124 posts categorized "Podcast"

 

Tenable Network Security Podcast Episode 101

Welcome to the Tenable Network Security Podcast Episode 101

Hosts

  • Paul Asadoorian, Product Evangelist
  • Carlos Perez, Lead Vulnerability Researcher
  • Jack Daniel, Product Manager

Announcements

Stories

  • Chasing APT: Persistence Pays Off - One of my greatest concerns that this article reminded me of is the risk to small business. And by small I mean the number of employees, not how much money they manage. You could likely construct a lucrative business attacking small firms that manage a LOT of money, but are small and have no dedicated IT team, let alone a dedicated security person.
  • Exposing the Market for Stolen Credit Cards Data - Maybe its just me but given that this article states "Liberty Reserve is the payment option of choice for the majority of the portals" can't you just follow the money and/or go after the organizations that are allowing the transactions? I'm sure its far more complicated than that, but just a thought. I'm sure that when targeting drug cartels and organized crime similar avenues are explored.
  • EFF on HTTPS - Great quote from this article: "In short: there are a lot of ways to break HTTPS/TLS/SSL today, even when websites do everything right." So true! There has to be a better way to get this SSL thing fixed. One suggestion from folks at the EFF was to have users rank SSL certificate authorities to build public trust into SSL.
  • US observation satellites hacked - I love this: "The article states that the nature of the attack appears to point to the Chinese military, though it stops short of making a direct accusation." Everyone is always quick to blame the Chinese, likely because people are saying "Well, if anyone would want to hack into a satellite it would be them". I'm saying who wouldn't want to hack into a satellite, thats so cool!
  • Cisco WebEx Player Buffer Overflows Let Remote Users Execute Arbitrary Code - Webex is popular software, and if you were to hold a webinar and tell people they get something for free, you could probably compromise a lot of systems with this vulnerability.
  • 6 Deadly Enterprise Security Mistakes - I have to say, usually when I see articles like this, I take the opportunity to rip them to shreds. I will not do that with this article because I agree with it 110%. Nicely done.
  • Hackers could have TAKEN OVER Amazon Web Services - Imagine if you could take over the cloud, would that make you God for a day?
  • The 8 Craziest YouTube Account Hacks - This is just fun and covers "Beiber Fever" and "Hanna Montana faking her death". Just doesn't get any better than this!
  • Why You Still Can’t Teach a Machine to Hack - I wanted to again explore the debate over automation versus manual testing.
  • US Government Regulations on Piracy

Download Tenable Podcast Episode 101

 

Tenable Network Security Podcast - Episode 100

Welcome to the Tenable Network Security Podcast Episode 100

Hosts

Announcements

Stories

In honor of the 100th Tenable podcast, and the nine year anniversary of Tenable Network Security, we've decided to produce a special podcast episode. In this episode we sit down with the founders of Tenable Network Security and ask them ten questions:

  1. How did the three of you meet?
  2. What spawned the idea to create Tenable Network Security?
  3. What are the qualities of Nessus, and its author, that were the driving factors to create the company around it?
  4. What was the first new product created as a company?
  5. What are some of your most favorite milestones in the companies history?
  6. What gets you most excited when you go to work everyday?
  7. What are some of the greatest challenges that organizations face in security and how do our products help them?
  8. What is the strangest feature request you've ever received?
  9. The creation of LCE, the Tenable Log Correlation Engine, is a distinct separatation from vulnerability management. What prompted this move and how does this product set itself apart from other products in the line?
  10. What's coming next for the company and Tenable's products? Spoiler Alert: Renaud gives us a sneak peek into the next version of Nessus!

Download Tenable Podcast Episode 100

 

Tenable Network Security Podcast - Episode 99

Welcome to the Tenable Network Security Podcast - Episode 99

Hosts

  • Paul Asadoorian, Product Evangelist
  • Carlos Perez, Lead Vulnerability Researcher
  • Jack Daniel, Product Manager

Announcements

Stories

  1. iPhone 5 Emails Infect Windows PCs with Malware - Attackers have proven to be very opportunistic when it comes to email scams and malware. Take the iPhone 5 for example, emails sent to thousands of people in an effort to get them to read up on the iPhone 5, which from the screenshot appears to be completely transparent. A neat defiance of physics, the real kicker being that Apple announced the 4S, not iPhone 5 yesterday.
  2. The 20 Controls That Aren’t - Ben Tomhave calls out the SANS CAG as 1) Not being actionable 2) Not able to scale and 3) Being designed to sell a product. While I agree in principle, its all about how you use the tools and guidelines. For example, if I want to know the areas that I should be covering in my information security program and some tips on how to do that, I might turn to the SANS CAG. Then I would go to the CIS benchmarks for recommendations about how to configure my systems security. At the end of the day, I am going to have to buy some products to help me get the job done, and I believe the various standards do not recommend a vendor, but areas in which you should focus on to help secure your organizations. Having said that, don't ignore vendors that provide products or services outside published guidelines, sometimes they can help you the most (of course, sometimes they are just the opposite).
  3. Some Hotel Safes Not So… Safe - We may have covered this one before, but just a reminder, the hotel safes are not safe and there are videos all over the web showing the default password. This one has reached true full-on public status. So you can either carry all of your stuff with you, or is there such a thing as a travel safe? Or, do you try to hack the safe first before putting your valuables in it?
  4. Cisco Patches Slew of IOS Bugs - I love this: "A vulnerability exists in the Smart Install feature of Cisco Catalyst Switches running Cisco IOS Software that could allow an unauthenticated, remote attacker to perform remote code execution on the affected device. Smart Install uses TCP port 4786 for communication. An established TCP connection with a completed TCP three-way handshake is needed to be able to trigger this vulnerability" Yeah, because a full TCP-Three-Way handhake is a defense, that'll stop em'! I love remote code execution on a switch, yes make my port a mirror port. No one is in a big hurry to apply an update to a switch either.
  5. Post Exploitation Shellbaging Security Aegis - I thought Carlos would enjoy this one, its a post-exploitation script that performs an interesting type of file system forensics: "Since the ShellBag keys store various metadata on how Windows Explorer items were arranged and since they are recorded for each user, from a computer forensics standpoint, one can parse the data and pull out various pieces of information that relate to user interaction. When combined with other available computer artifacts, it could provide a more complete picture of what files were accessed or deleted by the user and from what storage device they were accessing at the time (could be either an internal, external or network storage device)."
  6. File Disclosure Browser - DigiNinja - Ever see those weird .DS_Store files on various shares, web servers, and even on your own file systems and USB drives? Turns out those come from OS X and can contain information about your files, and even the location of some hidden files. Robin Wood's script extracts this information from .DS_Store files posted on web sites.
  7. NOTE: This page has been known to trigger A/V alerts, visit at your own risk! - http://securityxploded.com/passwordsecrets.php - Password Secrets of Popular Windows Applications - What a great list of applications and where they store their passwords, and how!
  8. Collected 1st & 2nd Level Domains - Some neat research from Max, who has collected 1st and 2nd level domain information, enumerating the domain names across large sections of the Internet.
  9. Fail a Security Audit Already -- It's Good for You - If that's the case, everyone is really healthy! However, failing is a part of learning. Most do not pass their first security audit, if you do, then why did you pay for one in the first place? You security audit should be telling you things you can do better, because chances are what you are doing has a few gaps or is just simply not enough. Audits, assessments, and penetration tests should tell you something you didn't already know.
  10. More Than One-Fourth of Google Chrome Extensions Contain Vulnerabilities - This is one of the things that keeps me up at night. We rely on all of these frameworks, and each of the frameworks allows people to write code and install it on your system(s). Sometimes that code does evil things.
  11. Sometimes the Security Helpdesk Gets The Last Laugh - Word to the wise: Format and re-install your OS after you've contracted Malware.
  12. Air Traffic Control Data Found on eBayed Network Gear
  13. Bank of America Website Disrupted for Fourth Day in a Row
  14. Check Your Machines for Malware, Linux Developers Told - I wonder if they are also formatting and re-installing? Oh wait, its Linux, it doesn't get viruses.
  15. Law Enforcement Increasingly Asking Internet Companies to Share Data - Yes, 4th Amendment in full swing, we need a warrant, we can't get one, so can you collect the evidence for us?
  16. Amazon Kindle Tablet Routes Web Traffic to Cloud First

Download Tenable Podcast Episode 99

 

Tenable Network Security Podcast Episode 98

Welcome to the Tenable Network Security Podcast - Episode 98

Hosts

  • Paul Asadoorian, Product Evangelist
  • Carlos Perez, Lead Vulnerability Researcher
  • Jack Daniel, Product Manager

Announcements

Stories

  1. Don’t Hit the Snooze Button on DigiNotar Alarm Bells - In 1995, we suggested the usage of network firewalls and SSL to protect web applications, and today we suggest that network firewalls and SSL protect cloud computing. There is a balance between evolving countermeasures and not hitting the snooze button on defensive technologies.
  2. So-so SASO … So What? - Bringing more balance to security, there is room for automated testing and static code analysis, but should you let a 3rd party analyze your code? Most would say "Yes", unless you are Oracle...
  3. Sound Database Security Starts With Segmentation - Segmentation needs to have context around it, and be based on the classification and location of your data.
  4. SIEM: Dead as Claimed? - Computerworld - Its fun to see which technology will be declared dead, first it was IDS, now SIEM. Is it really dead?
  5. 3 Indicted in Sophisticated Hacking Scheme - Attacker drove around the city of Seattle and broke into companies physical buildings and/or wireless networks, installed malware on their systems, and attempted to make a profit.
  6. SecurityTracker: Apache Tomcat HTTP DIGEST Authentication Weaknesses Let Remote Users Conduct Bypass Attacks - I've recommended that DIGEST authentication be used over BASIC authentication in Apache. If you implemented my suggestions, make sure you take notice of this patch!
  7. New OS X Trojan Horse sends Screenshots, Files to Remote Servers - I thought Macs didn't get viruses? Turns out they do...
  8. Facebook Unfriending 'Bug' Gets Quick Fix - For Facebook users, this is a big deal, as you don't want your "Friends" to know that you are breaking up with them.
  9. Man Builds Social Network Using Atlantic Ocean - I'd love to see the attacks against this social network, how would a cross-site scripting vulnerability play out?

Download Tenable Podcast Episode 98

 

Tenable Network Security Podcast - Episode 97

Welcome to the Tenable Network Security Podcast - Episode 97

Hosts

  • Paul Asadoorian, Product Evangelist
  • Carlos Perez, Lead Vulnerability Researcher
  • Jack Daniel, Product Manager

Announcements

Continue reading "Tenable Network Security Podcast - Episode 97" »

 

Tenable Network Security Podcast - Episode 96

Welcome to the Tenable Network Security Podcast - Episode 96

Hosts

  • Paul Asadoorian, Product Evangelist
  • Carlos Perez, Lead Vulnerability Researcher
  • Ron Gula, CEO/CTO

Announcements

Stories

  • 15 Years of Software Security: Looking Back and Looking Forward - First a look back: Remember "Smashing the Stack for Fun and Profit"? Buffer overflows were all the rage and resulted in what the author calls "undesired functionality" in applications. Vendors tended to ignore the vulnerability disclosure process, and many more vulnerabilities and associated exploits floated around the Internet until vendors decided to patch them (or not). The security community as a whole grew up, many companies were created to sell products, and many got bought and folded into larger companies. Before we look into the future, what has really changed? Web applications have provided us with a newer form of the buffer overflow, as the vulnerabilities lead to "undesired functionality", and are as plentiful, if not more, than traditional buffer overflows were. The difference is that they are now spread across thousands of applications and many require end-user interaction. The author then looks into the future, which is dangerous depending on how you look at it. Since it hasn't occurred yet, you can make predictions and it doesn't matter if you were correct or not... it was just a prediction.

Continue reading "Tenable Network Security Podcast - Episode 96" »

 

Tenable Network Security Podcast - Episode 95

Welcome to the Tenable Network Security Podcast - Episode 95

Hosts

  • Paul Asadoorian, Product Evangelist
  • Jack Daniel, Product Manager
  • Carlos Perez, Lead Vulnerability Researcher
  • Ron Gula, CEO/CTO

Announcements

Stories

Continue reading "Tenable Network Security Podcast - Episode 95" »

 

Tenable Network Security Podcast - Episode 94

Welcome to the Tenable Network Security Podcast - Episode 94

Hosts:

  • Paul Asadoorian, Product Evangelist
  • Jack Daniel, Product Manager
  • Carlos Perez, Lead Vulnerability Researcher

Announcements

Continue reading "Tenable Network Security Podcast - Episode 94" »

 

Tenable Network Security Podcast - Episode 93

Welcome to the Tenable Network Security Podcast - Episode 93

Hosts:

  • Paul Asadoorian, Product Evangelist
  • Ron Gula, CEO/CTO
  • Jack Daniel, Product Manager
  • Carlos Perez, Lead Vulnerability Researcher

Announcements


Continue reading "Tenable Network Security Podcast - Episode 93" »

 

Tenable Network Security Podcast - Episode 92

Welcome to the Tenable Network Security Podcast - Episode Episode 92

Hosts:

  • Paul Asadoorian, Product Evangelist
  • Ron Gula, CEO/CTO
  • Carlos Perez, Lead Vulnerability Researcher

Announcements

Continue reading "Tenable Network Security Podcast - Episode 92" »

 

Tenable Network Security Podcast - Episode 90

Welcome to the Tenable Network Security Podcast - Episode 90

Hosts:

  • Paul Asadoorian, Product Evangelist
  • Ron Gula, CEO/CTO
  • Carlos Perez, Lead Vulnerability Researcher
  • Jack Daniel, Product Manager

Announcements

  • Several new blog posts have been published this week, including:

  • LCE WMI Monitor Agent 3.6.0 Now Available
  • Check out our video channel on YouTube that contains the latest Nessus and SecurityCenter 4 tutorials. The latest two videos are updates to older videos and cover basic vulnerability scanning and local patch auditing using Nessus.
  • We're hiring! - Visit the Tenable web site for more information about open positions.
  • You can subscribe to the Tenable Network Security Podcast on iTunes!
  • Tenable Tweets - You can find us on Twitter at http://twitter.com/tenablesecurity where we make product and company announcements, provide Nessus plugin statistics and more!
  • Stories

    Continue reading "Tenable Network Security Podcast - Episode 90" »

     

    Tenable Network Security Podcast - Episode 89

    Welcome to the Tenable Network Security Podcast - Episode 89

    Hosts:

    • Paul Asadoorian, Product Evangelist
    • Ron Gula, CEO/CTO
    • Carlos Perez, Lead Vulnerability Researcher
    • Jack Daniel, Product Manager

    Announcements

    Stories

    • Facebook blocks a second contact export tool - Information, in the right context, can be quite powerful and expose your privacy. Facebook recently blocked Google+ from exporting your list of Facebook friends' names (not email addresses). When you put this in the context of attacks, knowing the names of someone's friends on Facebook could be quite valuable for social engineering.

    Continue reading "Tenable Network Security Podcast - Episode 89" »

     

    Tenable Network Security Podcast - Episode 88

    Welcome to the Tenable Network Security Podcast - Episode 88

    Hosts: Paul Asadoorian, Product Evangelist

    Announcements

    Interview: Jesse Kornblum

    Jesse Kornblum is a Computer Forensics Research Guru with the Kyrus Technology

    Continue reading "Tenable Network Security Podcast - Episode 88" »

     

    Tenable Network Security Podcast - Episode 86

    Welcome to the Tenable Network Security Podcast - Episode 86

    Hosts: Paul Asadoorian, Product Evangelist, Ron Gula, CEO/CTO, Carlos Perez, Lead Vulnerability Researcher

    Announcements

  • Check out our video channel on YouTube that contains the latest Nessus and SecurityCenter 4 tutorials. The latest two videos are updates to older videos and cover basic vulnerability scanning and local patch checking using Nessus.

  • We're hiring! - Visit the Tenable web site for more information about open positions.

  • You can subscribe to the Tenable Network Security Podcast on iTunes!

  • Tenable Tweets - You can find us on Twitter at http://twitter.com/tenablesecurity where we make product and company announcements, provide Nessus plugin statistics and more!

  • Jack Daniel joins Tenable as Product Manager.

  • Nessus for Android has been updated, including support for the Motorola Zoom.
  • Stories

    • Dan Kamsinky On The RSA SecurID Compromise - "I recommend replacing devices in an orderly fashion, possibly while increasing the rotation rate of PINs. I dismiss concerns about source compromise on the grounds that both hardware and software are readily reversed, and anyway we didn’t change operational behavior when Windows or IOS source leaked." It's true, when entire operating systems' source code has leaked, no one really panicked or changed the way they do business. Yes, you should be replacing all your tokens and, of course, have some other forms of security and authentication other than SecurID.

    Continue reading "Tenable Network Security Podcast - Episode 86" »

     

    Tenable Network Security Podcast - Episode 85

    Download Tenablepodcast-episode85.mp3

    Welcome to the Tenable Network Security Podcast - Episode 85

    Hosts: Paul Asadoorian, Product Evangelist, Ron Gula, CEO/CTO, Carlos Perez, Lead Vulnerability Researcher

    Announcements

  • Check out our video channel on YouTube that contains the latest Nessus and SecurityCenter 4 tutorials. The latest two videos are updates to older videos and cover basic vulnerability scanning and local patch checking using Nessus.

  • We're hiring! - Visit the Tenable web site for more information about open positions.

  • You can subscribe to the Tenable Network Security Podcast on iTunes!

  • Tenable Tweets - You can find us on Twitter at http://twitter.com/tenablesecurity where we make product and company announcements, provide Nessus plugin statistics and more!

  • Stories

    • RSA finally comes clean: SecurID is compromised - It turns out to be true: attackers possess the seed values for the tokens and the encryption algorithm is already public. RSA says they withheld the information because they did not want to tell attackers how to implement attacks, but it turns out evil bad guys figured it out and used it to attack Lockheed Martin. RSA is now offering to replace all 40 million+ SecurID tokens worldwide. Ouch. This is a breach that cost RSA dearly, in terms of money and reputation.

    Continue reading "Tenable Network Security Podcast - Episode 85" »

     

    Tenable Network Security Podcast - Episode 84

    Welcome to the Tenable Network Security Podcast - Episode 84

    Hosts: Paul Asadoorian, Product Evangelist, Ron Gula, CEO/CTO, Carlos Perez, Lead Vulnerability Researcher

    Announcements

    Discussion

    Continue reading "Tenable Network Security Podcast - Episode 84" »

     

    Tenable Network Security Podcast - Episode 83

    Welcome to the Tenable Network Security Podcast - Episode 83

    Hosts: Paul Asadoorian, Product Evangelist, Ron Gula, CEO/CTO, Carlos Perez, Lead Vulnerability Researcher

    Announcements

    • A new blog post has been published:
    • Check out our video channel on YouTube that contains the latest Nessus and SecurityCenter 4 tutorials. The latest two videos are updates to older videos and cover basic vulnerability scanning and local patch checking using Nessus.
    • We're hiring! - Visit the Tenable web site for more information about open positions.
    • You can subscribe to the Tenable Network Security Podcast on iTunes!
    • Tenable Tweets - You can find us on Twitter at http://twitter.com/tenablesecurity where we make product and company announcements, provide Nessus plugin statistics and more!
    • A new Nessus plugin is being released into the feed that will identify the device type of your targets. For example, if Nessus finds that a device is running Cisco IOS, it will flag it as device type: router. This is useful when reporting, trending, and "dashboarding" with SecurityCenter.
    • A new promotion is being run: All new Nessus Professional Feed users will receive a free demo of the Nessus Perimeter Service.
    • Upcoming Product Releases: SecurityCenter 4.2 and LCE 3.6.1. One of the major new features of SecurityCenter 4.2 is the ability to share dashboards. You can visit our dashboards page for a sneak preview.

    Stories

    Continue reading "Tenable Network Security Podcast - Episode 83" »

     

    Tenable Network Security Podcast - Episode 82

    Welcome to the Tenable Network Security Podcast - Episode 82

    Hosts: Paul Asadoorian, Product Evangelist

    Announcements

    Interview: KC Berg, Level3 Communications

    level3-logo-300x150.jpg

    KC works for Level3, the world's largest Internet service provider. He uses Nessus, and in a big way. They scan hundreds of thousands of IP addresses every day, customize NASL, and make extensive use of the API. KC is also a big fan of credentialed auditing and tells us how he uses that to help maintain security on some of the busiest networks in the world.

    Episode 82 Direct Download

     

    Tenable Network Security Podcast - Episode 81

    Welcome to the Tenable Network Security Podcast - Episode 81

    Hosts: Paul Asadoorian, Product Evangelist, Ron Gula, CEO/CTO

    Announcements

    Stories

    Continue reading "Tenable Network Security Podcast - Episode 81" »

     

    Tenable Network Security Podcast - Episode 80

    Welcome to the Tenable Network Security Podcast - Episode 80

    Hosts: Paul Asadoorian, Product Evangelist, Carlos Perez, Lead Vulnerability Researcher, Ron Gula, CEO/CTO

    Announcements

    Stories

    Continue reading "Tenable Network Security Podcast - Episode 80" »

     

    Tenable Network Security Podcast - Episode 79

    Welcome to the Tenable Network Security Podcast - Episode 79

    Announcements

    Continue reading "Tenable Network Security Podcast - Episode 79" »

     

    Tenable Network Security Podcast - Episode 78

    Welcome to the Tenable Network Security Podcast - Episode 78

    Hosts: Paul Asadoorian, Product Evangelist, Carlos Perez, Lead Vulnerability Researcher

    Announcements

    Stories

    Continue reading "Tenable Network Security Podcast - Episode 78" »

     

    Tenable Network Security Podcast - Episode 77

    Welcome to the Tenable Network Security Podcast - Episode 77

    Hosts: Paul Asadoorian, Product Evangelist, Carlos Perez, Lead Vulnerability Researcher, and Ron Gula, Tenable CEO/CTO

    Announcements

    Stories

    Continue reading "Tenable Network Security Podcast - Episode 77" »

     

    Tenable Network Security Podcast - Episode 76

    Welcome to the Tenable Network Security Podcast - Episode 76

    Hosts: Paul Asadoorian, Product Evangelist, Marcus Ranum, Tenable's CSO and Dave Poynter, Tenable Training Team

    Announcements

    Marcus Ranum Interview

    Marcus comes on the show to discuss risk management pitfalls, "APT" and more!

    Continue reading "Tenable Network Security Podcast - Episode 76" »

     

    Tenable Network Security Podcast - Episode 75

    Welcome to the Tenable Network Security Podcast - Episode 75

    Hosts: Paul Asadoorian, Product Evangelist & Dennis Brown, Research Engineer and "Malware Aficionado"

    Announcements

    Stories

    Continue reading "Tenable Network Security Podcast - Episode 75 " »

    Tenable Network Security


    The official BLOG of Tenable Network Security and Nessus vulnerability scanner.