<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2enclosuresfull.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>An Information Security Place</title>
	
	<link>http://infosecplace.com/blog</link>
	<description>Commentary on the State of Information Security</description>
	<lastBuildDate>Tue, 23 Feb 2010 22:28:21 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/AnInformationSecurityPlace" /><feedburner:info uri="aninformationsecurityplace" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><media:copyright>Copyright Michael R. Farnum</media:copyright><media:keywords>security,Michael,R,Farnum,podcast,blog,information,security,infosec</media:keywords><media:category scheme="http://www.itunes.com/dtds/podcast-1.0.dtd">Technology</media:category><itunes:owner><itunes:email>m1a1vet@infosecplace.com</itunes:email><itunes:name>Michael R. Farnum</itunes:name></itunes:owner><itunes:author>Michael R. Farnum</itunes:author><itunes:explicit>no</itunes:explicit><itunes:keywords>security,Michael,R,Farnum,podcast,blog,information,security,infosec</itunes:keywords><itunes:subtitle>Commentary on the state of information security.</itunes:subtitle><itunes:summary>Commentary on the state of information security.</itunes:summary><itunes:category text="Technology" /><creativeCommons:license>http://creativecommons.org/licenses/by-nd/2.0/</creativeCommons:license><image><url>http://www.feedburner.com/fb/images/pub/fb_pwrd.gif</url></image><item>
		<title>iTunes picked up the wrong episode</title>
		<link>http://feedproxy.google.com/~r/AnInformationSecurityPlace/~3/oeVHu6DGvyU/</link>
		<comments>http://infosecplace.com/blog/2010/02/23/itunes-picked-up-the-wrong-episode/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 22:28:04 +0000</pubDate>
		<dc:creator>m1a1vet@infosecplace.com (Michael R. Farnum)</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/2010/02/23/itunes-picked-up-the-wrong-episode/</guid>
		<description><![CDATA[Just realized that iTunes picked up Episode 31 instead of episode 32 on the latest post.  I had to delete the enclosure in Wordpress and then recreate it.  Not sure what happened.  If you subscribe to the podcast via iTunes, you may need to delete Episode 32 and then update.  Sorry [...]]]></description>
			<content:encoded><![CDATA[<p>Just realized that iTunes picked up Episode 31 instead of episode 32 on the latest post.  I had to delete the enclosure in Wordpress and then recreate it.  Not sure what happened.  If you subscribe to the podcast via iTunes, you may need to delete Episode 32 and then update.  Sorry about that!</p>
<p>Vet</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=oeVHu6DGvyU:kOW7ZZjnzmQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=oeVHu6DGvyU:kOW7ZZjnzmQ:5lVTG1FW49M"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=5lVTG1FW49M" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=oeVHu6DGvyU:kOW7ZZjnzmQ:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=oeVHu6DGvyU:kOW7ZZjnzmQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=oeVHu6DGvyU:kOW7ZZjnzmQ:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=oeVHu6DGvyU:kOW7ZZjnzmQ:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=oeVHu6DGvyU:kOW7ZZjnzmQ:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=oeVHu6DGvyU:kOW7ZZjnzmQ:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=63t7Ie-LG7Y" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2010/02/23/itunes-picked-up-the-wrong-episode/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecplace.com/blog/2010/02/23/itunes-picked-up-the-wrong-episode/</feedburner:origLink></item>
		<item>
		<title>An Information Security Place Podcast – Episode 32</title>
		<link>http://feedproxy.google.com/~r/AnInformationSecurityPlace/~3/FSrkbkSWbIg/</link>
		<comments>http://infosecplace.com/blog/2010/02/18/an-information-security-place-podcast-episode-32/#comments</comments>
		<pubDate>Thu, 18 Feb 2010 13:24:35 +0000</pubDate>
		<dc:creator>m1a1vet@infosecplace.com (Michael R. Farnum)</dc:creator>
				<category><![CDATA[Podcasts]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[agent]]></category>
		<category><![CDATA[arrested]]></category>
		<category><![CDATA[Brian Krebs]]></category>
		<category><![CDATA[Chuvakin]]></category>
		<category><![CDATA[dictatorship]]></category>
		<category><![CDATA[Gmail]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Iran]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Schmoocon]]></category>
		<category><![CDATA[Scorecard]]></category>
		<category><![CDATA[Security B-Sides]]></category>
		<category><![CDATA[security conference]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[TSA]]></category>
		<category><![CDATA[Zeus]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1136</guid>
		<description><![CDATA[
OK, holy crap.  We expected this episode to be pretty short since Jim was not around to add his golden commentary, but we got to yappin&#8217; and churned out almost an hour of content (I use that term loosely).  So enjoy the show!
Show Notes:
InfoSec News Update –

Iran Shutters Google&#8217;s Gmail Service, offering own email for [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>

<p>OK, holy crap.  We expected this episode to be pretty short since Jim was not around to add his golden commentary, but we got to yappin&#8217; and churned out almost an hour of content (I use that term loosely).  So enjoy the show!</p>
<p><strong>Show Notes:</strong></p>
<p><strong>InfoSec News Update –</strong></p>
<ul>
<li>Iran Shutters Google&#8217;s Gmail Service, offering own email for citizens &#8211; <a href="http://darkreading.com/security/app-security/showArticle.jhtml?articleID=222900064" target="_blank">Link here</a></li>
<li>Security Scoreboard &#8211; <a href="http://chuvakin.blogspot.com/2010/02/security-scoreboard-out.html" target="_blank">Link here</a></li>
<li>Brian Kreb&#8217;s has blog post used by scammers - <a href="http://www.krebsonsecurity.com/2010/02/warning-about-zeus-attack-used-as-lure/" target="_blank">Link here</a> and Sophos article <a href="http://www.sophos.com/blogs/sophoslabs/?p=8654" target="_blank">link here</a></li>
<li>The Death of Product Reviews (Mike Rothman at Securosis) - <a href="http://securosis.com/blog/death-of-product-reviews" target="_blank">Link here</a></li>
<li>TSA agent arrested for molestation - <a href="http://www.tsa.gov/blog/2010/02/orlando-officer-arrested.html" target="_blank">Link here</a></li>
</ul>
<div id="_mcePaste">
<div id="_mcePaste">We won&#8217;t get intot he details here because this guy is sick, but I had to point out this line from the TSA blog about the issue:</div>
<div id="_mcePaste">&#8220;TSA holds the highest standards for our workforce and this individual&#8217;s actions do not reflect on the more than 50,000 men and women who work every day to keep the traveling public safe.&#8221;</div>
</div>
<div>
<ul>
<li>Hacker threat forces DoH to close appraisal site (Political Activist?) - <a href="http://www.healthcarerepublic.com/news/982894/Hacker-threat-forces-DoH-close-appraisal-site/" target="_blank">Link here</a></li>
</ul>
</div>
<div><strong>Discussion Topic &#8211; </strong>Smaller, more intimate security conferences (Security B-Sides, Schmoocon, etc)</div>
<div>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong></p>
<ul style="clear: both;">
<li>Intro/Outro – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=d65dc8af297fd7a4cc57554b2a826a8e">Digital Breaks – “Therapy”</a></li>
<li>Segway 1 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=3d4e22af2d41713462855383c927ef43" target="_blank">Guitar Slingers &#8211; &#8220;Johnny Dangerously&#8221;</a></li>
<li>Segway 2 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=280202729dad1ad3a780a4d20afbe39b" target="_blank">Matthew Ebel &#8211; &#8220;Trees&#8221;</a></li>
</ul>
<p></strong><strong><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode32.mp3">Link to MP3</a><br />
</strong></p>
</div>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=FSrkbkSWbIg:koL-eJGNIJk:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=FSrkbkSWbIg:koL-eJGNIJk:5lVTG1FW49M"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=5lVTG1FW49M" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=FSrkbkSWbIg:koL-eJGNIJk:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=FSrkbkSWbIg:koL-eJGNIJk:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=FSrkbkSWbIg:koL-eJGNIJk:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=FSrkbkSWbIg:koL-eJGNIJk:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=FSrkbkSWbIg:koL-eJGNIJk:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=FSrkbkSWbIg:koL-eJGNIJk:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=63t7Ie-LG7Y" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2010/02/18/an-information-security-place-podcast-episode-32/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode31.mp3" length="91490432" type="audio/mpeg" />
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode32.mp3" length="63906508" type="audio/mpeg" />
		<media:content url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode31.mp3" fileSize="91490432" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:subtitle> OK, holy crap.  We expected this episode to be pretty short since Jim was not around to add his golden commentary, but we got to yappin&amp;#8217; and churned out almost an hour of content (I use that term loosely).  So enjoy the show! Show Notes: InfoSec Ne</itunes:subtitle><itunes:author>Michael R. Farnum</itunes:author><itunes:summary> OK, holy crap.  We expected this episode to be pretty short since Jim was not around to add his golden commentary, but we got to yappin&amp;#8217; and churned out almost an hour of content (I use that term loosely).  So enjoy the show! Show Notes: InfoSec News Update – Iran Shutters Google&amp;#8217;s Gmail Service, offering own email for [...]</itunes:summary><itunes:keywords>security,Michael,R,Farnum,podcast,blog,information,security,infosec</itunes:keywords><feedburner:origLink>http://infosecplace.com/blog/2010/02/18/an-information-security-place-podcast-episode-32/</feedburner:origLink></item>
		<item>
		<title>An Information Security Place Podcast – Episode 31</title>
		<link>http://feedproxy.google.com/~r/AnInformationSecurityPlace/~3/uyOarGhnbGE/</link>
		<comments>http://infosecplace.com/blog/2010/02/05/an-information-security-place-podcast-episode-31/#comments</comments>
		<pubDate>Fri, 05 Feb 2010 12:58:46 +0000</pubDate>
		<dc:creator>m1a1vet@infosecplace.com (Michael R. Farnum)</dc:creator>
				<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1134</guid>
		<description><![CDATA[

Everyone was here for this episode (meaning Dan, Jim, and Michael), and it was pretty much on schedule this time.  We do the normal cutting up, then talk about news and start discussing stuff.  Then Dan puts the hurt down on some developer geek speak.  You will definitely learn  from stuff from this [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>

<div class="post_content">
<p style="clear: both;">Everyone was here for this episode (meaning Dan, Jim, and Michael), and it was pretty much on schedule this time.  We do the normal cutting up, then talk about news and start discussing stuff.  Then Dan puts the hurt down on some developer geek speak.  You will definitely learn  from stuff from this episode (as opposed to the drivel you get from most of our episodes).  Very good stuff.</p>
<p>BTW, the format of the posts are changing just a bit.  While the podcast player will stay where it usually is at the top of the post, the link to the file will now be below the posts.  This is changing because when iTunes picks up the text from the feed, it throws the &#8220;Link to MP3&#8243; text at the top, and it looks weird when looking at the show description in iTunes.  Just a minor change really, but just wanted to point it out here in case that is where you grab the file.  OK, now on to the show!</p>
<p style="clear: both;"><strong>Show Notes:</strong></p>
<p style="clear: both;"><strong>InfoSec News Update – </strong></p>
<ul style="clear: both;">
<li>Hacker Cracks 49 House Sites and Insults Obama – <a href="http://www.msnbc.msn.com/id/35125467/ns/technology_and_science-security/?GT1=43001">Link Here</a></li>
<li>17 Year Old Vulnerability – <a href="http://www.microsoft.com/technet/security/advisory/979682.mspx">Link Here</a></li>
<li>77K Risk Data Loss in Alaska – <a href="http://www.darkreading.com/insiderthreat/security/privacy/showArticle.jhtml?articleID=222600500">Link Here</a></li>
<li>SEC Workers Surfing Pr0n – <a href="http://www.foxnews.com/politics/2010/02/02/sec-workers-investigated-porn-surfing/">Link Here</a> / <a href="http://www.break.com/index/worker-looks-at-nude-pics-during-news-report.html">BREAK.COM VIDEO Link</a></li>
<li>If your password is 123456, just make it HACKME – <a href="http://www.nytimes.com/2010/01/21/technology/21password.html?em">Link Here</a></li>
<li>ID Thieves Successfully Targeting Wealth Victims – <a href="http://www.darkreading.com/securityservices/security/privacy/showArticle.jhtml?articleID=222600185">Link Here</a></li>
</ul>
<p style="clear: both;"><strong>Discussion Topic #1 – </strong>Laptops on Hostile Networks – <a href="http://www.networkworld.com/news/2010/020310-black-hat-wi-fi-attackers.html?hpg1=bn">Link Here</a></p>
<p style="clear: both;">
<p style="clear: both;"><strong>Discussion Topic #2 -</strong> DK’s Web App Security Minute… and then some <img class="wp-smiley" src="http://www.jimsblog.org/blog/wp-includes/images/smilies/icon_smile.gif" alt=":)" /></p>
<ul style="clear: both;">
<li>Remote File Include Attacks – <a href="http://ha.ckers.org/blog/20100129/large-list-of-rfis-1000/">Link Here</a> / <a href="http://www.ntobjectives.com/research-anatomy-of-rfi-attack"><strong>DK’s Info Page</strong></a></li>
<li>Larry Suto’s New Web App Scanner Review Report -<strong> </strong><a href="http://ha.ckers.org/blog/20100203/accuracy-and-time-costs-of-web-application-security-scanner-report/">Link Here</a></li>
</ul>
<p style="clear: both;"><strong>Music Notes:</strong></p>
<p style="clear: both;"><strong> </strong></p>
<p style="clear: both;"><strong> </strong></p>
<p><strong> </strong></p>
<p><strong></p>
<ul style="clear: both;">
<li>Intro/Outro – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=d65dc8af297fd7a4cc57554b2a826a8e">Digital Breaks – “Therapy”</a></li>
<li>Segway 1 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=6b2fccdd12aaeb7e3fd40fc37d5cda29">Nathan Lee – “Hold Me Down”</a></li>
<li>Segway 2 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?pageNum_MusicList=3&amp;totalRows_MusicList=16&amp;BandHash=a84d881ac3a1f7dddc55cddfd9719126">Building Rome – “Bored”</a></li>
<li>Segway 3 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=53ed9999937c75761728272156dc002c">Devo Spice – “I’m Not Your Personal IT Guy”</a></li>
</ul>
<p><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode31.mp3">Link to MP3</a></p>
<p></strong></p>
</div>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=uyOarGhnbGE:xy3-Z9i6rF0:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=uyOarGhnbGE:xy3-Z9i6rF0:5lVTG1FW49M"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=5lVTG1FW49M" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=uyOarGhnbGE:xy3-Z9i6rF0:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=uyOarGhnbGE:xy3-Z9i6rF0:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=uyOarGhnbGE:xy3-Z9i6rF0:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=uyOarGhnbGE:xy3-Z9i6rF0:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=uyOarGhnbGE:xy3-Z9i6rF0:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=uyOarGhnbGE:xy3-Z9i6rF0:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=63t7Ie-LG7Y" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2010/02/05/an-information-security-place-podcast-episode-31/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode31.mp3" length="91490432" type="audio/mpeg" />
		<media:content url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode31.mp3" fileSize="91490432" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:subtitle> Everyone was here for this episode (meaning Dan, Jim, and Michael), and it was pretty much on schedule this time. We do the normal cutting up, then talk about news and start discussing stuff. Then Dan puts the hurt down on some developer geek speak. You </itunes:subtitle><itunes:author>Michael R. Farnum</itunes:author><itunes:summary> Everyone was here for this episode (meaning Dan, Jim, and Michael), and it was pretty much on schedule this time. We do the normal cutting up, then talk about news and start discussing stuff. Then Dan puts the hurt down on some developer geek speak. You will definitely learn  from stuff from this [...]</itunes:summary><itunes:keywords>security,Michael,R,Farnum,podcast,blog,information,security,infosec</itunes:keywords><feedburner:origLink>http://infosecplace.com/blog/2010/02/05/an-information-security-place-podcast-episode-31/</feedburner:origLink></item>
		<item>
		<title>An Information Security Place Podcast – Episode 30</title>
		<link>http://feedproxy.google.com/~r/AnInformationSecurityPlace/~3/KDUglb20lBg/</link>
		<comments>http://infosecplace.com/blog/2010/01/25/an-information-security-place-podcast-episode-30/#comments</comments>
		<pubDate>Tue, 26 Jan 2010 02:02:00 +0000</pubDate>
		<dc:creator>m1a1vet@infosecplace.com (Michael R. Farnum)</dc:creator>
				<category><![CDATA[Podcasts]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[gaming]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Las Vegas]]></category>
		<category><![CDATA[Mike Tuchen]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Rapid7]]></category>
		<category><![CDATA[Roger Hegland]]></category>
		<category><![CDATA[TruArx]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1126</guid>
		<description><![CDATA[
Link to MP3


The first podcast of the new year is here, and it is a nice round number!  That is sweet!  So please forgive any weirdness in the way this episode sounds.  It was put together over a couple of weeks doing interviews here and there with vendors as well as each other while we were at [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>

<p><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode30.mp3">Link to MP3</a></p>
<div class="post_content">
<p style="clear: both;">
<p style="clear: both;">The first podcast of the new year is here, and it is a nice round number!  That is sweet!  So please forgive any weirdness in the way this episode sounds.  It was put together over a couple of weeks doing interviews here and there with vendors as well as each other while we were at our (Michael and Jim) employer’s annual company meeting.  Jim is a miracle worker, but even he could not make it completely fluid!</p>
<p style="clear: both;">Also, because of scheduling, Dan did not get to join us.  But Jim and I were fortunate enough to be joined by coworker and wireless uber-beast, Mr. Tyler Theys.  I think you will enjoy this episode, even with all the weirdness!</p>
<p style="clear: both;">Show Notes:</p>
<p style="clear: both;"><strong>Info Sec News Update -</strong></p>
<ul style="clear: both;">
<li>Jim, Michael, and Tyler talk about all the Google Hacking – <strong><a href="http://www.computerworlduk.com/community/blogs/index.cfm?entryid=2741&amp;blogid=24">Link Here</a></strong></li>
</ul>
<p style="clear: both;"><strong>Interview #1 -</strong>Michael with Roger Hegland of <a href="http://www.truarx.com/"><strong>TruARX</strong></a></p>
<p style="clear: both;"><strong>Interview #2 -</strong> Jim with Mike Tuchen of <a href="http://www.rapid7.com/"><strong>Rapid7</strong></a></p>
<p style="clear: both;"><strong><em>“Added Bonus to Our Listeners”</em></strong></p>
<p><em>Going to RSA? Join Rapid7 on March 3<sup>rd</sup> for a party at Ruby Skye. Get on the VIP list for the evening everyone else will be talking about at RSA 2010: </em><em><span style="text-decoration: underline;"><strong><a href="http://www.rapid7.com/forms/rsarsvp.jsp">www.rapid7.com/forms/rsarsvp.jsp</a></strong><br />
</span></em></p>
<p style="clear: both;"><strong>Discussion Topic -</strong> PCI in the Gaming Industry</p>
<p style="clear: both;"><strong>Music Notes – </strong></p>
<ul style="clear: both;">
<li>Intro/Outro – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=d65dc8af297fd7a4cc57554b2a826a8e">Digital Breaks – “Therapy”</a></li>
<li>Segway 1 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=a84d881ac3a1f7dddc55cddfd9719126">Building Rome – “Dr. Doctor”</a></li>
<li>Segway 2 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=1089a8c084a1d803912e89f8b9cc6051">Megaphone – “Write it Down”</a></li>
<li>Segway 3 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?pageNum_MusicList=1&amp;totalRows_MusicList=7&amp;BandHash=4dc3e9f44e4ce8bcbbc83d56575f1300">This is Fiction – “Breathe”</a></li>
</ul>
</div>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=KDUglb20lBg:P2_e99j84hU:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=KDUglb20lBg:P2_e99j84hU:5lVTG1FW49M"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=5lVTG1FW49M" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=KDUglb20lBg:P2_e99j84hU:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=KDUglb20lBg:P2_e99j84hU:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=KDUglb20lBg:P2_e99j84hU:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=KDUglb20lBg:P2_e99j84hU:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=KDUglb20lBg:P2_e99j84hU:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=KDUglb20lBg:P2_e99j84hU:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=63t7Ie-LG7Y" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2010/01/25/an-information-security-place-podcast-episode-30/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode29.mp3" length="86507648" type="audio/mpeg" />
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode30.mp3" length="86642816" type="audio/mpeg" />
		<media:content url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode29.mp3" fileSize="86507648" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:subtitle> Link to MP3 The first podcast of the new year is here, and it is a nice round number!  That is sweet!  So please forgive any weirdness in the way this episode sounds.  It was put together over a couple of weeks doing interviews here and there with vendor</itunes:subtitle><itunes:author>Michael R. Farnum</itunes:author><itunes:summary> Link to MP3 The first podcast of the new year is here, and it is a nice round number!  That is sweet!  So please forgive any weirdness in the way this episode sounds.  It was put together over a couple of weeks doing interviews here and there with vendors as well as each other while we were at [...]</itunes:summary><itunes:keywords>security,Michael,R,Farnum,podcast,blog,information,security,infosec</itunes:keywords><feedburner:origLink>http://infosecplace.com/blog/2010/01/25/an-information-security-place-podcast-episode-30/</feedburner:origLink></item>
		<item>
		<title>An Information Security Place Podcast – Episode 29</title>
		<link>http://feedproxy.google.com/~r/AnInformationSecurityPlace/~3/pbFBeJRZyrw/</link>
		<comments>http://infosecplace.com/blog/2009/12/23/an-information-security-place-podcast-episode-29/#comments</comments>
		<pubDate>Wed, 23 Dec 2009 14:48:46 +0000</pubDate>
		<dc:creator>m1a1vet@infosecplace.com (Michael R. Farnum)</dc:creator>
				<category><![CDATA[Podcasts]]></category>
		<category><![CDATA[2009]]></category>
		<category><![CDATA[2010. Adobe]]></category>
		<category><![CDATA[buggy]]></category>
		<category><![CDATA[COFEE]]></category>
		<category><![CDATA[Cybersecurity coordinator]]></category>
		<category><![CDATA[DECAF]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[drones]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Howard Schmidt]]></category>
		<category><![CDATA[Merry Christmas]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1123</guid>
		<description><![CDATA[
Link to MP3

Merry Christmas to all our listeners!  It&#8217;s that time of the year again where we sit down and make a fun podcast and recap the year and look forward to next year. Heck there was even a Christmas Miracle on this episode… it was actually recorded on time !!!!  So sit [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>

<p><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode29.mp3">Link to MP3</a></p>
<div class="post_content">
<p style="clear: both">Merry Christmas to all our listeners!  It&#8217;s that time of the year again where we sit down and make a fun podcast and recap the year and look forward to next year. Heck there was even a Christmas Miracle on this episode… it was actually recorded on time !!!!  So sit back with your eggnog next to the Yule log fire under the stockings and enjoy!</p>
<p style="clear: both"><strong>Show Notes:</strong></p>
<p><strong>InfoSec News Update – </strong></p>
<ul style="clear: both">
<li>Howard Schmidt new White House cybersecurity coordinator – <a href="http://www.computerworld.com/s/article/9142579/Schmidt_tapped_as_White_House_cybersecurity_coordinator">Link Here</a></li>
<li>deCOFEEnating Windows – <a href="http://www.h-online.com/security/news/item/New-tool-deCOFEEnates-Windows-systems-885688.html">Link Here</a></li>
<li>Twitter DNS hack came from authorized credentials – <a href="http://voices.washingtonpost.com/securityfix/2009/12/twittercom_hijacked_by_iranian.html">Link Here</a></li>
<li>Social Networks searches could be a hackers dream… <a href="http://www.usatoday.com/tech/news/2009-12-14-searchsecurity14_ST_N.htm">Link 1</a> / <a href="http://www.paterva.com/web4/index.php/maltego">Link 2</a></li>
<li>FireFox and Adobe named “Most Buggy” – <a href="http://news.cnet.com/8301-27080_3-10417785-245.html">Link Here</a> / <a href="http://www.bit9.com/news-events/press-release-details.php?id=140">Bit9 Link</a></li>
<li>Insurgents Hack US Drones – <a href="http://online.wsj.com/article/SB126102247889095011.html?mod=wsj_share_twitter">Link Here</a> / <a href="http://www.skygrabber.com/en/index.php">Software Link</a></li>
</ul>
<p style="clear: both"><strong>Discussion Topic -</strong></p>
<p style="clear: both">2009 Year in Review and Looking Forward Predictions to 2010 –</p>
<p style="clear: both"><a href="http://www.darkreading.com/vulnerability_management/security/attacks/showArticle.jhtml?articleID=222003008">Link 1</a> / <a href="http://securityblog.verizonbusiness.com/2009/12/15/2010-security-predictions/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+verizonbusiness%2FtWvQ+%28Verizon+Business+Security+Blog%29 http://securityblog.verizonbusiness.com/2009/12/15/2010-security-predictions/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+verizonbusiness%2FtWvQ+%28Verizon+Business+Security+Blog%29 http://securityblog.verizonbusiness.com/2009/12/15/2010-security-predictions/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+verizonbusiness%2FtWvQ+%28Verizon+Business+Security+Blog%29 http://securityblog.verizonbusiness.com/2009/12/15/2010-security-predictions/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+verizonbusiness%2FtWvQ+%28Verizon+Business+Security+Blog%29">Link 2</a> / <a href="http://www.greebo.net/2009/12/18/web-app-sec-predictions-for-2010/">Link 3</a></p>
<p style="clear: both"><strong>Music Notes -</strong></p>
<p style="clear: both">
<ul style="clear: both">
<li>Intro – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=94354662c286953389e4b053406665ba">TheHipCola – “SleighRide”</a></li>
<li>Segway 1 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=082e5aa3474a24d58c17e9f91c210311">Winzenried – “Have Yourself A Merry Little Christmas”</a></li>
<li>Segway 2 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=7d112cb6e6d69c810497671ae56fb618">OutSpoken – “Punk Rock Bells”</a></li>
<li>Outro – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=94354662c286953389e4b053406665ba">TheHipCola – “Winter WonderLand”</a></li>
</ul>
</div>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=pbFBeJRZyrw:qV5Qle5Q8L8:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=pbFBeJRZyrw:qV5Qle5Q8L8:5lVTG1FW49M"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=5lVTG1FW49M" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=pbFBeJRZyrw:qV5Qle5Q8L8:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=pbFBeJRZyrw:qV5Qle5Q8L8:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=pbFBeJRZyrw:qV5Qle5Q8L8:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=pbFBeJRZyrw:qV5Qle5Q8L8:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=pbFBeJRZyrw:qV5Qle5Q8L8:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=pbFBeJRZyrw:qV5Qle5Q8L8:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=63t7Ie-LG7Y" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2009/12/23/an-information-security-place-podcast-episode-29/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode29.mp3" length="86507648" type="audio/mpeg" />
		<media:content url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode29.mp3" fileSize="86507648" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:subtitle> Link to MP3 Merry Christmas to all our listeners! It&amp;#8217;s that time of the year again where we sit down and make a fun podcast and recap the year and look forward to next year. Heck there was even a Christmas Miracle on this episode… it was actually r</itunes:subtitle><itunes:author>Michael R. Farnum</itunes:author><itunes:summary> Link to MP3 Merry Christmas to all our listeners! It&amp;#8217;s that time of the year again where we sit down and make a fun podcast and recap the year and look forward to next year. Heck there was even a Christmas Miracle on this episode… it was actually recorded on time !!!! So sit [...]</itunes:summary><itunes:keywords>security,Michael,R,Farnum,podcast,blog,information,security,infosec</itunes:keywords><feedburner:origLink>http://infosecplace.com/blog/2009/12/23/an-information-security-place-podcast-episode-29/</feedburner:origLink></item>
		<item>
		<title>An Information Security Place Podcast – Episode 28</title>
		<link>http://feedproxy.google.com/~r/AnInformationSecurityPlace/~3/1vQE3O78F4o/</link>
		<comments>http://infosecplace.com/blog/2009/12/11/an-information-security-place-podcast-episode-28/#comments</comments>
		<pubDate>Fri, 11 Dec 2009 13:49:11 +0000</pubDate>
		<dc:creator>m1a1vet@infosecplace.com (Michael R. Farnum)</dc:creator>
				<category><![CDATA[Podcasts]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[cracking]]></category>
		<category><![CDATA[DHS]]></category>
		<category><![CDATA[felon]]></category>
		<category><![CDATA[Gunnar]]></category>
		<category><![CDATA[Marlinspike]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Moxie]]></category>
		<category><![CDATA[Nessus]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[ProxMark3]]></category>
		<category><![CDATA[Rapid7]]></category>
		<category><![CDATA[Salahis]]></category>
		<category><![CDATA[TSA]]></category>
		<category><![CDATA[WPA]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1119</guid>
		<description><![CDATA[
Link to MP3
OK, this was just a stupid, crazy, and fun episode.  We had technical hiccups, a roving co-host that likes to text another cohost during recording, plus this episode is late getting recorded because of end-of-year schedule.  But we powered through it, and Jim got to spend a lot of time on post-production.
I think [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>
<p><br />
<a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode28.mp3">Link to MP3</a></p>
<p style="clear: both">OK, this was just a stupid, crazy, and fun episode.  We had technical hiccups, a roving co-host that likes to text another cohost during recording, plus this episode is late getting recorded because of end-of-year schedule.  But we powered through it, and Jim got to spend a lot of time on post-production.</p>
<p style="clear: both">I think you are going to enjoy this randomness&#8230;</p>
<p style="clear: both"><strong>Show Notes:</strong></p>
<p style="clear: both"><strong>InfoSec News Update and Geek Toys Update – </strong></p>
<ul style="clear: both">
<li>T-Mobile Employee causes largest data theft in the UK – <a href="http://www.darkreading.com/database_security/security/privacy/showArticle.jhtml?articleID=221900209">Link Here</a></li>
<li>Government Security Woes<br />
Story 1 – 5 TSA workers put on leave over online posting – <a href="http://www.msnbc.msn.com/id/34346213/ns/travel-news/?gt1=43001">Link here</a><br />
Story 2 – The Party Crashing Scandal – <a href="http://www.foxnews.com/politics/2009/11/30/rep-white-house-crashers-says-couple-interested-media-interviews/">Link Here</a><br />
Story 3 – Felon working for DHS for 2 years – <a href="http://www.theregister.co.uk/2009/12/10/dhs_fugitive/">Link Here</a></li>
<li>Nessus 4.2 is released – <a href="http://www.tenablesecurity.com">Link Here</a></li>
<li>Rapid7 and Metasploit Community Projects – <a href="http://www.metasploit.com/framework/">Link 1</a> / <a href="http://www.rapid7.com/nexposecommunitydownload.jsp">Link 2</a></li>
<li>ProxMark3 now shipping completed RFID read/write/clone kits – <a href="http://www.proxmark3.com/">Link here</a></li>
<li>Moxie launched cloud-based WPA password Cracking – <a href="http://blogs.zdnet.com/BTL/?p=28224 ">Link Here</a></li>
<li>Cure for Eye Strain – Gunnar Glasses – <a href="http://www.gunnars.com/gunnar_indoor_collection.php">Link Here</a></li>
</ul>
<p style="clear: both"><strong>Discussion Topic -</strong></p>
<p style="clear: both">Changes to OWASP standard for 2010 –</p>
<p style="clear: both"><a href="http://www.owasp.org/index.php/File:OWASP_T10_-_2010_rc1.pdf">Link Here</a></p>
<p style="clear: both"><strong>Consultants Corner -</strong> Picking your tools wisely… 2009/2010 update</p>
<p style="clear: both"><strong>Music Notes – </strong></p>
<ul style="clear: both">
<li>Intro/Outro – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=d65dc8af297fd7a4cc57554b2a826a8e">Digital Breaks – “Therapy”</a></li>
<li>Segway 1 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?pageNum_MusicList=1&amp;totalRows_MusicList=7&amp;BandHash=4dc3e9f44e4ce8bcbbc83d56575f1300">This is Fiction – “Breathe”</a></li>
<li>Segway 2 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=9f82d2117026d7ba7595c8161d91ec17">Patent Pending – “Los Angeles”</a></li>
<li>Segway 3 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?pageNum_MusicList=2&amp;totalRows_MusicList=331&amp;BandHash=53ed9999937c75761728272156dc002c">The FUMP – “”All You Can Tweet”</a></li>
</ul>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=1vQE3O78F4o:GRS-wKc--Vo:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=1vQE3O78F4o:GRS-wKc--Vo:5lVTG1FW49M"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=5lVTG1FW49M" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=1vQE3O78F4o:GRS-wKc--Vo:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=1vQE3O78F4o:GRS-wKc--Vo:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=1vQE3O78F4o:GRS-wKc--Vo:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=1vQE3O78F4o:GRS-wKc--Vo:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=1vQE3O78F4o:GRS-wKc--Vo:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=1vQE3O78F4o:GRS-wKc--Vo:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=63t7Ie-LG7Y" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2009/12/11/an-information-security-place-podcast-episode-28/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode28.mp3" length="73980032" type="audio/mpeg" />
		<media:content url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode28.mp3" fileSize="73980032" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:subtitle> Link to MP3 OK, this was just a stupid, crazy, and fun episode.  We had technical hiccups, a roving co-host that likes to text another cohost during recording, plus this episode is late getting recorded because of end-of-year schedule.  But we powered th</itunes:subtitle><itunes:author>Michael R. Farnum</itunes:author><itunes:summary> Link to MP3 OK, this was just a stupid, crazy, and fun episode.  We had technical hiccups, a roving co-host that likes to text another cohost during recording, plus this episode is late getting recorded because of end-of-year schedule.  But we powered through it, and Jim got to spend a lot of time on post-production. I think [...]</itunes:summary><itunes:keywords>security,Michael,R,Farnum,podcast,blog,information,security,infosec</itunes:keywords><feedburner:origLink>http://infosecplace.com/blog/2009/12/11/an-information-security-place-podcast-episode-28/</feedburner:origLink></item>
		<item>
		<title>An Information Security Place Podcast – Episode 27</title>
		<link>http://feedproxy.google.com/~r/AnInformationSecurityPlace/~3/Dte9XZmgR4Y/</link>
		<comments>http://infosecplace.com/blog/2009/11/12/an-information-security-place-podcast-episode-27/#comments</comments>
		<pubDate>Thu, 12 Nov 2009 12:51:51 +0000</pubDate>
		<dc:creator>m1a1vet@infosecplace.com (Michael R. Farnum)</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Acer]]></category>
		<category><![CDATA[BBQ]]></category>
		<category><![CDATA[chief]]></category>
		<category><![CDATA[ChoicePoint]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Dell]]></category>
		<category><![CDATA[DigiQ]]></category>
		<category><![CDATA[FDIC]]></category>
		<category><![CDATA[FTC]]></category>
		<category><![CDATA[Houston]]></category>
		<category><![CDATA[ikee]]></category>
		<category><![CDATA[jailbreak]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[NAISG]]></category>
		<category><![CDATA[NAS]]></category>
		<category><![CDATA[Netbook]]></category>
		<category><![CDATA[Nvidia]]></category>
		<category><![CDATA[Obama]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Windows 7]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1115</guid>
		<description><![CDATA[
Link to MP3

OK, Episode 27 is FINALLY here.  Sincere apologies to all of our listeners.  We really could not avoid the long break.  Work and family and everything else seriously pounded us this time.  ENJOY!
Show Notes:
InfoSec News Update -

FTC Orders ChoicePoint To Pay $275,000 For 2008 Data Breach – Link Here
Senator [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>

<p><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode27.mp3">Link to MP3</a></p>
<div class="post_content">
<p style="clear: both">OK, Episode 27 is FINALLY here.  Sincere apologies to all of our listeners.  We really could not avoid the long break.  Work and family and everything else seriously pounded us this time.  ENJOY!</p>
<p style="clear: both"><strong>Show Notes:</strong></p>
<p style="clear: both"><strong>InfoSec News Update -</strong></p>
<ul style="clear: both">
<li>FTC Orders ChoicePoint To Pay $275,000 For 2008 Data Breach – <a href="http://www.darkreading.com/database_security/security/app-security/showArticle.jhtml?articleID=220900031">Link Here</a></li>
<li>Senator says the cybersecurity chief should be in DHS, not the White house – <a href="http://www.computerworld.com/s/article/9140307/Put_cybersecurity_chief_in_DHS_not_the_White_House_Senator_says?taxonomyId=82">Link Here</a></li>
<li>Major SSL Flaw Find Prompts Protocol Update – <a href="http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=221600523">Link Here</a></li>
<li>Jailbroken iPhones more vulnerable to attack; ikee worm Rick Rolls iPhone users – <a href="http://www.computerworld.com/s/article/9140699/Hackers_pillage_jailbroken_iPhones?taxonomyId=82">Link Here</a></li>
<li>New FDIC Phishing Attack – <a href="http://www.fdic.gov/consumers/consumer/alerts/index.html">Link Here</a></li>
<li>MSFT trying to walk the annoyance / security fine line with toned down User Access Control (UAC) in Windows 7 – <a href="http://www.computerworld.com/s/article/9140323/Microsoft_neutered_UAC_in_Windows_7_says_researcher?taxonomyId=145">Link Here</a></li>
<li>Awesomely funny story about an IT engineer in Iraq annoying the troops with some bogus war driving – <a href="http://blogs.computerworld.com/15012/the_fobbit">Link Here</a></li>
</ul>
<p style="clear: both"><strong>Discussion Topic -</strong> Highlights from Michael’s NAISG Chapter Meeting</p>
<p style="clear: both"><strong>Geek Toys – “Ideas to get your Geek for Christmas”</strong></p>
<ul style="clear: both">
<li>Still Need A Netbook? Try and <a href="http://www.officemax.com/technology/computers/netbook-computers/product-prod2550242">Acer</a> or a <a href="http://www.dell.com/home/netbooks">Dell</a></li>
<li>Playing with GPU Acceleration – <a href="http://www.newegg.com/Product/Product.aspx?Item=N82E16814125294&amp;cm_re=gtx_260-_-14-125-294-_-Product">The Nvidia GTX 260 is a great choice</a></li>
<li>Windows 7 – <a href="http://store.microsoft.com/Windows7/Compare">Pick your favorite version</a></li>
<li>Network Attached Storage – <a href="http://www.netgear.com/Products/Storage/ReadyNASDuo.aspx">2 Drive</a> / <a href="http://www.qnap.com/pro_detail_feature.asp?p_id=127">4 Drive</a> / <a href="http://www.qnap.com/pro_detail_feature.asp?p_id=109">8 Drive</a> Solutions</li>
<li>Make Perfect BBQ everytime – <a href="http://secure.thebbqguru.com/ProductCart/pc/viewPrd.asp?idcategory=49&amp;idproduct=235">DigiQ system from thebbqguru.com</a></li>
</ul>
<p style="clear: both"><strong>Music notes -</strong></p>
<ul style="clear: both">
<li>Intro/Outro – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=d65dc8af297fd7a4cc57554b2a826a8e">Digital Breaks – “Therapy”</a></li>
<li>Segway 1 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=6b2fccdd12aaeb7e3fd40fc37d5cda29">Nathan Lee – “Hold Me Down”</a></li>
<li>Segway 2 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?pageNum_MusicList=1&amp;totalRows_MusicList=9&amp;BandHash=49cc3a9880475e71522596bdaa3dcb4d">Junk Yard Groove – “Its OK”</a></li>
<li>Segway 3 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=53ed9999937c75761728272156dc002c">Great Luke SKI – “Parents Bought Me intellivision”</a></li>
</ul>
</div>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=Dte9XZmgR4Y:jRCPPQuyOEc:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=Dte9XZmgR4Y:jRCPPQuyOEc:5lVTG1FW49M"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=5lVTG1FW49M" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=Dte9XZmgR4Y:jRCPPQuyOEc:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=Dte9XZmgR4Y:jRCPPQuyOEc:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=Dte9XZmgR4Y:jRCPPQuyOEc:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=Dte9XZmgR4Y:jRCPPQuyOEc:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=Dte9XZmgR4Y:jRCPPQuyOEc:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=Dte9XZmgR4Y:jRCPPQuyOEc:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=63t7Ie-LG7Y" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2009/11/12/an-information-security-place-podcast-episode-27/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode27.mp3" length="58497152" type="audio/mpeg" />
		<media:content url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode27.mp3" fileSize="58497152" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:subtitle> Link to MP3 OK, Episode 27 is FINALLY here. Sincere apologies to all of our listeners. We really could not avoid the long break. Work and family and everything else seriously pounded us this time. ENJOY! Show Notes: InfoSec News Update - FTC Orders Choic</itunes:subtitle><itunes:author>Michael R. Farnum</itunes:author><itunes:summary> Link to MP3 OK, Episode 27 is FINALLY here. Sincere apologies to all of our listeners. We really could not avoid the long break. Work and family and everything else seriously pounded us this time. ENJOY! Show Notes: InfoSec News Update - FTC Orders ChoicePoint To Pay $275,000 For 2008 Data Breach – Link Here Senator [...]</itunes:summary><itunes:keywords>security,Michael,R,Farnum,podcast,blog,information,security,infosec</itunes:keywords><feedburner:origLink>http://infosecplace.com/blog/2009/11/12/an-information-security-place-podcast-episode-27/</feedburner:origLink></item>
		<item>
		<title>An Information Security Place Podcast – Episode 26</title>
		<link>http://feedproxy.google.com/~r/AnInformationSecurityPlace/~3/-wBH4fdx8B4/</link>
		<comments>http://infosecplace.com/blog/2009/10/01/an-information-security-place-podcast-episode-26/#comments</comments>
		<pubDate>Thu, 01 Oct 2009 10:51:19 +0000</pubDate>
		<dc:creator>m1a1vet@infosecplace.com (Michael R. Farnum)</dc:creator>
				<category><![CDATA[Podcasts]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AV]]></category>
		<category><![CDATA[bad]]></category>
		<category><![CDATA[behavior]]></category>
		<category><![CDATA[grid]]></category>
		<category><![CDATA[Houston]]></category>
		<category><![CDATA[Marketing]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[NAISG]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[power]]></category>
		<category><![CDATA[Rsnake]]></category>
		<category><![CDATA[security consulting]]></category>
		<category><![CDATA[Star Trek]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[WAF]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1110</guid>
		<description><![CDATA[
 
Link to MP3

Episode 26 is here.  It almost didn&#8217;t happen since I was playing remote helpdesk dude for a relative from my hotel room in Dallas right before the recording, but we got it worked out.  Enjoy!
Show Notes:
InfoSec News Update – 

Michael’s New NAISG Group are having their first meeting on Nov 2, 2009 in [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>
<p> </p>
<p><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode26.mp3">Link to MP3</a></p>
<div class="post_content">
<p style="clear: both">Episode 26 is here.  It almost didn&#8217;t happen since I was playing remote helpdesk dude for a relative from my hotel room in Dallas right before the recording, but we got it worked out.  Enjoy!</p>
<p style="clear: both"><strong>Show Notes:</strong></p>
<p style="clear: both"><strong><span style="text-decoration: underline;">InfoSec News Update – </span></strong></p>
<ul style="clear: both">
<li>Michael’s New NAISG Group are having their first meeting on Nov 2, 2009 in Houston, TX. – <a href="http://houston.naisg.org">Houston Chapter Website</a> / <a href="http://chair-houston@naisg.org">Email Link</a><span style="text-decoration: underline;"><br />
</span></li>
<li>Power Grid Takedown – a HowTO – <a href="http://www.theregister.co.uk/2009/09/16/power_grid_weakness/">Link Here</a></li>
<li>Court Ruling – Disloyal Computing is Not Illegal – <a href="http://www.wired.com/threatlevel/2009/09/disloyalcomputing/">Link Here</a></li>
<li>New OWASP Sponsored Web App Firewall – <a href="http://www.darkreading.com/security/app-security/showArticle.jhtml?articleID=220100630">Link Here</a></li>
<li>MS Gets into the AV Game … Again…with latest release – <a href="http://blogs.pcmag.com/securitywatch/2009/09/microsoft_security_essentials.php">Link 1</a> / <a href="http://news.techworld.com/security/3202965/rivals-mock-microsoft-security-essentials-download/?olo=rss">Link 2</a></li>
<li>Trojans getting Smarter – <a href="http://www.h-online.com/security/Trojan-hides-in-Windows-recovery--/news/114322">Link Here</a><span style="text-decoration: underline;"><br />
</span></li>
<li>PCI DSS Update Could Include Virtualization Security – <a href=" http://www.darkreading.com/database_security/security/government/showArticle.jhtml?articleID=220200260">Link Here</a></li>
</ul>
<p style="clear: both"><strong><span style="text-decoration: underline;">Discussion Topic -</span></strong></p>
<p style="clear: both">Encouraging Bad Behavior via marketing (Identity Guard Commercials)</p>
<p style="clear: both"> </p>
<p style="clear: both"><strong><span style="text-decoration: underline;">Consultants Corner -</span></strong> Predicting what Security Consulting will be like in the future – <a href="http://ha.ckers.org/blog/20090918/what-star-trek-predicts-about-the-future-of-information-security/">Link Here</a><span style="text-decoration: underline;"><br />
</span></p>
<p style="clear: both"><strong><span style="text-decoration: underline;">Music notes – </span></strong></p>
<ul style="clear: both">
<li>Intro/Outro – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=d65dc8af297fd7a4cc57554b2a826a8e">Digital Breaks – “Therapy”</a></li>
<li>Segway 1 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=4a9250fbcd40a316a120f27af824054f">SwampdaWamp – “Lady”</a></li>
<li>Segway 2 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=a84d881ac3a1f7dddc55cddfd9719126">Building Rome – “Dr. Doctor”</a></li>
<li>Segway 3 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=5d22a6793650e9303f9b611f67e7d294">The Summer Set – “Chelsea”</a><span style="text-decoration: underline;"><br />
</span></li>
</ul>
<p> Vet</p></div>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=-wBH4fdx8B4:SuPhrK6VhVU:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=-wBH4fdx8B4:SuPhrK6VhVU:5lVTG1FW49M"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=5lVTG1FW49M" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=-wBH4fdx8B4:SuPhrK6VhVU:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=-wBH4fdx8B4:SuPhrK6VhVU:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=-wBH4fdx8B4:SuPhrK6VhVU:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=-wBH4fdx8B4:SuPhrK6VhVU:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=-wBH4fdx8B4:SuPhrK6VhVU:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=-wBH4fdx8B4:SuPhrK6VhVU:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=63t7Ie-LG7Y" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2009/10/01/an-information-security-place-podcast-episode-26/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode26.mp3" length="60579968" type="audio/mpeg" />
		<media:content url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode26.mp3" fileSize="60579968" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>   Link to MP3 Episode 26 is here.  It almost didn&amp;#8217;t happen since I was playing remote helpdesk dude for a relative from my hotel room in Dallas right before the recording, but we got it worked out.  Enjoy! Show Notes: InfoSec News Update – Michael’</itunes:subtitle><itunes:author>Michael R. Farnum</itunes:author><itunes:summary>   Link to MP3 Episode 26 is here.  It almost didn&amp;#8217;t happen since I was playing remote helpdesk dude for a relative from my hotel room in Dallas right before the recording, but we got it worked out.  Enjoy! Show Notes: InfoSec News Update – Michael’s New NAISG Group are having their first meeting on Nov 2, 2009 in [...]</itunes:summary><itunes:keywords>security,Michael,R,Farnum,podcast,blog,information,security,infosec</itunes:keywords><feedburner:origLink>http://infosecplace.com/blog/2009/10/01/an-information-security-place-podcast-episode-26/</feedburner:origLink></item>
		<item>
		<title>An Information Security Place Podcast – Episode 25</title>
		<link>http://feedproxy.google.com/~r/AnInformationSecurityPlace/~3/CsCA1FTSkfQ/</link>
		<comments>http://infosecplace.com/blog/2009/09/15/an-information-security-place-podcast-episode-25/#comments</comments>
		<pubDate>Wed, 16 Sep 2009 02:00:01 +0000</pubDate>
		<dc:creator>m1a1vet@infosecplace.com (Michael R. Farnum)</dc:creator>
				<category><![CDATA[Podcasts]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[GhostExodus]]></category>
		<category><![CDATA[SCADA]]></category>
		<category><![CDATA[Wesley McGrew]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1107</guid>
		<description><![CDATA[
Link to MP3
Episode 25 is here.  Today&#8217;s podcast is different than our usual.  Instead of having Jim, Dan, and me spout off and pontificate, I am interviewing Wesley McGrew from McGrew Security.  Wesley is a security researcher at Mississippi State University&#8217;s Critical Infrastructure Protection Center, where he works to find vulnerabilities in SCADA software.  He [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>

<p><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode25.mp3">Link to MP3</a></p>
<p>Episode 25 is here.  Today&#8217;s podcast is different than our usual.  Instead of having Jim, Dan, and me spout off and pontificate, I am interviewing Wesley McGrew from McGrew Security.  Wesley is a security researcher at Mississippi State University&#8217;s Critical Infrastructure Protection Center, where he works to find vulnerabilities in SCADA software.  He also operates <a href="http://mcgrewsecurity.com/">mcgrewsecurity.com</a> , where he blogs about information security topics.</p>
<p>Wesley caught a script-kiddie back in June trying to do some pretty weak SCADA hacking at a Dallas-area hospital.  He and I talked about the incident and also discussed some of Wesley&#8217;s future plan (not much since he couldn&#8217;t divulge a lot &#8211; oooo, mysterious!).  So enjoy the show.  Links to the blog posts from Wesley&#8217;s script kiddie adventure are below.</p>
<p><a href="http://www.mcgrewsecurity.com/2009/06/30/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-1/">http://www.mcgrewsecurity.com/2009/06/30/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-1/</a></p>
<p><a href="http://www.mcgrewsecurity.com/2009/07/02/ghostexodus-part2/">http://www.mcgrewsecurity.com/2009/07/02/ghostexodus-part2/</a></p>
<p><a href="http://www.mcgrewsecurity.com/2009/07/06/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-3/">http://www.mcgrewsecurity.com/2009/07/06/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-3/</a></p>
<p><a href="http://www.mcgrewsecurity.com/2009/07/07/ghostexodus-part4/">http://www.mcgrewsecurity.com/2009/07/07/ghostexodus-part4/</a></p>
<p>Vet</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=CsCA1FTSkfQ:_tVu0pB1_oA:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=CsCA1FTSkfQ:_tVu0pB1_oA:5lVTG1FW49M"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=5lVTG1FW49M" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=CsCA1FTSkfQ:_tVu0pB1_oA:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=CsCA1FTSkfQ:_tVu0pB1_oA:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=CsCA1FTSkfQ:_tVu0pB1_oA:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=CsCA1FTSkfQ:_tVu0pB1_oA:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=CsCA1FTSkfQ:_tVu0pB1_oA:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=CsCA1FTSkfQ:_tVu0pB1_oA:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=63t7Ie-LG7Y" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2009/09/15/an-information-security-place-podcast-episode-25/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode25.mp3" length="50219912" type="audio/mpeg" />
		<media:content url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode25.mp3" fileSize="50219912" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:subtitle> Link to MP3 Episode 25 is here.  Today&amp;#8217;s podcast is different than our usual.  Instead of having Jim, Dan, and me spout off and pontificate, I am interviewing Wesley McGrew from McGrew Security.  Wesley is a security researcher at Mississippi State</itunes:subtitle><itunes:author>Michael R. Farnum</itunes:author><itunes:summary> Link to MP3 Episode 25 is here.  Today&amp;#8217;s podcast is different than our usual.  Instead of having Jim, Dan, and me spout off and pontificate, I am interviewing Wesley McGrew from McGrew Security.  Wesley is a security researcher at Mississippi State University&amp;#8217;s Critical Infrastructure Protection Center, where he works to find vulnerabilities in SCADA software.  He [...]</itunes:summary><itunes:keywords>security,Michael,R,Farnum,podcast,blog,information,security,infosec</itunes:keywords><feedburner:origLink>http://infosecplace.com/blog/2009/09/15/an-information-security-place-podcast-episode-25/</feedburner:origLink></item>
		<item>
		<title>An Information Security Place Podcast – Episode 24</title>
		<link>http://feedproxy.google.com/~r/AnInformationSecurityPlace/~3/6m1KWVIIxVc/</link>
		<comments>http://infosecplace.com/blog/2009/09/03/an-information-security-place-podcast-episode-24/#comments</comments>
		<pubDate>Thu, 03 Sep 2009 14:09:49 +0000</pubDate>
		<dc:creator>m1a1vet@infosecplace.com (Michael R. Farnum)</dc:creator>
				<category><![CDATA[Podcasts]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Card skimming]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Credit Unions]]></category>
		<category><![CDATA[flaw]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[ipod Touch]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Safari]]></category>
		<category><![CDATA[Sears]]></category>
		<category><![CDATA[SkyJack]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[TKIP broken]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[web app firewalls]]></category>
		<category><![CDATA[Web app scanners]]></category>
		<category><![CDATA[website]]></category>
		<category><![CDATA[WLAN]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1102</guid>
		<description><![CDATA[
Link to MP3

Hello all you happy people!  Episode 24 is here.  I was out sick, so Jim and Dan put it together. Jim is adamant about sticking to a schedule. Dang slave driver!
Show Notes:
InfoSec News Update – 

Credit Unions Under Attack – Link 1 / Link 2
Massive SQL Injection Attacks – Link 1 / Link2
Cisco [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img class="alignnone size-medium wp-image-21" title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>

<p><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode24.mp3">Link to MP3</a></p>
<div class="post_content">
<p style="clear: both">Hello all you happy people!  Episode 24 is here.  I was out sick, so Jim and Dan put it together. Jim is adamant about sticking to a schedule. Dang slave driver!</p>
<p style="clear: both">Show Notes:</p>
<p style="clear: both"><strong>InfoSec News Update – </strong></p>
<ul style="clear: both">
<li>Credit Unions Under Attack – <strong></strong><a href="http://threatpost.com/blogs/attackers-sending-malware-infected-cds-credit-unions-127 ">Link 1</a> / <a href="http://www.ncua.gov/news/press_releases/2009/MR09-0825a.htm">Link 2</a></li>
<li>Massive SQL Injection Attacks – <a href="http://www.scmagazineus.com/Mass-SQL-injection-attacks-still-scaling-up/article/147490/">Link 1</a> / <a href="http://www.securityfocus.com/brief/1001?ref=rss">Link2</a></li>
<li>Cisco Wireless LANS get “Skyjacked” – <a href="http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=219401274">Link 1</a> / <a href="http://tools.cisco.com/security/center/viewAlert.x?alertId=18919">Link 2</a></li>
<li>Flaw in Sear’s Website Left Database Open To Attack – <a href="http://www.darkreading.com/database_security/security/app-security/showArticle.jhtml?articleID=219500830&amp;cid=nl_DR_DAILY_T">Link Here</a></li>
<li>WPA/TKIP Can be Broken in 1 Minute – <a href="http://jwis2009.nsysu.edu.tw/location/paper/A%20Practical%20Message%20Falsification%20Attack%20on%20WPA.pdf">Link 1</a> / <a href="http://seclists.org/dailydave/2009/q3/0091.html">Link 2</a></li>
<li>100 Dirtiest Web Sites of Summer 2009 – <a href="http://www.mightyseek.com/web-application-security/dirtiest-web-sites-of-summer-2009">Link Here</a></li>
<li>No Thumbprint, No Check-Cashing, Bank Told Armless Man – <a href="http://www.foxnews.com/story/0,2933,545560,00.html">Link Here</a></li>
<li>PCI Council Releases recommendation for Preventing Card Skimming – <a href="http://www.darkreading.com/security/government/showArticle.jhtml;jsessionid=MR0HE1VGH0KNXQE1GHRSKHWATMY32JVN?articleID=219401468">Link 1</a> / <a href="https://www.pcisecuritystandards.org/education/info_sup.shtml">Link 2</a></li>
<li>Federal Certification Program for “Cyber Professionals” / Bill would give President emergency control of the Internet – <a href="http://news.cnet.com/8301-13578_3-10320096-38.html">Link Here</a></li>
</ul>
<p style="clear: both"><strong>Discussion Topic -</strong> Web App Scanners And Web App Firewalls According to Gartner</p>
<p>- <a href="http://blogs.gartner.com/neil_macdonald/2009/08/25/are-web-application-security-testing-tools-a-waste-of-time-and-money/">Link 1</a> / <a href="http://blogs.gartner.com/neil_macdonald/2009/08/19/security-no-brainer-9-application-vulnerability-scanners-should-communicate-with-application-firewalls/">Link 2</a></p>
<p><strong>Consultant’s Corner – </strong>Updating Tools and Techniques</p>
<p style="clear: both"><strong>Music Notes:</strong></p>
<ul style="clear: both">
<li>Intro/Outro – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=d65dc8af297fd7a4cc57554b2a826a8e">Digital Breaks – “Therapy”</a></li>
<li>Segway 1 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=855fce1cfc0ead0f552963ba3bff22a5">Dave Stanley Band – “Lights Out”</a></li>
<li>Segway 2 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=1f9df891c1c8f91eaf5023d111ac0975">No Mans Hero -”Now That Its Over”</a></li>
<li>Segway 3 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=d87754a0ef419277dbdf2bbb6b2e284d">ByTheWayside- “DoYouEverNotice”</a></li>
</ul>
</div>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=6m1KWVIIxVc:RAKFb3PWry0:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=6m1KWVIIxVc:RAKFb3PWry0:5lVTG1FW49M"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=5lVTG1FW49M" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=6m1KWVIIxVc:RAKFb3PWry0:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=6m1KWVIIxVc:RAKFb3PWry0:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=6m1KWVIIxVc:RAKFb3PWry0:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=6m1KWVIIxVc:RAKFb3PWry0:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=6m1KWVIIxVc:RAKFb3PWry0:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=6m1KWVIIxVc:RAKFb3PWry0:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=63t7Ie-LG7Y" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2009/09/03/an-information-security-place-podcast-episode-24/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode24.mp3" length="90349696" type="audio/mpeg" />
		<media:content url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode24.mp3" fileSize="90349696" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:subtitle> Link to MP3 Hello all you happy people!  Episode 24 is here.  I was out sick, so Jim and Dan put it together. Jim is adamant about sticking to a schedule. Dang slave driver! Show Notes: InfoSec News Update – Credit Unions Under Attack – Link 1 / Link 2 M</itunes:subtitle><itunes:author>Michael R. Farnum</itunes:author><itunes:summary> Link to MP3 Hello all you happy people!  Episode 24 is here.  I was out sick, so Jim and Dan put it together. Jim is adamant about sticking to a schedule. Dang slave driver! Show Notes: InfoSec News Update – Credit Unions Under Attack – Link 1 / Link 2 Massive SQL Injection Attacks – Link 1 / Link2 Cisco [...]</itunes:summary><itunes:keywords>security,Michael,R,Farnum,podcast,blog,information,security,infosec</itunes:keywords><feedburner:origLink>http://infosecplace.com/blog/2009/09/03/an-information-security-place-podcast-episode-24/</feedburner:origLink></item>
	<copyright>Copyright Michael R. Farnum</copyright><media:credit role="author">Michael R. Farnum</media:credit><media:rating>nonadult</media:rating></channel>
</rss>
