Episode 0x1E -- Absenteeism
Insert Subtitle Here
With Matt and James out this week, Dave, Ben and Wil are left to their own devices. I think you'll understand what I mean when you get to the end.
Upcoming this week... Lots of News Breaches No Scadas, no Matt, No Jamie finishing it off with DERPs/Mailbag and Our new weekly Briefs - no arguing or discussion allowedAnd if you've got commentary, please sent it to mailbag@liquidmatrix.org for us to check out.
DISCLAIMER: It's not that explicit, but you may want to use headphones if you're at work.
ADDITIONAL DISCLAIMER: In case it is unclear, this is the story of 5 opinionated infosec pros who have sufficient opinions of their own they don't need to speak for anyone except themselves. Ok? Good.
In this episode:
News and Commentary The RCMP says they have no intention of using their Drones for surveilance purposes. Rapid7 white-paper says 81 million descrete publicly routable addresses responded to UPnP poll, as recently as last year. Sony fined many many quid India bars ZTE, Huawei and others from sensitive government projects Govt Sites Hacked Following Arrest of Alleged Jember Hacker FBI going after potential leakers of Stuxnet info Breaches - The never ending never ending story... USSC.gov Hacked : pwned Hackers in China Attacked The New York Times for Last 4 Months Errata / DERP of the week award Barracuda!!!! More Fishy Mailbag / Bizarro LandHi all,
Just came across this crazy story.GitHub's new search functionality has been temporarily disabled after users discovered they could search for juicy content that had been accidentally uploaded, such as private keys, known hosts, and bash history files. According to a couple of different accounts, some credentials and other sensitive data may already have been used to cause mischief.However, it's not all doom and gloom. Some doofus uploaded his home directory to GitHub, which in itself is mighty stupid. This immediately turned into something disturbing: his history contained mplayer commands aimed at playing videos of child pornography, with rather graphic titles. The details were summarily posted to Reddit, where an investigation ensued. GitHub has disabled the user's account, and it seems that a few people may have contacted his university.So, whilst it looks like GitHub's search features may have caused problems for a few users, it has also lead to the discover and outing of a paedophile.
Keep up the good work!
-- Graham Sutherland
Briefly - NO ARGUING OR DISCUSSION ALLOWED Red teaming at a CCDC Honey Spider Whisper Systems' Spring Break of Code FTC Reaches Settlement Over Cord Blood Bank's Data Breach Liquidmatrix Staff Projects The Security Conference Library Contribute to the Strategic Defense Execution Standard (#SDES) and you'll be Doing Infosec Right in no time. If you're interested in helping out with openCERT.ca, drop a line to info@openCERT.ca Upcoming Appearances: James and Dave at RSA e10+, also attending Shmoocon but not speaking In Closing We're thinking about doing a live podcast with audience participation - drop us a tweet or a line if you're interested Movie Review Under The Tuscan Scan everyday is CTF! go set up a team Signing up for a SANS course? Be sure to use the code "Liquidmatrix_150" and save $150 off the course fee! Seacrest Says: vote SEACREST!!!!!... I mean LiquidMatrixCreative Commons license: BY-NC-SA