Paul's Security Weekly - Episode 379 for Thursday July 3rd, 2014

And now, from the dark corners of the Internet, where exploits run wild, packets aren’t the only things getting sniffed, and the beer flows steady its Paul’s Security Weekly!

"Now, fire up a packet capture, pour yourself a beer, and give the intern control of your botnet..."

"Here's your host, a huge fan of the little chubby monster, thinks wider is better, and loves the tight shot on his crooked wood", Paul Asadoorian!"

Tech Segment: Disrupting opportunistic SSH Scanners

By: Ben "Get Out of my House" Jackson

Paul's Stories

  1. Remote Access Hack Compromises POS Vendor - Light on details, but seems to be the newer POS systems that use tablets. Wondering what the backend looks like...
  2. Mysterious cyberattack compromises more than a thousand power plant systems - A thousand? Yikes.
  3. Attackers poison legitimate apps to infect sensitive industrial control systems | Ars Technica
  4. Burp Suite Tutorial – Web Application Penetration Testing (Part 1)
  5. Locking down PHP
  6. OpenSSL describes its own sad state of affairs
  7. Netflix Open Sources AWS Monitoring Tool: Security Monkey!
  8. Living Up To Rock Star Status
  9. How to Become a PMP
  10. Exploding Cigarettes and AppSec

Larry's Stories

  1. GSM with a beagle bone Black - [Larry] - Yes, you too can set up your own GSM base station. Sure you’ve been able to do that for a while with OpenBTS, but using it with a small form factor computer is cool. Drone based cell tower anyone?
  2. Ciscohno-you-didnt - [Larry] - Oh no, they did. Yes, default private SSH keys left behind on Unified Communication Domain Manager, world readable. I’m assuming that the SSH key is the same for all devices and is hard coded, In that if you recover one, you recover the private key for all installed implementations.
  3. Hey, Google, can you “unsend" that - [Larry] - A Goldman Sachs contractor accidentally sent an e-mail with boatloads of sensitive customer data to a google e-mails dress by mistake. Uh huh. Sure, by mistake. Now GS wants google to “unsend it”…it more accurately delete it form the gmail recipients mailbox. I see a whole lot wrong here: 1.) why sending sensitive info by e-mail as a matter of business process? 2.) contractor was using who’s e-mail server? 3.) where was DLP in any of this?
  4. Backtrack as a Pineapple - [Larry] - Definitely the DIY version without the nice sexy interface, but still small form factor RasPi
  5. Hackin’ like it is 1980 - [Larry] by leveraging commands that use wild cards in combination with specifically named and craved files, it is possible for arbitrary or other comannds to be run…This is way old school, but is still likely possible on modern *NIX systems including OSX.
  6. Tor nodes illegal in Austria? - [Larry] - Damn, where is CJR when we need him? A gentleman was running a TOR exit node from his home in Austria and it was used to commit computer crimes. He was arrested, charged and found guilty of being an accomplice. Yikes. This sets all kinds of interesting precedence.