Securit13 Podcast
Первый украинский подкаст об информационной безопасности

UISGCON14 https://14.uisgcon.org/ 
SECURITY BSIDES KYIV AUTUMN 2018 https://kyiv.securitybsides.org.ua/ 
Interview with Yanick Fratantonio http://www.s3.eurecom.fr/~yanick/ 

Securit13 Patreon https://www.patreon.com/securit13 
Keygen Music [2+ hour Mix] https://www.youtube.com/watch?v=cYkaG5CT53I 

Direct download: 104.mp3
Category:Technology -- posted at: 12:20pm CEST
Comments[0]

UISGCON14 https://14.uisgcon.org/ 
SECURITY BSIDES KYIV AUTUMN 2018 https://kyiv.securitybsides.org.ua/ 
Interview with Serhii Korolenko about #UISGCON14 #CTF

https://www.hackthis.co.uk 
The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
https://www.amazon.com/Web-Application-Hackers-Handbook-Exploiting/dp/1118026470 
Passing Security By - Serhii Korolenko https://www.youtube.com/watch?v=rDOYUCy9phA 
Serhii Korolenko - XSS from zer0 to Hero (Workshop) https://www.youtube.com/watch?v=mKqc9u_BRLM 

Securit13 Patreon https://www.patreon.com/securit13 
Keygen Music [2+ hour Mix] https://www.youtube.com/watch?v=cYkaG5CT53I 

Direct download: 106.mp3
Category:Technology -- posted at: 4:30pm CEST
Comments[0]

UISGCON14 https://14.uisgcon.org/ 
SECURITY BSIDES KYIV AUTUMN 2018 https://kyiv.securitybsides.org.ua/ 
Interview with Alexander Færøy

Tech billionaire Elon Musk smokes marijuana on podcast as shares fall and senior execs leave 

https://www.news.com.au/technology/innovation/motoring/tech-billionaire-elon-musk-smokes-marijuana-and-drinks-whiskey-on-podcast/news-story/b228f58547f797e012c26074b959435e 
Windows 10 to get disposable sandboxes for dodgy apps https://arstechnica.com/staff/2018/08/windows-10-to-get-disposable-sandboxes-for-dodgy-apps/ 
Mongo Lock Attack Ransoming Deleted MongoDB Databases https://www.bleepingcomputer.com/news/security/mongo-lock-attack-ransoming-deleted-mongodb-databases/ 
Open .Git Directories Leave 390K Websites Vulnerable https://threatpost.com/open-git-directories-leave-390k-websites-vulnerable/137299/ 
Tesla’s new bug bounty protects hackers — and your warranty https://techcrunch.com/2018/09/06/teslas-new-bug-bounty-protects-hackers-and-your-warranty/ 
How Bitcoin's hidden footprint is impacting water use https://www.thesourcemagazine.org/how-bitcoins-footprint-is-impacting-water-use/ 

Securit13 Patreon https://www.patreon.com/securit13 
Keygen Music [2+ hour Mix] https://www.youtube.com/watch?v=cYkaG5CT53I 

Direct download: 105.mp3
Category:Technology -- posted at: 3:58pm CEST
Comments[0]

Спеціальний епізод про відвідини 26ї конференції #DEFCON нашими співведучими

Direct download: special.mp3
Category:Technology -- posted at: 3:51pm CEST
Comments[0]

UISGCON14 https://14.uisgcon.org/ 
На Дніпропетровщині СБУ попередила кібератаку російських спецслужб на об’єкт критичної інфраструктури https://ssu.gov.ua/ua/news/1/category/2/view/5037#.MkS7rpun.dpbs 
Ukraine claims it blocked VPNFilter attack at chemical plant https://www.theregister.co.uk/2018/07/13/ukraine_vpnfilter_attack/ 
Speculative Buffer Overflows: Attacks and Defenses (pdf) https://people.csail.mit.edu/vlk/spectre11.pdf 
New Spectre 1.1 and Spectre 1.2 CPU Flaws Disclosed https://www.bleepingcomputer.com/news/security/new-spectre-11-and-spectre-12-cpu-flaws-disclosed/ 
Google Enables 'Site Isolation' Feature By Default For Chrome Desktop Users https://thehackernews.com/2018/07/google-chrome-site-isolation.html 
Вийшов річний звіт CISCO з кібербезпеки і піврічний звіт чекпоінт, але ми поговоримо про них наступного разу https://www.cisco.com/c/dam/global/uk_ua/assets/pdfs/Final_Files_Cisco_2018_ACR_Web.pdf?dtid=oemzzz000186&ccid=cc000160&ecid=10432&oid=anrsc005679 
Scam alert: No, hackers don't have webcam vids of you enjoying p0rno. Don't give them any $$s https://www.theregister.co.uk/2018/07/13/hacker_extortion_scam/ 
GitHub to Pythonistas: Let us save you from vulnerable code https://www.theregister.co.uk/2018/07/16/github_to_pythonistas_let_us_save_you_from_vulnerable_code/ 
Microsoft seeks regulation of facial recognition technology https://www.reuters.com/article/us-microsoft-facial-recognition/microsoft-seeks-regulation-of-facial-recognition-technology-idUSKBN1K32F0 
Two-factor auth totally locks down Office 365? You may want to check all your services... https://www.theregister.co.uk/2018/07/13/2fa_o365_bypass_attacks/ 
The Tale of SettingContent-ms Files https://posts.specterops.io/the-tale-of-settingcontent-ms-files-f1ea253e4d39 
Facebook fined for data breaches in Cambridge Analytica scandal https://amp.theguardian.com/technology/2018/jul/11/facebook-fined-for-data-breaches-in-cambridge-analytica-scandal 
Cops suspect Detroit fuel station was hacked before 10 drivers made off with 2.3k 'free' litres https://www.theregister.co.uk/2018/07/09/gas_station_hack/ 
2018-07 Security Bulletin: Junos OS: Junos OS: MPC7/8/9, PTX-FPC3 (FPC-P1, FPC-P2), PTX3K-FPC3 and PTX1K: Line card may crash upon receipt of specific MPLS packet (CVE-2018-0030) https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10864&cat=SIRT_1&actp=LIST 
Revoked Certificate when viewing mydlink IP Cameras with-in web-browsers https://securityadvisories.dlink.com/announcement/publication.aspx?name=SAP10089 
Certificates stolen from Taiwanese tech-companies misused in Plead malware campaign https://www.welivesecurity.com/2018/07/09/certificates-stolen-taiwanese-tech-companies-plead-malware-campaign/ 
Ammyy Admin compromised with malware again; World Cup used as cover https://www.welivesecurity.com/2018/07/11/ammyy-admin-compromised-malware-world-cup-cover/ 
https://regmedia.co.uk/2018/07/13/burkdoll_affidavit.pdf 
US: Government Has Planted Spy Phones With Suspects https://www.hrw.org/news/2018/07/13/us-government-has-planted-spy-phones-suspects 
The 111 Million Record Pemiblanc Credential Stuffing List https://www.troyhunt.com/the-111-million-pemiblanc-credential-stuffing-list/ 
June’s Most Wanted Malware: Banking Trojans Up 50% Among Threat Actors https://blog.checkpoint.com/2018/07/05/junes-most-wanted-malware-banking-trojans-crypto-mining/ 
Did CrowdStrike really miss the mark? https://medium.com/@rsatter/did-crowdstrike-really-miss-the-mark-ecedf0e09dd7 

Securit13 Patreon https://www.patreon.com/securit13 

Direct download: 103.mp3
Category:Technology -- posted at: 12:05pm CEST
Comments[0]

В этом эпизоде Алиса, Логин и Алексей поговорили про скандальный 6688, браузеры, уязвимости с лого и сайтами, и некоторые другие новости прошедших двух недель.

6688 http://w1.c1.rada.gov.ua/pls/zweb2/webproc4_1?pf3511=62236 
Github Gentoo organization hacked - resolved https://gentoo.org/news/2018/06/28/Github-gentoo-org-hacked.html
Apple corrects the record on reported iPhone vulnerability https://www.cyberscoop.com/iphone-brute-force-passcode-matthew-hickey/
Cops May Unlock iPhones Without a Warrant to Beat Apple's New Security Feature https://motherboard.vice.com/en_us/article/bj34wa/cops-unlock-iphones-without-a-warrant-apple-usb-restricted-mode
Facebook shells out $8k bug bounty after quiz web app used by 120m people spews profiles https://www.theregister.co.uk/2018/06/28/facebook_data_abuse_bug_bounty/
Former NSA contractor Reality Winner accepts guilty plea for leaking classified report https://www.cyberscoop.com/former-nsa-contractor-reality-winner-accepts-guilty-plea-leaking-classified-report/
Firefox is adding 'Have I Been Pwned' alerts https://www.cyberscoop.com/firefox-is-adding-haveibeenpwned-alerts/
«Грязный секрет» Gmail: письма пользователей читают не только сотрудники Google https://thebell.io/gryaznyj-sekret-gmail-pisma-polzovatelej-chitayut-ne-tolko-sotrudniki-google/
"Stylish" browser extension steals all your internet history https://robertheaton.com/2018/07/02/stylish-browser-extension-steals-your-internet-history/
Brave browser adds private tabs with Tor for 'enhanced privacy protection' https://www.cyberscoop.com/brave-browser-adds-tor-tabs/
Fusion https://wiki.mozilla.org/Security/Fusion
Alter attack https://alter-attack.net/
ProtonMail DDoS Attacks Are a Case Study of What Happens When You Mock Attackers https://www.bleepingcomputer.com/news/security/protonmail-ddos-attacks-are-a-case-study-of-what-happens-when-you-mock-attackers/
A year after devastating NotPetya outbreak, what have we learnt? Er, not a lot, says BlackBerry bod https://www.theregister.co.uk/2018/06/27/notpetya_anniversary/
New RAMpage attack affects all Android phones released since 2012 [Update] https://www.androidcentral.com/rampage-attack-discovered
Thanatos Ransomware Decryptor Released by the Cisco Talos Group https://www.bleepingcomputer.com/news/security/thanatos-ransomware-decryptor-released-by-the-cisco-talos-group/ 
First Nationwide Undercover Operation Targeting Darknet Vendors Results in Arrests of More Than 35 Individuals Selling Illicit Goods and the Seizure of Weapons, Drugs and More Than $23.6 Million https://www.justice.gov/opa/pr/first-nationwide-undercover-operation-targeting-darknet-vendors-results-arrests-more-35
The Perfect Weapon: War, Sabotage, and Fear in the Cyber Age https://www.amazon.com/Perfect-Weapon-Sabotage-Fear-Cyber/dp/0451497899/
UISGCON14 https://14.uisgcon.org/ 
Securit13 Patreon https://www.patreon.com/securit13 

Keygen Music [2+ hour Mix] https://www.youtube.com/watch?v=cYkaG5CT53I 

 

Direct download: 102.mp3
Category:Technology -- posted at: 7:00am CEST
Comments[0]

SecurityBsides Odessa CTF is open!
https://odessa.securitybsides.org.ua/#ctf 
All who wants to support BSides Odessa you can do it here 
https://bsidesodessa.ticketforevent.com/ 

SecurityBSides Kharkiv
https://kharkiv.securitybsides.org.ua 

The mysterious hacker who claimed responsibility for the hack on the DNC is likely a disinformation campaign by Russian spies.
https://motherboard.vice.com/en_us/article/wnxgwq/guccifer-20-is-likely-a-russian-government-attempt-to-cover-up-their-own-hack 

The security firm halted the work after questions were asked in the European Parliament about its software.
https://www.bbc.com/news/technology-44501506 

She wrote an email posing as him, turning down a $50,000-a-year scholarship so that he wouldn't leave
http://montrealgazette.com/news/local-news/mcgill-music-student-awarded-350000-after-girlfriend-stalls-career 

Commentary: People can no longer tell when they're chatting with a robot. Google, what have you done?
https://www.cnet.com/news/google-duplex-assistant-bot-deception-scary-ethics-question/ 
https://www.ieee-security.org/TC/SP2018/program.html 
https://www.cnet.com/news/google-duplex-assistant-bot-deception-scary-ethics-question/ 
https://www.engadget.com/2018/06/05/apple-safari-canvas-fingerprinting/ 
https://webkit.org/blog/8311/intelligent-tracking-prevention-2-0/ 
https://fpcentral.tbb.torproject.org 

Apple is going after another way sites track you for ads.
https://www.engadget.com/2018/06/05/apple-safari-canvas-fingerprinting/ 
https://webkit.org/blog/8311/intelligent-tracking-prevention-2-0/ 

Phone scammers are spoofing numbers to make them look familiar to you. You're more likely to pick up and trust the person on the other end
https://www.cnbc.com/2018/06/12/you-think-its-your-friend-calling-but-its-actually-this-growing-phone-scam.html 


Support us on Patreon https://patreon.com/securit13 

Direct download: 101.mp3
Category:Technology -- posted at: 1:35pm CEST
Comments[0]

Интервью с Александром Оленевым и Андреем Волошиным из Thea/Techmaker за жизнь, бизнес, обучение тренингам хардвер инженеров и немного про безопасность автомобилей.

https://www.youtube.com/watch?v=5QBOmr_ZyLo 
DEFCON 25 Nissan Leaf security

https://www.troyhunt.com/controlling-vehicle-features-of-nissan/ 
Controlling vehicle features of Nissan LEAFs across the globe via vulnerable APIs

https://users.ece.cmu.edu/~koopman/pubs/koopman14_toyota_ua_slides.pdf 
Tpyota unintended acceleration bug

http://esd.cs.ucr.edu/webres/can20.pdf 
CAN bus specs (BOSCH)

https://www.bmw.co.uk/bmw-ownership/connecteddrive 
BMW ConnectedDrive

https://www.macworld.co.uk/news/apple/apple-car-release-date-3425394/ 
Apple iCar release date rumours, features & images

https://www.nvidia.com/en-us/self-driving-cars/ 
NVIDIA Self-driving cars

https://hackaday.com/2017/06/19/intel-discontinues-joule-galileo-and-edison-product-lines/ 
Intel Discontinues Joule, Galileo, And Edison Product Lines

https://techmaker.ua 
TWIC who wants to participate as an AppSec mentor on Techmaker email to info@techmaker.ua

https://mobiliuz.com/ 
Connected cars

Books
Thinking, Fast and Slow, Daniel Kahneman ISBN 9785170800537 https://www.amazon.co.uk/Thinking-medlenno-reshay-bystro-Russian/dp/5170800533/ref=sr_1_1 
Franchesca, Dorje Batuu ISBN 978-617-679-485-1 https://www.yakaboo.ua/ua/francheska-povelitel-ka-traektorij.html 

 

Securit13 Patreon https://www.patreon.com/securit13

Direct download: 100.mp3
Category:Technology -- posted at: 12:44pm CEST
Comments[0]

16.06.2018 BSidesKharkiv https://kharkiv.securitybsides.org.ua/
07.06.2018 OWASP Odesa https://www.facebook.com/events/2104923576405410/
07.07.2018 BSidesOdessa https://odessa.securitybsides.org.ua/
Kostiantyn Korsun про NoNameCon https://www.facebook.com/kostiantyn.korsun/posts/840821456102957
EFAIL https://efail.de/
Efail: Breaking S/MIME and OpenPGP Email Encryption using Exfiltration Channels (draft 0.9.1) https://efail.de/efail-attack-paper.pdf
ProtonMail is safe against the efail PGP vulnerability. https://twitter.com/ProtonMail/status/995996112526954496
Efail or OpenPGP is safer than S/MIME https://lists.gnupg.org/pipermail/gnupg-users/2018-May/060315.html
Digital Photocopiers Loaded With Secrets https://www.cbsnews.com/news/digital-photocopiers-loaded-with-secrets/
Throwhammer: Rowhammer Attacks over the Network and Defenses https://www.cs.vu.nl/~herbertb/download/papers/throwhammer_atc18.pdf
Rowhammer strikes networks, Bolton strikes security jobs, and Nigel Thornberry strikes Chrome, and more http://www.theregister.co.uk/2018/05/12/security_roundup/
Memcached https://memcached.org/
7-Zip: From Uninitialized Memory to Remote Code Execution https://landave.io/2018/05/7-zip-from-uninitialized-memory-to-remote-code-execution/
IBM bans all removable storage, for all staff, everywhere http://www.theregister.co.uk/2018/05/10/ibm_bans_all_removable_storage_for_all_staff_everywhere/
Second wave of Spectre-like CPU security flaws won't be fixed for a while http://www.theregister.co.uk/2018/05/09/spectr_ng_fix_delayed/
Every major OS maker misread Intel's docs. Now their kernels can be hijacked or crashed http://www.theregister.co.uk/2018/05/09/intel_amd_kernel_privilege_escalation_flaws/
Ex-CIA man fingered as prime suspect in Vault 7 spy tool manuals leak http://www.theregister.co.uk/2018/05/15/vault_7_leak/
DHCP Client Script Code Execution Vulnerability - CVE-2018-1111 https://access.redhat.com/security/vulnerabilities/3442151

Securit13 Patreon https://www.patreon.com/securit13

Keygen Music [2+ hour Mix] https://www.youtube.com/watch?v=cYkaG5CT53I

Direct download: 99.mp3
Category:Technology -- posted at: 8:30am CEST
Comments[0]

Мы немного поговорили про конференции, организованные, будущие и посещенные.

#BSidesKyiv 2018 https://www.facebook.com/pg/BSidesUkraine/
Video https://www.youtube.com/channel/UCOSf0249iC28paeqYY5nRSQ
22.05.2018 WWCode Security event https://www.facebook.com/events/243552549527834/
16.06.2018 BSidesKharkiv https://kharkiv.securitybsides.org.ua/
07.07.2018 BSidesOdessa https://odessa.securitybsides.org.ua/
Jack Daniel https://twitter.com/jack_daniel/status/992135632616124416
GiSec https://www.gisec.ae/

Music - KEYGEN MUSIC ~ One hour mix https://www.youtube.com/watch?v=c17k4LfLkaE

Direct download: 98.mp3
Category:Technology -- posted at: 11:30am CEST
Comments[0]