<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>JadedSecurity</title>
	
	<link>http://jadedsecurity.net</link>
	<description>Much Ado about nothing but Information Security</description>
	<lastBuildDate>Wed, 23 Nov 2011 17:29:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/jadedsecurity/pHAE" /><feedburner:info uri="jadedsecurity/phae" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><media:thumbnail url="http://jadedsecurity.net/wp-content/uploads/2011/07/podcastimage.jpg" /><media:keywords>infosec,risk,news,rant,ISC2,information,Security,Risk,Policy,Drunks</media:keywords><media:category scheme="http://www.itunes.com/dtds/podcast-1.0.dtd">Technology/Gadgets</media:category><itunes:owner><itunes:email>boris.sverdlik@jadedsecurity.com</itunes:email></itunes:owner><itunes:explicit>yes</itunes:explicit><itunes:image href="http://jadedsecurity.net/wp-content/uploads/2011/07/podcastimage.jpg" /><itunes:keywords>infosec,risk,news,rant,ISC2,information,Security,Risk,Policy,Drunks</itunes:keywords><itunes:subtitle>JadedExposure</itunes:subtitle><itunes:summary>The Weekly Drunken Information Security Rant. We got the news, we got Hax0rs and don't the forget the Duck..&#xD;
&#xD;
We hate the CISSP and also are the only security show that has a a female "hax0r"  </itunes:summary><itunes:category text="Technology"><itunes:category text="Gadgets" /></itunes:category><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Ffeeds.feedburner.com%2Fjadedsecurity%2FpHAE" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2Fjadedsecurity%2FpHAE" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Ffeeds.feedburner.com%2Fjadedsecurity%2FpHAE" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://feeds.feedburner.com/jadedsecurity/pHAE" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Ffeeds.feedburner.com%2Fjadedsecurity%2FpHAE" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2Fjadedsecurity%2FpHAE" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2Fjadedsecurity%2FpHAE" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><feedburner:feedFlare href="http://www.plusmo.com/add?url=http%3A%2F%2Ffeeds.feedburner.com%2Fjadedsecurity%2FpHAE" src="http://plusmo.com/res/graphics/fbplusmo.gif">Subscribe with Plusmo</feedburner:feedFlare><feedburner:feedFlare href="http://www.thefreedictionary.com/_/hp/AddRSS.aspx?http%3A%2F%2Ffeeds.feedburner.com%2Fjadedsecurity%2FpHAE" src="http://img.tfd.com/hp/addToTheFreeDictionary.gif">Subscribe with The Free Dictionary</feedburner:feedFlare><feedburner:feedFlare href="http://www.bitty.com/manual/?contenttype=rssfeed&amp;contentvalue=http%3A%2F%2Ffeeds.feedburner.com%2Fjadedsecurity%2FpHAE" src="http://www.bitty.com/img/bittychicklet_91x17.gif">Subscribe with Bitty Browser</feedburner:feedFlare><feedburner:feedFlare href="http://www.live.com/?add=http%3A%2F%2Ffeeds.feedburner.com%2Fjadedsecurity%2FpHAE" src="http://tkfiles.storage.msn.com/x1piYkpqHC_35nIp1gLE68-wvzLZO8iXl_JMledmJQXP-XTBOLfmQv4zhj4MhcWEJh_GtoBIiAl1Mjh-ndp9k47If7hTaFno0mxW9_i3p_5qQw">Subscribe with Live.com</feedburner:feedFlare><feedburner:feedFlare href="http://mix.excite.eu/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2Fjadedsecurity%2FpHAE" src="http://image.excite.co.uk/mix/addtomix.gif">Subscribe with Excite MIX</feedburner:feedFlare><feedburner:feedFlare href="http://www.webwag.com/wwgthis.php?url=http%3A%2F%2Ffeeds.feedburner.com%2Fjadedsecurity%2FpHAE" src="http://www.webwag.com/images/wwgthis.gif">Subscribe with Webwag</feedburner:feedFlare><feedburner:feedFlare href="http://www.podcastready.com/oneclick_bookmark.php?url=http%3A%2F%2Ffeeds.feedburner.com%2Fjadedsecurity%2FpHAE" src="http://www.podcastready.com/images/podcastready_button.gif">Subscribe with Podcast Ready</feedburner:feedFlare><feedburner:feedFlare href="http://www.wikio.com/subscribe?url=http%3A%2F%2Ffeeds.feedburner.com%2Fjadedsecurity%2FpHAE" src="http://www.wikio.com/shared/img/add2wikio.gif">Subscribe with Wikio</feedburner:feedFlare><feedburner:feedFlare href="http://www.dailyrotation.com/index.php?feed=http%3A%2F%2Ffeeds.feedburner.com%2Fjadedsecurity%2FpHAE" src="http://www.dailyrotation.com/rss-dr2.gif">Subscribe with Daily Rotation</feedburner:feedFlare><item>
		<title>Ineffective CISOs breed shady vendor practices</title>
		<link>http://feedproxy.google.com/~r/jadedsecurity/pHAE/~3/rBpbhbqG8AY/</link>
		<comments>http://jadedsecurity.net/2011/11/23/ineffective-cisos-breed-shady-vendor-practices/#comments</comments>
		<pubDate>Wed, 23 Nov 2011 17:29:04 +0000</pubDate>
		<dc:creator>boris.sverdlik@jadedsecurity.com</dc:creator>
				<category><![CDATA[Topics]]></category>

		<guid isPermaLink="false">http://jadedsecurity.net/?p=817</guid>
		<description><![CDATA[I know I have become a bit lazy in keeping up with my rants and various positions I have taken within the industry, and for that I apologize. I have become somewhat preoccupied with work, life, conferences and most importantly the podcast. I will try to balance all going forward because I believe my passion [...]]]></description>
			<content:encoded><![CDATA[<p>I know I have become a bit lazy in keeping up with my rants and various positions I have taken within the industry, and for that I apologize. I have become somewhat preoccupied with work, life, conferences and most importantly the podcast. I will try to balance all going forward because I believe my passion for information security drives me to be the best I can be across the board.</p>
<p>With all that self promotion bullshit behind me, I&#8217;d like to address some of you that have made claims of my move to the dark side (vendor). I am still the guy who goes by the mantra of &#8220;Don&#8217;t Buy Shit!&#8221;, and that will never change. I for one strongly believe in the proven flow of People, Processes, Technology. There has been a lot of debate back and forth on the concept of the inexperienced CISO, regardless of what side of the fence you are on you must at least acknowledge that we have a serious problem in the industry.</p>
<p><span style="color: #ff6600;"><strong> &#8221;After a breach the right thing to ask your vendor for is the morning after pill not a condom.&#8221;</strong></span></p>
<p>While I am fairly new to the industry in terms of marketing and sales, I am just appalled at some of the expectations inexperienced CISOs make of vendors. I am almost willing to believe that shady vendor practices were born through shady client requests. We are all in the business of making money, and I get it. If you don&#8217;t take the clients money then someone else will. As greedy as we are as individuals, we provide almost no value to the consumer and the industry as a whole when we engage in these types of practices.</p>
<p>As security professionals we are used to money getting tossed our way after an incident… I like to call them reactionary dollars which are for the most part used to bring a feeling of warmth and goodness to the cockles of C level individuals. The question remains how much faith is too much to put in the hands of your vendors? Without a thorough analysis of the inner workings of your organization, it is impossible for any external entity to make recommendations on where your reactionary dollars are best spent.</p>
<p>A recent incident at an organization has led the CISO to reach out with an open ended request, that for the shadier vendor would instantly shine dollar signs. &#8220;We think we might of had a breach, we&#8217;re not sure when, how or why, but we need you to come here and monitor the network for everything&#8221;</p>
<p>How do you approach that? Do you take advantage of the organization and sell them your (Insert magic Anti-Apt, Blinky, Cyber Monitoring Unicorn Here)? Who is really to blame for the path our industry has taken when it comes to magic?</p>
<p>An experienced CISO would take a step back and first determine the problem. Identify weaknesses in his processes and take steps to remediate and implement an effect risk management program. This is where experience comes into account and will allow your organization to make strategic decisions based on risk and not based on fear, uncertainty and doubt. Reactionary dollars will run out and when they do can you definitively say that you have done what you could to reduce your organizations&#8217; exposure?</p>
<p>In a perfect world you would have infinite resources to implement security controls that address every potential threat against your organization. This is not a perfect world. and resources are limited. Don&#8217;t rely on your product vendors to tell you where you need to spend your dollars. Every organization will in some way shape or form be popped.. It&#8217;s the cost of doing business in the global economy, and as such we must adapt to the threat and act accordingly. As an organization you need to depend on your CISO to keep a level head and make informed decisions both day to day and during a breach. If your CISO doesn&#8217;t understand that warm and fuzzies aren&#8217;t bottled by (insert product vendor here), then use the incident to reconsider the strategy for the position.</p>
<p>&nbsp;</p>

<p><a href="http://feedads.g.doubleclick.net/~a/YOWye19cje5ASAKcCxmazbb8VgU/0/da"><img src="http://feedads.g.doubleclick.net/~a/YOWye19cje5ASAKcCxmazbb8VgU/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/YOWye19cje5ASAKcCxmazbb8VgU/1/da"><img src="http://feedads.g.doubleclick.net/~a/YOWye19cje5ASAKcCxmazbb8VgU/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=rBpbhbqG8AY:POjQG41gHc0:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=rBpbhbqG8AY:POjQG41gHc0:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=rBpbhbqG8AY:POjQG41gHc0:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=rBpbhbqG8AY:POjQG41gHc0:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=rBpbhbqG8AY:POjQG41gHc0:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=rBpbhbqG8AY:POjQG41gHc0:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=rBpbhbqG8AY:POjQG41gHc0:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/jadedsecurity/pHAE/~4/rBpbhbqG8AY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://jadedsecurity.net/2011/11/23/ineffective-cisos-breed-shady-vendor-practices/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://jadedsecurity.net/2011/11/23/ineffective-cisos-breed-shady-vendor-practices/</feedburner:origLink></item>
		<item>
		<title>Hack3rcon 2011</title>
		<link>http://feedproxy.google.com/~r/jadedsecurity/pHAE/~3/dRTzknzrLN4/</link>
		<comments>http://jadedsecurity.net/2011/11/23/hack3rcon-2011/#comments</comments>
		<pubDate>Wed, 23 Nov 2011 17:26:28 +0000</pubDate>
		<dc:creator>boris.sverdlik@jadedsecurity.com</dc:creator>
				<category><![CDATA[Topics]]></category>

		<guid isPermaLink="false">http://jadedsecurity.net/?p=808</guid>
		<description />
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-809" title="Dontclickshit" src="http://jadedsecurity.net/wp-content/uploads/2011/11/Dontclickshit.jpg" alt="" width="553" height="138" /></p>
<p><iframe width="425" height="349" src="https://www.youtube.com/embed/VW_tqUD4_4k" frameborder="0" allowfullscreen></iframe></p>

<p><a href="http://feedads.g.doubleclick.net/~a/zbcUShJfFITAB33wEblftIkNbbI/0/da"><img src="http://feedads.g.doubleclick.net/~a/zbcUShJfFITAB33wEblftIkNbbI/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/zbcUShJfFITAB33wEblftIkNbbI/1/da"><img src="http://feedads.g.doubleclick.net/~a/zbcUShJfFITAB33wEblftIkNbbI/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=dRTzknzrLN4:KWznpRaNMKs:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=dRTzknzrLN4:KWznpRaNMKs:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=dRTzknzrLN4:KWznpRaNMKs:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=dRTzknzrLN4:KWznpRaNMKs:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=dRTzknzrLN4:KWznpRaNMKs:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=dRTzknzrLN4:KWznpRaNMKs:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=dRTzknzrLN4:KWznpRaNMKs:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/jadedsecurity/pHAE/~4/dRTzknzrLN4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://jadedsecurity.net/2011/11/23/hack3rcon-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://jadedsecurity.net/2011/11/23/hack3rcon-2011/</feedburner:origLink></item>
		<item>
		<title>Been Busy.. Planning some things for the site next week</title>
		<link>http://feedproxy.google.com/~r/jadedsecurity/pHAE/~3/B2rvvSVRYqw/</link>
		<comments>http://jadedsecurity.net/2011/08/27/been-busy-planning-some-things-for-the-site-next-week/#comments</comments>
		<pubDate>Sat, 27 Aug 2011 01:27:30 +0000</pubDate>
		<dc:creator>boris.sverdlik@jadedsecurity.com</dc:creator>
				<category><![CDATA[Topics]]></category>

		<guid isPermaLink="false">http://jadedsecurity.net/?p=804</guid>
		<description><![CDATA[Apologies.. I haven&#8217;t gone 404, just been a little busy with client work. Will be updating in a few days.]]></description>
			<content:encoded><![CDATA[<p>Apologies.. I haven&#8217;t gone 404, just been a little busy with client work. Will be updating in a few days.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/-YMqxI1d45ZkTS0iPQlz0wJ0YyY/0/da"><img src="http://feedads.g.doubleclick.net/~a/-YMqxI1d45ZkTS0iPQlz0wJ0YyY/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/-YMqxI1d45ZkTS0iPQlz0wJ0YyY/1/da"><img src="http://feedads.g.doubleclick.net/~a/-YMqxI1d45ZkTS0iPQlz0wJ0YyY/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=B2rvvSVRYqw:TX_dkWuDHTw:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=B2rvvSVRYqw:TX_dkWuDHTw:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=B2rvvSVRYqw:TX_dkWuDHTw:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=B2rvvSVRYqw:TX_dkWuDHTw:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=B2rvvSVRYqw:TX_dkWuDHTw:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=B2rvvSVRYqw:TX_dkWuDHTw:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=B2rvvSVRYqw:TX_dkWuDHTw:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/jadedsecurity/pHAE/~4/B2rvvSVRYqw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://jadedsecurity.net/2011/08/27/been-busy-planning-some-things-for-the-site-next-week/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://jadedsecurity.net/2011/08/27/been-busy-planning-some-things-for-the-site-next-week/</feedburner:origLink></item>
		<item>
		<title>HBGary can’t shake Anonymous LOL… #Defcon Correction #Blackhat</title>
		<link>http://feedproxy.google.com/~r/jadedsecurity/pHAE/~3/Rl6bzxglhUI/</link>
		<comments>http://jadedsecurity.net/2011/08/06/hbgary-cant-shake-anonymous-lol-defcon/#comments</comments>
		<pubDate>Sat, 06 Aug 2011 02:32:50 +0000</pubDate>
		<dc:creator>boris.sverdlik@jadedsecurity.com</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Topics]]></category>
		<category><![CDATA[Defcon]]></category>
		<category><![CDATA[LOL]]></category>

		<guid isPermaLink="false">http://jadedsecurity.net/?p=798</guid>
		<description><![CDATA[Even though I couldn&#8217;t make it to #Defcon this year, I have to thank &#8220;A furry little creature of security&#8221; for this awesome #FAIL Shot]]></description>
			<content:encoded><![CDATA[<p>Even though I couldn&#8217;t make it to #Defcon this year, I have to thank &#8220;A furry little creature of security&#8221; for this awesome #FAIL Shot</p>
<p><img class="size-full wp-image-799 alignnone" title="hbgary" src="http://jadedsecurity.net/wp-content/uploads/2011/08/hbgary.jpg" alt="" width="678" height="495" /></p>

<p><a href="http://feedads.g.doubleclick.net/~a/oB-zdLo9HpJKc9x_S1gOuk7CeVQ/0/da"><img src="http://feedads.g.doubleclick.net/~a/oB-zdLo9HpJKc9x_S1gOuk7CeVQ/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/oB-zdLo9HpJKc9x_S1gOuk7CeVQ/1/da"><img src="http://feedads.g.doubleclick.net/~a/oB-zdLo9HpJKc9x_S1gOuk7CeVQ/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=Rl6bzxglhUI:V8xDDsaAPJI:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=Rl6bzxglhUI:V8xDDsaAPJI:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=Rl6bzxglhUI:V8xDDsaAPJI:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=Rl6bzxglhUI:V8xDDsaAPJI:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=Rl6bzxglhUI:V8xDDsaAPJI:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=Rl6bzxglhUI:V8xDDsaAPJI:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=Rl6bzxglhUI:V8xDDsaAPJI:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/jadedsecurity/pHAE/~4/Rl6bzxglhUI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://jadedsecurity.net/2011/08/06/hbgary-cant-shake-anonymous-lol-defcon/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		<feedburner:origLink>http://jadedsecurity.net/2011/08/06/hbgary-cant-shake-anonymous-lol-defcon/</feedburner:origLink></item>
		<item>
		<title>#Antisec Shoot The Sheriff Saturday</title>
		<link>http://feedproxy.google.com/~r/jadedsecurity/pHAE/~3/RCKpE-IUuTY/</link>
		<comments>http://jadedsecurity.net/2011/08/06/antisec-shoot-the-sheriff-saturday/#comments</comments>
		<pubDate>Sat, 06 Aug 2011 01:28:14 +0000</pubDate>
		<dc:creator>boris.sverdlik@jadedsecurity.com</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[#antisec #jadedexposure]]></category>

		<guid isPermaLink="false">http://jadedsecurity.net/?p=773</guid>
		<description><![CDATA[According to a link (Original has been removed) mirror  that was posted to the @AnonymousIRC twitter stream..  Last week we saw over 70 Domains attacked with personal details of law enforcement released. This week they are claiming to have much more including jpegs depicting teens on a certain sherrifs machine. I will be keeping up with the [...]]]></description>
			<content:encoded><![CDATA[<p>According to a <a href="https://vv7pabmmyr2vnflf.tor2web.org/antisec_shoots_the_sheriff.txt" target="_blank">link</a> (Original has been removed) <a href="http://jadedsecurity.net/wp-content/uploads/2011/07/antisec_shoots_the_sheriff.txt" target="_blank">mirror</a>  that was posted to the @AnonymousIRC twitter stream..  Last week we saw over 70 Domains attacked with personal details of law enforcement released. This week they are claiming to have much more including jpegs depicting teens on a certain sherrifs machine. I will be keeping up with the release and updating accordingly. I&#8217;m not going to posting any specifics, obviously as I don&#8217;t agree with releasing personal information. This is just another example of the inept security experts that we rely upon to keep us secure. This data should of been kept in the strictest of confidence, and by means accessible by an internet facing system.</p>
<p>The excerpt below has a statement which we know is false according to the release last week. &#8220;According to the Missouri Sheriff&#8217;s Association Executive Director Mick Covington tells KHQA that the most the hackers got from their organization were email addresses&#8221; <a href="http://www.connecttristates.com/news/story.aspx?id=646614" target="_blank">Original</a></p>
<p>&nbsp;</p>
<p><img class="alignleft size-full wp-image-785" title="Screen shot 2011-08-05 at 9.53.20 PM" src="http://jadedsecurity.net/wp-content/uploads/2011/08/Screen-shot-2011-08-05-at-9.53.20-PM.jpg" alt="" width="585" height="222" /></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>According to the release txt the release will contain</p>
<pre>The booty contains: 

   [*] Over 300 mail accounts from 56 law enforcement domains
   [*] Missouri Sheriff account dump (mosheriffs.com)
       7000+ usernames, passwords, home addresses, phones and SSNs
   [*] Online Police Training Academy files
       PDFs, videos, HTML files
   [*] "Report a Crime" snitch list compilation (60+ entries)
   [*] Plesk plaintext server passwords (ftp/ssh, email, cpanel, protected dirs)</pre>
<pre></pre>
<p>This latest release potentially puts the lives of many innocent civilians in harms way.. The following is an an excerpt of an informants e-mail to MN police.</p>
<pre>Name:
Email: 

I live at XXXXXX The home from standing in my front lawn
looking at the road using the clock method is at 10 oclock I am only
using this because they dont have numbers on the house. They have all
different types of cars comming and going at different times of day
and night. They dont stay longer that 5 minutes most shorter than
that. I cant prove any of it but if I were to guess they deal drugs
out of the home. I am not sure if this will help but I wanted to
report it any way. I put my name up but do want to remain anonymous
so no retaliation or fights with the neighbors.</pre>
<p>&nbsp;</p>
<pre>An attack of this nature was made easier because all 70 Domains were hosted on
a single system. Looking through the release that was posted
appears that although the servers each had what appears to be there own
authentication files, they were easy to pull once access was obtained.</pre>
<p>&nbsp;</p>
<pre>Over 70 US law enforcement institutions were attacked including:

20jdpa.com, adamscosheriff.org, admin.mostwantedwebsites.net,
alabamasheriffs.com, arkansassheriffsassociation.com,
bakercountysheriffoffice.org, barrycountysheriff.com, baxtercountysheriff.com,
baxtercountysherifffoundation.org, boonecountyar.com, boonesheriff.com,
cameronso.org, capecountysheriff.org, cherokeecountyalsheriff.com,
cityofgassville.org, cityofwynne.com, cleburnecountysheriff.com,
coahomacountysheriff.com, crosscountyar.org, crosscountysheriff.org,
drewcountysheriff.com, faoret.com, floydcountysheriff.org, fultoncountyso.org,
georgecountymssheriff.com, grantcountyar.com, grantcountysheriff-collector.com,
hodgemansheriff.us, hotspringcountysheriff.com, howardcountysheriffar.com,
izardcountyar.org, izardcountysheriff.org, izardhometownhealth.com,
jacksonsheriff.org, jeffersoncountykssheriff.com, jeffersoncountyms.gov,
jocomosheriff.org, johnsoncosheriff.com, jonesso.com, kansassheriffs.org,
kempercountysheriff.com, knoxcountysheriffil.com, lawrencecosheriff.com,
lcsdmo.com, marioncountysheriffar.com, marionsoal.com, mcminncountysheriff.com,
meriwethercountysheriff.org, monroecountysheriffar.com, mosheriffs.com,
mostwantedgovernmentwebsites.com, mostwantedwebsites.net,
newtoncountysheriff.org, perrycountysheriffar.org, plymouthcountysheriff.com,
poalac.org, polkcountymosheriff.org, prairiecountysheriff.org,
prattcountysheriff.com, prentisscountymssheriff.com, randolphcountysheriff.org,
rcpi-ca.org, scsosheriff.org, sebastiancountysheriff.com, sgcso.com,
sharpcountysheriff.com, sheriffcomanche.com, stfranciscountyar.org,
stfranciscountysheriff.org, stonecountymosheriff.com, stonecountysheriff.com,
talladegasheriff.org, tatecountysheriff.com, tishomingocountysheriff.com,
tunicamssheriff.com, vbcso.com, woodsonsheriff.com</pre>
<p>A file listing of all virtual hosts</p>
<p>////////////////////////////////////////////////////////////////////////////////<br />
// ENOUGH TALK&#8230; TIME TO RIDE ON THESE PIG MOTHAFUCKAS !!! BRING ON THE HACKLOG<br />
////////////////////////////////////////////////////////////////////////////////<br />
$ ls -al /var/www/vhosts/<br />
total 332</p>
<p>and now for the passwords.. If you notice, just looking at the hashes some of the<br />
users had used the same password for multiple vhosts.</p>
<p>// CAT&#8217;N HUNDREDS OF .HTPASSWD FILES IN ONE COMMAND LIKE A BOSS</p>
<p>$ cat /var/www/vhosts/*/pd/*<br />
2010user:$1$YfJPNAST$w9rRAaYhAMjpkw.GRLUD90<br />
jdpa:$1$e1JbcQkZ$sR59gW8uPd/6Dyae9xneL0<br />
jdpa:$1$uBEldfcW$mzSY61wj97PN41JWNPcA9/<br />
jdpa:$1$e1JbcQkZ$sR59gW8uPd/6Dyae9xneL0<br />
acsoms:$1$/OuADgxB$l7pPU2kXeKlw7Iz9NLGID.<br />
acsoms:$1$uDsXPWpq$mhRoR3B3JicVBpuHWxYue1<br />
acsoms:$1$uDsXPWpq$mhRoR3B3JicVBpuHWxYue1<br />
code:$1$7.KAx/YD$J7SuxsDsBOij.qgPD3GJ60<br />
code:$1$7.KAx/YD$J7SuxsDsBOij.qgPD3GJ60<br />
alsa:$1$gg9rFhvF$S41htlhsl3AJYZu4dKWR50<br />
alsa:$1$RnNxf5wV$NMmcQvODrjBzyi0RI1MqO.<br />
alsa:$1$RnNxf5wV$NMmcQvODrjBzyi0RI1MqO.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/MnG83ZKPftJoAQatlHoNXhHq8jw/0/da"><img src="http://feedads.g.doubleclick.net/~a/MnG83ZKPftJoAQatlHoNXhHq8jw/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/MnG83ZKPftJoAQatlHoNXhHq8jw/1/da"><img src="http://feedads.g.doubleclick.net/~a/MnG83ZKPftJoAQatlHoNXhHq8jw/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=RCKpE-IUuTY:4_pYrfVN68A:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=RCKpE-IUuTY:4_pYrfVN68A:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=RCKpE-IUuTY:4_pYrfVN68A:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=RCKpE-IUuTY:4_pYrfVN68A:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=RCKpE-IUuTY:4_pYrfVN68A:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=RCKpE-IUuTY:4_pYrfVN68A:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=RCKpE-IUuTY:4_pYrfVN68A:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/jadedsecurity/pHAE/~4/RCKpE-IUuTY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://jadedsecurity.net/2011/08/06/antisec-shoot-the-sheriff-saturday/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://jadedsecurity.net/2011/08/06/antisec-shoot-the-sheriff-saturday/</feedburner:origLink></item>
		<item>
		<title>Blackhat, ISC2 and The Shady Rat</title>
		<link>http://feedproxy.google.com/~r/jadedsecurity/pHAE/~3/BK7MLAIDXU0/</link>
		<comments>http://jadedsecurity.net/2011/08/05/blackhat-isc2-and-the-shady-rat/#comments</comments>
		<pubDate>Fri, 05 Aug 2011 00:24:44 +0000</pubDate>
		<dc:creator>boris.sverdlik@jadedsecurity.com</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Topics]]></category>
		<category><![CDATA[#antisec #jadedexposure]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[Infosec]]></category>
		<category><![CDATA[ISC2]]></category>
		<category><![CDATA[Mcafee]]></category>
		<category><![CDATA[Shady Rat]]></category>
		<category><![CDATA[Vegas]]></category>

		<guid isPermaLink="false">http://jadedsecurity.net/?p=751</guid>
		<description><![CDATA[So unfortunately this year I&#8217;m not at Black Hat and/or Defcon because I went the route of self employment. I&#8217;d like to say that I enjoy being at the mercy of my clients, but that&#8217;s neither here nor there. Fortunately for me, I am not alone in being absent, I can sit back and watch [...]]]></description>
			<content:encoded><![CDATA[<p>So unfortunately this year I&#8217;m not at Black Hat and/or Defcon because I went the route of self employment. I&#8217;d like to say that I enjoy being at the mercy of my clients, but that&#8217;s neither here nor there. Fortunately for me, I am not alone in being absent, I can sit back and watch the drama unfold on Twitter along with some on my online friends such as Bill Brenner who wrote a similar missing out on <a href="http://billbrenner1970.wordpress.com/2011/08/04/blackhat-defcon-bsides-symptoms-of-withdrawl/" target="_blank">Blackhat</a> piece .</p>
<p><img class="alignright size-full wp-image-755" title="Screen shot 2011-08-04 at 6.31.19 PM" src="http://jadedsecurity.net/wp-content/uploads/2011/08/Screen-shot-2011-08-04-at-6.31.19-PM.jpg" alt="" width="427" height="250" />Fortunately for us, some of the talks are being streamed live via the Blackhat Uplink which is being run by INXPO.com. While I find it amusing that a Security Conference is being hosted by a company that passes the username in plain text within the context of the URL (https://vts.inxpo.com/scripts/Server.nxp?LASCmd=AI:1;F:US!100&amp;ShowName=Black%20Hat%20Uplink%20Presents%20<br />
Black%20Hat%20USA%202011&amp;UserName=Boris%20Sverdlik&amp;PreviousLoginCount) I do appreciate the effort.</p>
<p>So with Black Hat ending today and the real festivities about to begin, It&#8217;s interesting to see just how mainstream the venue has become. I had a missed most of the talks yesterday, so I can&#8217;t speak to them for the most part. Of course what Con would be complete without the proverbial initial prank. This years pranks start with a fire alarm going off during the first track.. Security be warned, you have a &#8220;hacker&#8221; amongst you who in his spare time at the conference will be messing with your systems. We are not reacting, because it&#8217;s nothing new.</p>
<p>I did catch a few minutes of <strong>Macs in the Age of the APT by ALEX STAMOS + AARON GRATTAFIORI + TOM DANIELS + PAUL YOUN + B.J. ORVIS</strong></p>
<p>I do have a real problem with the use of APT. Macs are just as susceptible as any other OS. WTF does APT mean here?</p>
<p>Let&#8217;s move on… Kaminsky, has gone the corporate route (Shirt &amp; Tie) since his validation of DNSSEC. I&#8217;ll leave DNSSEC for a later time, as I&#8217;m still trying to grasp why people think this is a good idea.</p>
<p>McAfee publishes their award winning piece on Operation Shady Rat, using terms like Cyber and APT across the board. Needless to say, all of the data is relatively old (in security terms 8 months is Ancient History). Just more evidence of the incompetence of a good chunk of these so called security professionals we rely on to reduce our exposure. The attacks outlined within the document are not advance to any extent. These are the types of attacks that for the most part should be considered low hanging fruit, but the &#8220;Security Pros&#8221; aka Mr CISSP tasked with Risk Management, are oblivious to them.</p>
<p>J. Oquendo wrote a very interesting piece expanding on this titled<a href="http://www.infiltrated.net/index.php?option=com_content&amp;view=article&amp;id=41&amp;Itemid=47" target="_blank"> &#8220;That Shady Rat was Only a Security Peer&#8221;</a></p>
<p><img class="alignleft size-full wp-image-758" title="shadyrat" src="http://jadedsecurity.net/wp-content/uploads/2011/08/shadyrat.jpg" alt="" width="337" height="251" />Symantec, has it&#8217;s own piece on the this uber sophisticated attack and dives deeper into the <a href="http://www.symantec.com/connect/blogs/truth-behind-shady-rat" target="_blank">attack flow</a>.</p>
<p>Apparently Vanity Fair does security reporting as well these days, as they also have a piece speaking for the most part to the attention that the report has gotten as well as an interesting<a href="http://www.vanityfair.com/culture/features/2011/09/operation-shady-rat-201109?" target="_blank"> tidbit of information.</a></p>
<p><strong><em>&#8220;Shady rat’s command-and-control server is still operating, and some organizations, including the World Anti-doping Agency, were still under attack as of last month. (As of Tuesday, according to a WADA spokesman, the group was unaware of any breach, but “WADA is investigating” McAfee’s discovery.)&#8221;</em></strong></p>
<p>Since we are talking McAfee, we should probably also touch on their excellent marketing plan.. Babes and Motorcycles… While there has been plenty of controversy on the intertubez about this, I personally do not see anything wrong with it. Formula One and other major companies have always used sex to sell. Information Security is a funny animal, what other industry can you mass market something that does absolutely nothing and have the product sell itself due to marketing? Why wouldn&#8217;t you throw sex into the mix? All I can say is.. RIGHT ON McAfee, next year get Unicorns with Boobs!</p>
<p>&nbsp;</p>
<p>With that said, I&#8217;d like to take a minute to review the talks I did get to watch..</p>
<p>First up. Chris Paget.. I have followed Chris&#8217;s work since seeing some videos from ShmooCon 2009 on <a href="http://www.youtube.com/watch?v=9isKnDiJNPk" target="_blank">RFID</a> and his earlier GSM Hacking. I&#8217;m unsure why he would submit<strong> &#8220;Microsoft Vista: NDA-less The Good, The Bad, and The Ugly&#8221;</strong> for a BlackHat topic? Vista for the most part is dead, if it hasn&#8217;t been completely killed off yet, then someone should get the thermite. This would of made a great white paper, but a talk post user accepted EOL not so much. Oh, and Chris… This had to of been the funniest moment of the entire cast. Were you shocked or awed <img src='http://jadedsecurity.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><img class="alignnone size-full wp-image-768" title="Screen shot 2011-08-04 at 1.33.14 PM" src="http://jadedsecurity.net/wp-content/uploads/2011/08/Screen-shot-2011-08-04-at-1.33.14-PM1.jpg" alt="" width="436" height="327" /></p>
<p>Next up<br />
<strong>Staring into the Abyss: The Dark Side of Security and Professional Intelligence by Richard Thieme</strong></p>
<p>All I can say is wow… what a speaker, no slides no bullshit. I haven&#8217;t been so wrapped up in a talk in a long time. Every security professional should sit down and here him speak on the the generic misnomers that are going around our industry like wildfire lately. The physical borders that had previously separated countries have been knocked down by globalization. Time to start thinking that way. I&#8217;m ordering his book <a href="http://www.thiemeworks.com/" target="_blank">Mind Games</a></p>
<p>Last up.<br />
<strong>WORKSHOP &#8211; Infosec 2021: A Career Odyssey by Lee Kushner &amp; Mike Murray</strong></p>
<p>While I have met Lee before and have worked with him on a few opportunities, I am somewhat conflicted about this presentation. We all know the HR Drones are trained to use CISSP as a requirement for even the most basic IT Security position. Instead of giving a presentation on what we already know, how about going out and citing real world examples of what security professionals do and how the certification does not apply directly to their roles. I have been in information securiy/risk management for over a decade and on the management side of the house for the last five years or so. I cringe every time I see a job req for the hands on security types where the requirements outline a CISSP. Did you know that everyone in that room that raised a hand when asked if they are a CISSP, according to Dorsey Morrow are in violation of the Ethics agreement?</p>
<p>I&#8217;m not knocking the full presentation as it got better towards the end, but come on.. This is nothing new. Oh and Dorsey, I know your reading this F ISC2.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/m4fV4hJj-UY4wz3WmONx-3o9Ghs/0/da"><img src="http://feedads.g.doubleclick.net/~a/m4fV4hJj-UY4wz3WmONx-3o9Ghs/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/m4fV4hJj-UY4wz3WmONx-3o9Ghs/1/da"><img src="http://feedads.g.doubleclick.net/~a/m4fV4hJj-UY4wz3WmONx-3o9Ghs/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=BK7MLAIDXU0:U2Aalx7bXCQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=BK7MLAIDXU0:U2Aalx7bXCQ:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=BK7MLAIDXU0:U2Aalx7bXCQ:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=BK7MLAIDXU0:U2Aalx7bXCQ:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=BK7MLAIDXU0:U2Aalx7bXCQ:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=BK7MLAIDXU0:U2Aalx7bXCQ:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=BK7MLAIDXU0:U2Aalx7bXCQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/jadedsecurity/pHAE/~4/BK7MLAIDXU0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://jadedsecurity.net/2011/08/05/blackhat-isc2-and-the-shady-rat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://jadedsecurity.net/2011/08/05/blackhat-isc2-and-the-shady-rat/</feedburner:origLink></item>
		<item>
		<title>Episode #8</title>
		<link>http://feedproxy.google.com/~r/jadedsecurity/pHAE/~3/0Gp8-2KMsz4/</link>
		<comments>http://jadedsecurity.net/2011/08/04/episode-8/#comments</comments>
		<pubDate>Thu, 04 Aug 2011 22:12:52 +0000</pubDate>
		<dc:creator>boris.sverdlik@jadedsecurity.com</dc:creator>
				<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://jadedsecurity.net/?p=749</guid>
		<description><![CDATA[Infosec,Drunks and Ducks John Foster hosting the Money Updates (Which might just become regular) @Abhaxas makes an appearance Spridel forgets his password X25Princess trolls tinychat in a BIKINI With most of the regular hosts away at #blackhat #bsides or DC, we had some new guests.. Enlight2k UrbanFox Psyxx nuhbleach]]></description>
			<content:encoded><![CDATA[<p><a href="http://jadedsecurity.net/wp-content/uploads/2011/07/podcastimage1.jpg"><img class="aligncenter size-full wp-image-675" title="podcastimage" src="http://jadedsecurity.net/wp-content/uploads/2011/07/podcastimage1.jpg" alt="" width="583" height="549" /></a></p>
<p><a href="http://jadedsecurity.net/wp-content/uploads/2011/07/Episode8.mp3">Infosec,Drunks and Ducks</a></p>
<p>John Foster hosting the Money Updates (Which might just become regular)</p>
<p>@Abhaxas makes an appearance<br />
Spridel forgets his password<br />
X25Princess trolls tinychat in a BIKINI</p>
<p>With most of the regular hosts away at #blackhat #bsides or DC, we had some new guests..</p>
<p>Enlight2k<br />
UrbanFox<br />
Psyxx<br />
nuhbleach</p>

<p><a href="http://feedads.g.doubleclick.net/~a/2fYW_Ada8rWnj5cCK6qpQ8vLNYA/0/da"><img src="http://feedads.g.doubleclick.net/~a/2fYW_Ada8rWnj5cCK6qpQ8vLNYA/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/2fYW_Ada8rWnj5cCK6qpQ8vLNYA/1/da"><img src="http://feedads.g.doubleclick.net/~a/2fYW_Ada8rWnj5cCK6qpQ8vLNYA/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=0Gp8-2KMsz4:EH0-O8Wzo8M:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=0Gp8-2KMsz4:EH0-O8Wzo8M:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=0Gp8-2KMsz4:EH0-O8Wzo8M:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=0Gp8-2KMsz4:EH0-O8Wzo8M:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=0Gp8-2KMsz4:EH0-O8Wzo8M:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=0Gp8-2KMsz4:EH0-O8Wzo8M:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=0Gp8-2KMsz4:EH0-O8Wzo8M:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/jadedsecurity/pHAE/~4/0Gp8-2KMsz4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://jadedsecurity.net/2011/08/04/episode-8/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://jadedsecurity.net/wp-content/uploads/2011/07/Episode8.mp3" length="175334857" type="audio/mpeg" />
		<media:content url="http://jadedsecurity.net/wp-content/uploads/2011/07/Episode8.mp3" fileSize="175334857" type="audio/mpeg" /><itunes:explicit>yes</itunes:explicit><itunes:subtitle>Infosec,Drunks and Ducks John Foster hosting the Money Updates (Which might just become regular) @Abhaxas makes an appearance Spridel forgets his password X25Princess trolls tinychat in a BIKINI With most of the regular hosts away at #blackhat #bsides or </itunes:subtitle><itunes:summary>Infosec,Drunks and Ducks John Foster hosting the Money Updates (Which might just become regular) @Abhaxas makes an appearance Spridel forgets his password X25Princess trolls tinychat in a BIKINI With most of the regular hosts away at #blackhat #bsides or DC, we had some new guests.. Enlight2k UrbanFox Psyxx nuhbleach</itunes:summary><itunes:keywords>infosec,risk,news,rant,ISC2,information,Security,Risk,Policy,Drunks</itunes:keywords><feedburner:origLink>http://jadedsecurity.net/2011/08/04/episode-8/</feedburner:origLink></item>
		<item>
		<title>Episode #7</title>
		<link>http://feedproxy.google.com/~r/jadedsecurity/pHAE/~3/28PQFQvIt6E/</link>
		<comments>http://jadedsecurity.net/2011/07/31/episode-7/#comments</comments>
		<pubDate>Sun, 31 Jul 2011 02:24:31 +0000</pubDate>
		<dc:creator>boris.sverdlik@jadedsecurity.com</dc:creator>
				<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://jadedsecurity.net/?p=746</guid>
		<description><![CDATA[Infosec,Drunks and Ducks Trolling the Examiner @Abhaxas gets vanned, dies or something mid show.. We just keep Going&#8230; Talk About Defcon and some other news&#8230; Regular Hosts Aricon IllWill Spridel Abhaxas]]></description>
			<content:encoded><![CDATA[<p><a href="http://jadedsecurity.net/wp-content/uploads/2011/07/podcastimage1.jpg"><img class="aligncenter size-full wp-image-675" title="podcastimage" src="http://jadedsecurity.net/wp-content/uploads/2011/07/podcastimage1.jpg" alt="" width="583" height="549" /></a></p>
<p><a href="http://jadedsecurity.net/wp-content/uploads/2011/07/Episode7.mp3">Infosec,Drunks and Ducks</a></p>
<p>Trolling the Examiner<br />
@Abhaxas gets vanned, dies or something mid show.. We just keep Going&#8230; </p>
<p>Talk About Defcon and some other news&#8230; </p>
<p>Regular Hosts<br />
Aricon<br />
IllWill<br />
Spridel<br />
Abhaxas</p>

<p><a href="http://feedads.g.doubleclick.net/~a/Yz1Az87wmxB7HR2VYqwsF5FYMOk/0/da"><img src="http://feedads.g.doubleclick.net/~a/Yz1Az87wmxB7HR2VYqwsF5FYMOk/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/Yz1Az87wmxB7HR2VYqwsF5FYMOk/1/da"><img src="http://feedads.g.doubleclick.net/~a/Yz1Az87wmxB7HR2VYqwsF5FYMOk/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=28PQFQvIt6E:5-b1Ap3C1Ng:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=28PQFQvIt6E:5-b1Ap3C1Ng:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=28PQFQvIt6E:5-b1Ap3C1Ng:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=28PQFQvIt6E:5-b1Ap3C1Ng:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=28PQFQvIt6E:5-b1Ap3C1Ng:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=28PQFQvIt6E:5-b1Ap3C1Ng:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=28PQFQvIt6E:5-b1Ap3C1Ng:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/jadedsecurity/pHAE/~4/28PQFQvIt6E" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://jadedsecurity.net/2011/07/31/episode-7/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://jadedsecurity.net/wp-content/uploads/2011/07/Episode7.mp3" length="93129581" type="audio/mpeg" />
		<media:content url="http://jadedsecurity.net/wp-content/uploads/2011/07/Episode7.mp3" fileSize="93129581" type="audio/mpeg" /><itunes:explicit>yes</itunes:explicit><itunes:subtitle>Infosec,Drunks and Ducks Trolling the Examiner @Abhaxas gets vanned, dies or something mid show.. We just keep Going&amp;#8230; Talk About Defcon and some other news&amp;#8230; Regular Hosts Aricon IllWill Spridel Abhaxas</itunes:subtitle><itunes:summary>Infosec,Drunks and Ducks Trolling the Examiner @Abhaxas gets vanned, dies or something mid show.. We just keep Going&amp;#8230; Talk About Defcon and some other news&amp;#8230; Regular Hosts Aricon IllWill Spridel Abhaxas</itunes:summary><itunes:keywords>infosec,risk,news,rant,ISC2,information,Security,Risk,Policy,Drunks</itunes:keywords><feedburner:origLink>http://jadedsecurity.net/2011/07/31/episode-7/</feedburner:origLink></item>
		<item>
		<title>Episode #6</title>
		<link>http://feedproxy.google.com/~r/jadedsecurity/pHAE/~3/GAponNd_IeI/</link>
		<comments>http://jadedsecurity.net/2011/07/30/740/#comments</comments>
		<pubDate>Sat, 30 Jul 2011 00:38:05 +0000</pubDate>
		<dc:creator>boris.sverdlik@jadedsecurity.com</dc:creator>
				<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://jadedsecurity.net/?p=740</guid>
		<description><![CDATA[Infosec,Drunks and Ducks John Foster (@dezlock) joins to discuss his interesting piece on the libertarian view in response to paypal Link Regular Hosts Aricon IllWill Spridel Abhaxas]]></description>
			<content:encoded><![CDATA[<p><a href="http://jadedsecurity.net/wp-content/uploads/2011/07/podcastimage1.jpg"><img class="aligncenter size-full wp-image-675" title="podcastimage" src="http://jadedsecurity.net/wp-content/uploads/2011/07/podcastimage1.jpg" alt="" width="583" height="549" /></a></p>
<p><a href="http://jadedsecurity.net/wp-content/uploads/2011/06/Episode6.mp3">Infosec,Drunks and Ducks</a></p>
<p>John Foster (@dezlock) joins to discuss his interesting piece on the libertarian view in response to paypal <a href="http://dearestleader.me/2011/07/20/why-we-dont-need-an-antisec-hunt/" target="_blank">Link</a></p>
<p>Regular Hosts<br />
Aricon<br />
IllWill<br />
Spridel<br />
Abhaxas</p>

<p><a href="http://feedads.g.doubleclick.net/~a/fxupakRZvn5SRvLmXiTdgdX8SVs/0/da"><img src="http://feedads.g.doubleclick.net/~a/fxupakRZvn5SRvLmXiTdgdX8SVs/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/fxupakRZvn5SRvLmXiTdgdX8SVs/1/da"><img src="http://feedads.g.doubleclick.net/~a/fxupakRZvn5SRvLmXiTdgdX8SVs/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=GAponNd_IeI:-lgmz1wc-5s:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=GAponNd_IeI:-lgmz1wc-5s:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=GAponNd_IeI:-lgmz1wc-5s:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=GAponNd_IeI:-lgmz1wc-5s:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=GAponNd_IeI:-lgmz1wc-5s:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=GAponNd_IeI:-lgmz1wc-5s:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=GAponNd_IeI:-lgmz1wc-5s:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/jadedsecurity/pHAE/~4/GAponNd_IeI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://jadedsecurity.net/2011/07/30/740/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://jadedsecurity.net/wp-content/uploads/2011/06/Episode6.mp3" length="132138437" type="audio/mpeg" />
		<media:content url="http://jadedsecurity.net/wp-content/uploads/2011/06/Episode6.mp3" fileSize="132138437" type="audio/mpeg" /><itunes:explicit>yes</itunes:explicit><itunes:subtitle>Infosec,Drunks and Ducks John Foster (@dezlock) joins to discuss his interesting piece on the libertarian view in response to paypal Link Regular Hosts Aricon IllWill Spridel Abhaxas</itunes:subtitle><itunes:summary>Infosec,Drunks and Ducks John Foster (@dezlock) joins to discuss his interesting piece on the libertarian view in response to paypal Link Regular Hosts Aricon IllWill Spridel Abhaxas</itunes:summary><itunes:keywords>infosec,risk,news,rant,ISC2,information,Security,Risk,Policy,Drunks</itunes:keywords><feedburner:origLink>http://jadedsecurity.net/2011/07/30/740/</feedburner:origLink></item>
		<item>
		<title>Episode #5.5</title>
		<link>http://feedproxy.google.com/~r/jadedsecurity/pHAE/~3/WTfLOhHoDpQ/</link>
		<comments>http://jadedsecurity.net/2011/07/30/episode-5-5/#comments</comments>
		<pubDate>Sat, 30 Jul 2011 00:34:40 +0000</pubDate>
		<dc:creator>boris.sverdlik@jadedsecurity.com</dc:creator>
				<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://jadedsecurity.net/?p=738</guid>
		<description><![CDATA[Infosec,Drunks and Ducks Drunken Mess Weekend Show&#8230; Regular Hosts Aricon IllWill Spridel Abhaxas]]></description>
			<content:encoded><![CDATA[<p><a href="http://jadedsecurity.net/wp-content/uploads/2011/07/podcastimage1.jpg"><img class="aligncenter size-full wp-image-675" title="podcastimage" src="http://jadedsecurity.net/wp-content/uploads/2011/07/podcastimage1.jpg" alt="" width="583" height="549" /></a></p>
<p><a href="http://jadedsecurity.net/wp-content/uploads/2011/06/Episode5_and_half.mp3">Infosec,Drunks and Ducks</a></p>
<p>Drunken Mess Weekend Show&#8230; </p>
<p>Regular Hosts<br />
Aricon<br />
IllWill<br />
Spridel<br />
Abhaxas</p>

<p><a href="http://feedads.g.doubleclick.net/~a/em6XczDCUjUjfPZ-fz4PUoHqRew/0/da"><img src="http://feedads.g.doubleclick.net/~a/em6XczDCUjUjfPZ-fz4PUoHqRew/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/em6XczDCUjUjfPZ-fz4PUoHqRew/1/da"><img src="http://feedads.g.doubleclick.net/~a/em6XczDCUjUjfPZ-fz4PUoHqRew/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=WTfLOhHoDpQ:Yc9gRIM4o_A:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=WTfLOhHoDpQ:Yc9gRIM4o_A:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=WTfLOhHoDpQ:Yc9gRIM4o_A:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=WTfLOhHoDpQ:Yc9gRIM4o_A:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=WTfLOhHoDpQ:Yc9gRIM4o_A:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?i=WTfLOhHoDpQ:Yc9gRIM4o_A:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?a=WTfLOhHoDpQ:Yc9gRIM4o_A:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/jadedsecurity/pHAE?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/jadedsecurity/pHAE/~4/WTfLOhHoDpQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://jadedsecurity.net/2011/07/30/episode-5-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://jadedsecurity.net/wp-content/uploads/2011/06/Episode5_and_half.mp3" length="211201548" type="audio/mpeg" />
		<media:content url="http://jadedsecurity.net/wp-content/uploads/2011/06/Episode5_and_half.mp3" fileSize="211201548" type="audio/mpeg" /><itunes:explicit>yes</itunes:explicit><itunes:subtitle>Infosec,Drunks and Ducks Drunken Mess Weekend Show&amp;#8230; Regular Hosts Aricon IllWill Spridel Abhaxas</itunes:subtitle><itunes:summary>Infosec,Drunks and Ducks Drunken Mess Weekend Show&amp;#8230; Regular Hosts Aricon IllWill Spridel Abhaxas</itunes:summary><itunes:keywords>infosec,risk,news,rant,ISC2,information,Security,Risk,Policy,Drunks</itunes:keywords><feedburner:origLink>http://jadedsecurity.net/2011/07/30/episode-5-5/</feedburner:origLink></item>
	<media:rating>adult</media:rating><media:description type="plain">JadedExposure</media:description></channel>
</rss>

