nofollow" target="_blank" href="http://blog.tenablesecurity.com/2010/01/finding-and-stopping-advanced-persistent-threats-webinar.html">available for download</a>. </li> <p><li>You can provide feedback to this podcast and all of our social media outlets by visiting our discussions forum and adding messages to the "<a rel="nofollow" target="_blank" href="https://discussions.nessus.org/community/social">Tenable Social Media</a>" thread. I would love to hear your feedback, questions, comments and suggestions! <a rel="nofollow" target="_blank" href="https://discussions.nessus.org/thread/2018">I put up a call for ideas on new Nessus videos</a>, so please give us your feedback!</li><br />
<li><a rel="nofollow" target="_blank" href="http://www.nessus.org/about/index.php?view=careers">We're hiring</a>! - Visit the web site for more information about open positions, there are currently 7 open positions listed! </li><br />
<li>You can subscribe to the <a rel="nofollow" target="_blank" href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=329735657">Tenable Network Security Podcast on iTunes!</a></li><br />
<li>Tenable Tweets - You can find us on Twitter at <a rel="nofollow" target="_blank" href="http://twitter.com/tenablesecurity">http://twitter.com/tenablesecurity</a> where we make various announcements, Nessus plugin statistics and more!</li><br />
</ul><br />
</p><p><br />
<h3>Stories</h3></p> <ul>
<li><a rel="nofollow" target="_blank" href="https://discussions.nessus.org/message/5228#5228">Detecting the TDSS/TDL3/Tidserv rootkit with Nessus (Login Required)</a> - This is really great usage of an audit file! It searches the Windows registry for keys associated with the rootkits and alerts on it. This is the <a rel="nofollow" target="_blank" href="http://blogs.technet.com/msrc/archive/2010/02/12/update-restart-issues-after-installing-ms10-015.aspx">rootkit that was causing the "Blue Screen Of Death" problems when users applied some of the recent Microsoft patches</a>. Nessus ProfessionalFeed customers can download the audit file and use it to detect this rootkit in your environment before applying the patches from Microsoft.</li>
<li><a rel="nofollow" target="_blank" href="http://www.ghacks.net/2010/03/01/new-internet-explorer-vulnerability-confirmed/">New Internet Explorer Vulnerability</a> - This is perhaps one of my favorite vulnerability write-ups in a long time. First it states, <em>"a user on the target system needs to be convinced to press the F1 key in response to a pop up dialog box on a specifically prepared website"</em> and then goes on to say <em>"As of now all users need to remember is to not press F1 when they are accessing websites."</em> Can we just remove the F1 key from the keyboard?</li>
<li><a rel="nofollow" target="_blank" href="http://www.digitalbond.com/index.php/2010/03/01/scada-devices-on-verizon-and-other-wireless-networks/"> SCADA Devices on Verizon and Other Wireless Networks </a> - This is interesting, as I have been doing some of my own research in this area. Many SCADA security tactics rely on the so-called "air-gapped" network. This usually does not work out so well when stuff needs to actually talk to other stuff. So slowly they creep onto the network, but since the assumption is that it's "Air-gapped" no one really bothers to look for these devices on the network. Also, since it's a "harmless" embedded system people will assume that they do not have to secure it, so they leave default passwords. This is just a bad combination! Take time to secure everything in your environment and apply your security strategy to all systems, even the embedded ones.</li>
<li><a rel="nofollow" target="_blank" href="http://feedproxy.google.com/~r/SecurityBloggersNetwork/~3/BEn0Pk-YGXM/">GuestStealer Information Wrapup</a> - This is a great summary post of all of the information surrounding the guest stealing vulnerability released at Shmoocon. Nessus was used to detect a directory traversal vulnerability that lead to multiple vulnerabilities in VMware systems that could allow an attacker access to download the entire collection of guest operating systems on the host. Nessus has new checks that look for this specific vulnerability as well.</li>
</ul> <p class="asset asset-audio at-xid-6a00d8345495f669e201310f539da7970c"><a rel="nofollow" target="_blank" href="http://tenable.typepad.com/files/tenablepodcast-episode25.mp3">Download Tenable Podcast Episode 25</a></p><img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/h3PEzaF1wcQ" height="1" width="1"/>]]></content:encoded>
         <category>Podcast</category>
         
      <feedburner:origLink>http://blog.tenablesecurity.com/2010/03/tenable-network-security-podcast---episode-25.html</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/Is0tis5E_HE/tenablepodcast-episode25.mp3" length="0" type="audio/mpeg" /><feedburner:origEnclosureLink>http://tenable.typepad.com/files/tenablepodcast-episode25.mp3</feedburner:origEnclosureLink></item>
      <item>
         <title>@securabit: SecuraBit EP51 – Malware Detection With Sunbelt Software</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/uC9ZFOnIYMw/</link>
         <description>SecuraBit EP51 &amp;#8211; Malware Detection With Sunbelt Software
Listen in as we discuss Sunbelt Software&amp;#8217;s CWSandbox and other products, along with in-depth malware detection and analysis!
#BSidesSF &amp;#8211; Tuesday/Wednesday, March 2-3, 2010 @ 10am &amp;#8211; 5pm
#BSidesAustin &amp;#8211; Saturday, March 13, 2010
#BSidesBOS &amp;#8211; Saturday/Sunday, April 24-25, 2010
Chat with us on IRC at irc.freenode.net #securabit
Hosts:
Anthony [...]&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;</description>
         <guid isPermaLink="false">http://www.securabit.com/?p=1314</guid>
         <pubDate>Tue, 02 Mar 2010 08:44:12 -0800</pubDate>
         <content:encoded><![CDATA[<p>SecuraBit EP51 &#8211; Malware Detection With Sunbelt Software</p>
<p>Listen in as we discuss Sunbelt Software&#8217;s CWSandbox and other products, along with in-depth malware detection and analysis!</p>
<p>#BSidesSF &#8211; Tuesday/Wednesday, March 2-3, 2010 @ 10am &#8211; 5pm<br />
#BSidesAustin &#8211; Saturday, March 13, 2010<br />
#BSidesBOS &#8211; Saturday/Sunday, April 24-25, 2010<br />
Chat with us on IRC at irc.freenode.net #securabit</p>
<p>Hosts:<br />
Anthony Gartner – @anthonygartner<br />
Christopher Mills – @thechrisam<br />
Chris Gerling – @chrisgerling<br />
Jason Mueller – @securabit_jay<br />
Andrew Borel – @andrew_secbit</p>
<p>Guests:<br />
Brian Jack &#8211; Sunbelt Software<br />
Chad Loeven &#8211; Sunbelt Software</p>
<p>Links:</p>
<p><a rel="nofollow" target="_blank" href="http://www.sunbeltsoftware.com/">http://www.sunbeltsoftware.com/</a></p>
<p><a rel="nofollow" target="_blank" href="http://www.sunbeltsoftware.com/Malware-Research-Analysis-Tools/Sunbelt-CWSandbox/">http://www.sunbeltsoftware.com/Malware-Research-Analysis-Tools/Sunbelt-CWSandbox/</a></p>
<p><a rel="nofollow" target="_blank" href="http://www.securitybsides.com/">http://www.securitybsides.com/</a></p><img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/uC9ZFOnIYMw" height="1" width="1"/>]]></content:encoded>
         
      <feedburner:origLink>http://www.securabit.com/2010/03/02/securabit-ep51-malware-detection-with-sunbelt-software/</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/K9A9MS-1jbk/SecuraBit_EP51.mp3" length="32538667" type="audio/mpeg" /><feedburner:origEnclosureLink>http://media.libsyn.com/media/securabit/SecuraBit_EP51.mp3</feedburner:origEnclosureLink></item>
      <item>
         <title>@pauldotcom: PaulDotCom Security Weekly - Episode 188 Part 2 - February 25, 2010</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/UTK3ZZ0OooU/</link>
         <description>&lt;p&gt;&lt;a rel="nofollow" target="_blank" href="http://pauldotcom.com/wiki/index.php/Episode188"&gt;Episode 187 Show Notes&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Part 2: DNS sub-domain brute forcing &amp; Penetration&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;div style="text-align:center;"&gt;&lt;img src="http://pauldotcom.com//nopenetration.png" alt="nopenetration.png" border="0" width="501" height="343"/&gt;&lt;/div&gt; &lt;p&gt;We discuss when penetration is important, how to talk to management, coolest WRT54G hack, and a technical segment on DNS sub-domain brute forcing.&lt;/p&gt; &lt;p&gt;&lt;div style="text-align:center;"&gt;&lt;a rel="nofollow" target="_blank" href="http://media.libsyn.com/media/pauldotcom/pauldotcom-SW-episode188pt2.mp3"&gt;188 Part 2 - Direct Audio Download&lt;/a&gt;&lt;/div&gt; &lt;p&gt;Hosts: &lt;a rel="nofollow" target="_blank" href="http://www.pauldotcom.com"&gt;Larry "HaxorTheMatrix" Pesce&lt;/a&gt;, &lt;a rel="nofollow" target="_blank" href="http://pauldotcom.com"&gt;Paul "PaulDotCom" Asadoorian&lt;/a&gt;, &lt;a rel="nofollow" target="_blank" href="http://www.pauldotcom.com"&gt;John Strand&lt;/a&gt;, &lt;a rel="nofollow" target="_blank" href="http://www.pauldotcom.com"&gt;Mick Douglas&lt;/a&gt;, &lt;a rel="nofollow" target="_blank" href="http://pauldotcom.com"&gt;Carlos "Dark0perator" Perez&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Audio Feeds: &lt;a rel="nofollow" target="_blank" href="http://pauldotcom.com/podcast/psw.xml"&gt;&lt;img src="http://pauldotcom.com/images/xml.png"&gt;&lt;/a&gt; &lt;a rel="nofollow" target="_blank" href="http://www.odeo.com/channel/38062/view"&gt;&lt;img src="http://pauldotcom.com/images/badge-channel-black.gif"&gt;&lt;/a&gt;&lt;a rel="nofollow" target="_blank" href="http://phobos.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=91472687"&gt; &lt;img src="http://pauldotcom.com/images/itunes.gif"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;&lt;img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/UTK3ZZ0OooU" height="1" width="1"/&gt;</description>
         <author>psw@pauldotcom.com</author>
         <guid isPermaLink="false">pauldotcom-security-weekly-episode-188-part-2-</guid>
         <pubDate>Mon, 01 Mar 2010 10:33:15 -0800</pubDate>
         
      <feedburner:origLink>http://pauldotcom.com/</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/JHysRtrs9oU/pauldotcom-SW-episode188pt2.mp3" length="57380144" type="audio/mpeg" /><feedburner:origEnclosureLink>http://media.libsyn.com/media/pauldotcom/pauldotcom-SW-episode188pt2.mp3</feedburner:origEnclosureLink></item>
      <item>
         <title>@pauldotcom: PaulDotCom Security Weekly - Episode 188 Part 1 - February 25, 2010</title>
         <link>http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~3/UTK3ZZ0OooU/</link>
         <description>&lt;p&gt;&lt;a rel="nofollow" target="_blank" href="http://pauldotcom.com/wiki/index.php/Episode188"&gt;Episode 187 Show Notes&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Part 1: "Freedom TM"&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;div style="text-align:center;"&gt;&lt;img src="http://pauldotcom.com//FreedomCoverIsometric03.jpg" alt="FreedomCoverIsometric03.jpg" border="0" width="226" height="290"/&gt;&lt;/div&gt; &lt;p&gt;The PaulDotCom crew interviews Daniel Suarez to discuss his new book Freedom TM, security, privacy, socialogy, and more!&lt;/p&gt; &lt;p&gt;Hosts: &lt;a rel="nofollow" target="_blank" href="http://www.pauldotcom.com"&gt;Larry "HaxorTheMatrix" Pesce&lt;/a&gt;, &lt;a rel="nofollow" target="_blank" href="http://pauldotcom.com"&gt;Paul "PaulDotCom" Asadoorian&lt;/a&gt;, &lt;a rel="nofollow" target="_blank" href="http://www.pauldotcom.com"&gt;John Strand&lt;/a&gt;, &lt;a rel="nofollow" target="_blank" href="http://www.pauldotcom.com"&gt;Mick Douglas&lt;/a&gt;, &lt;a rel="nofollow" target="_blank" href="http://pauldotcom.com"&gt;Carlos "Dark0perator" Perez&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Audio Feeds: &lt;a rel="nofollow" target="_blank" href="http://pauldotcom.com/podcast/psw.xml"&gt;&lt;img src="http://pauldotcom.com/images/xml.png"&gt;&lt;/a&gt; &lt;a rel="nofollow" target="_blank" href="http://www.odeo.com/channel/38062/view"&gt;&lt;img src="http://pauldotcom.com/images/badge-channel-black.gif"&gt;&lt;/a&gt;&lt;a rel="nofollow" target="_blank" href="http://phobos.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=91472687"&gt; &lt;img src="http://pauldotcom.com/images/itunes.gif"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;small&gt;&lt;a rel="nofollow" target="_blank" href="http://feeds.andrewallen.co.uk/andrewallen/podroll"&gt;http://feeds.andrewallen.co.uk/andrewallen/podroll&lt;/a&gt;, digital fingerprint: f9522c4eac241a6898424d24dd2b321a&lt;/small&gt;&lt;img src="http://feeds.feedburner.com/~r/andrewallen/podroll/~4/UTK3ZZ0OooU" height="1" width="1"/&gt;</description>
         <author>psw@pauldotcom.com</author>
         <guid isPermaLink="false">pauldotcom-security-weekly-episode-188-part-1-</guid>
         <pubDate>Mon, 01 Mar 2010 10:27:32 -0800</pubDate>
         
      <feedburner:origLink>http://pauldotcom.com/</feedburner:origLink><enclosure url="http://feeds.andrewallen.co.uk/~r/andrewallen/podroll/~5/wQLHpxB7QOg/pauldotcom-SW-episode188pt1.mp3" length="52253805" type="audio/mpeg" /><feedburner:origEnclosureLink>http://media.libsyn.com/media/pauldotcom/pauldotcom-SW-episode188pt1.mp3</feedburner:origEnclosureLink></item>
   </channel>
</rss><!-- fe1.pipes.re3.yahoo.com uncompressed/chunked Thu Mar 18 18:34:26 PDT 2010 -->
