Location:

United States

Description:

A show about infosec, technology and life!

Twitter:

@shellsharks

Language:

English

Contact:

5404247404


Episodes
Pídele al anfitrión que permita compartir el control de reproducción

The foremost expert on court cybersecurity vulnerabilities?

5/29/2024
Join me as I chat with Jason Parker, a Software Developer, Cybersecurity Researcher and Independent Journalist about hacking court systems, punycode, infosec training and more! !! Explicit Language Alert !! Show Notes Jason Parker on MastodonTwitter MigrationMaricopa County Superior Corut eFiling system disclosureMy call for Podcast guests on MastodonJeltzBluesky ExploitsDisorder In The CourtOWASP Broken Access Control404 MediaLockBit ransomware Fulton countyToothbrush botnetSecurity flaws in court record systems used in five US states exposed sensitive legal documents | Tech CrunchFlaws in public records management tool could let hackers nab sensitive data linked to requests | NextgovSoftware Flaws Exposed Sealed Court Docs, Researcher Says | Law360Multiple Vulnerabilities Affecting Web-Based Court Case and Document Management Systems | CISACalifornia Bar investigates after confidential discipline records published onlineState Bar of Calif. Data Breach Caused Confidential Disciplinary Records to Show Up on Third-Party Website, Class Action SaysMicrosoft RecallThe best counterargument to using RecallPunycodeSingle-letter second-level domainInteresting instance domainsDonate to the EFFISC2 certified in cybersecurityWeb Security AcademyCalifornia Consumer Privacy Act (CCPA)Other US States w/ Privacy LawsiTerm moves AI functionality into a pluginGovernor Wants to Prosecute Journalist Who Clicked View Source on Government SiteAWS Shared Responsibility Model

Duración:01:21:31

Pídele al anfitrión que permita compartir el control de reproducción

The Shellsharks Podcast is back! (Season 2)

5/23/2024
The Shellsharks Podcast is back! Season 2 begins now. Mastodon & Cyber-success w/ @rebootkid@ShellsharksPodcast@podcast.shellsharks.comdirect RSS linkShellsharks.com@shellsharks@shellsharks.social

Duración:00:01:43

Pídele al anfitrión que permita compartir el control de reproducción

Mastodon & Cyber-success w/ @rebootkid

5/9/2024
Positivity abounds in this edition of The Shellsharks Podcast! @rebootkid (Nate) joins me to discuss the great Infosec Mastodon migration, getting into infosec, mentorship, cybersecurity as a practice and management’s role in combatting burnout. MastodonStars, Boosts & TootsDiasporaInfosec.ExchangeFediverseDefcon.socialActivityPub rocks!Why I Blog. You Should Too!SQL SlammerWhat Certification or Training Should I Take?Interview w/ Security Engineer, Eva GeorgievaMFA Prompt BombingGetting Into Information SecurityAn Ode to RSSCybersecurity burnout is real

Duración:01:19:54

Pídele al anfitrión que permita compartir el control de reproducción

Privacy Chat w/ Dan Frechtling

5/9/2024
Boltive CEO and privacy advocate, Dan Frechtling joins me to discuss all things in the world of Internet privacy! I Said No to Online Cookies. Websites Tracked Me Anyway.Story of Dan Frechtling & Scott MooreGDPRLGPDCCPACPRASephora Privacy SettlementGlobal Privacy ControlThe American Data Privacy and Protection Act (ADPPA)Advanced Data Protection Control (ADPC)US Privacy StringOSINT Sock PuppetsRuTarget Harvesting Google DataExecutive Order on Protecting Foreign Intel from Surveilling US CitizensIs TikTok safe?Deprecation of third-party cookiesSSO wall of shameGDPR enforcement trackerFuture of Privacy ForumTROPT Defining the Privacy tech Landscape WhitepaperIAPPThree Ways Your Data is Leaking in Advertising and How to Avoid It

Duración:01:02:15

Pídele al anfitrión que permita compartir el control de reproducción

Interview w/ Security Engineer, Eva Georgieva

5/9/2024
Join myself (@shellsharks) and Eva Georgieva, security engineer and founder of #hackintocybersec as we discuss getting into infosec, cybersecurity education, women in cyber and more! Note: Had some challenges with audio leveling, I apologize for any audio weirdness! Uber IncidentEva’s AMA on Reddit#hackintocybersecOLLMOOTryHackMeHack The Box (Academy)TCM Security

Duración:00:59:12

Pídele al anfitrión que permita compartir el control de reproducción

Threat Hunting w/ Shahar Vaknin of Hunters.ai

5/9/2024
Join myself (@shellsharks) and Shahar Vaknin, Axon Team Lead at Hunters.ai as we discuss the world of Threat Hunting! Hunters.aiLong Tail AnalysisThe DFIR Report2022 CrowdStrike Global Threat ReportRed Canary 2022 Threat Detection ReportTwitter Global CERTs/CSIRTs/ISACs listMISPThreat Hunting w/ PythonThe Cyber Kill ChainshellsharksCIS Critical Security ControlsPractical Threat Hunting TrainingMITRE ATT&CK

Duración:01:21:57

Pídele al anfitrión que permita compartir el control de reproducción

Vuln Research & Exploit Dev w/ VoidSec

5/9/2024
Join myself (@shellsharks) and VoidSec as we discuss Exploit Development and Vulnerability Research! VoidSecThe Shellcoder’s HandbookOffensive Security | EXP-401 | AWE | OSEEGoogle Project ZeroPrintDemonVoidSec CVE-2020-1337ZerodiumImmunefiIDA ProBurp Suite Professional010 EditorGhidraBinaryNinjaThe Art of Software Security AssessmentRET2SYSTEMS TrainingZero Day Initiative (ZDI)TrendMicroCorelanCVE North StarsPwn2Ownsecret clubUpdatedSecurity

Duración:01:06:57

Pídele al anfitrión que permita compartir el control de reproducción

Zero Trust is not 0 or 1

5/9/2024
Join myself (@shellsharks) and Bobby DeSimone, Founder & CEO of Pomerium as we discuss the Pomerium platform, context-aware access control and all things Zero Trust! PomeriumLatin meaning of “pomerium”The Enchiridion of Impetus ExemplarJericho ForumThe Open Group Security ForumBeyondCorpNIST SP 800-207: Zero Trust ArchitectureMoving the US Government Toward Zero Trust Cybersecurity PrinciplesQ&A with Zero Trust Architecture Writers from NISTRego Policy LanguageOpen Policy AgentIstio Service MeshOpen Source Pomerium on GitHub2021 Twitter HackOASIS eXtensible Access Control Markup Language (XACML)HashiCorp Sentinel FrameworkAwesome Zero trust

Duración:00:55:14

Pídele al anfitrión que permita compartir el control de reproducción

Hacker Profile: Kevin Borders (NSA Red Team to Software Entrepreneur)

5/9/2024
A fascinating interview with Kevin Borders, where we discuss his origin story, time spent working on the NSA Red Team, growing a successful online collage business and his current venture, Minware! TI-85 Graphing CalculatorNumber MunchersDragonRealms, Gemstone III NSA Student ProgramsWeb Tap: detecting covert web trafficUniversity of Michigan PhD in CSEExecutive Order on Improving the Nation’s CybersecurityU.S. Cyber CommandChimera: A Declarative Language for Streaming Network Traffic AnalysisNSA SlidesSecuring Network Input via a Trusted Input ProxyTowards Quantification of Network-Based Information Leaks via HTTPSELinuxProject ZeroKevin Borders on QuoraDoes the NSA Have Better Engineers than Facebook or Google?About minwareHalting problemBlackhatDefcon100% PreventionWhat are some computer hacks that hackers know but most people don’t?The Most Hated Man on the InternetNSO Group iMessage Zero-Click Exploit, FORCEDENTRYOkta breach 2022NIST SP 800-207: Zero Trust ArchitectureSolarWinds BreachHow to Contribute to Open Source

Duración:01:34:44

Pídele al anfitrión que permita compartir el control de reproducción

”Extra Decentralized” (A discussion on Web3 and SLSA)

5/9/2024
Join myself (@shellsharks) and my good friend Mike (@QWORDsmith) as we discuss supply chain security via the SLSA framework, Web3 and more! MITRE ATT&CKOWASP Docker Top 10OWASP Kubernetes Top 10 SLSA - Supply Chain FrameworkSoftware Artifact ProvenanceSoftware Attestationsin-toto - Supply Chain FrameworkOpenSSF YouTube ChannelSLSA CommunitySLSA Githubslsa.devOWASP Software Component Verification StandardPocketNFTs, explains (The Verge)2021 Gamestop short squeezer/wallstreetbetsGameStop NFT MarketplaceImmortal GameReddit NFT MarketplaceBored Ape Yacht Club + Roaring 20’sCRYPTOCVESNVDMitreMoxie Marlinspike on NFTs and Web3Web3Web5 (lol)Bitcoin51% attacksPoly Network cryptocurrency hackWeb 3 is going just greatLattice-based cryptography Chinese Housewife Wikipedia MisinformationTwitter verification

Duración:01:17:34

Pídele al anfitrión que permita compartir el control de reproducción

Ransomware as a Podcast (RaaP)

5/9/2024
Join myself (@shellsharks) and Greg Edwards, CEO of CryptoStopper, as we discuss ransomware, existential cyber threats, the OST debate and more! Greg EdwardsCryptoStopperWannaCry ransomwareJigsaw ransomwareColonial Pipeline hackLambdaLockerSolarwinds Supply Chain Compromise18 CIS Critical Security ControlsRansomware as a Service (RaaS)Ransomware Payments via CryptoOST DebateShadow Brokers

Duración:01:03:02

Pídele al anfitrión que permita compartir el control de reproducción

Take a Fika

5/9/2024
Join myself (@shellsharks) and Thomas Peterson as we dive into his experience with Offensive Security’s challenging OSWE certification, discuss where we get our inspiration for blogging and more! tpetersonkth.github.ioOffensive Security - OSWEDEF CON YouTube channelHackTheBoxOffensive Security - OSCPThomas’s OSWE Review 2022Shellsharks Desk setupeLearnSecurity - PTPIKEAOG Shellsharks LookShellsharks - Captains Log Swedish Fika

Duración:01:18:24

Pídele al anfitrión que permita compartir el control de reproducción

Suburban Turtle

5/9/2024
Listen in on a fun conversation between myself (@shellsharks) and my friend/guest Kyle as we discuss everything from our monitor setups to OSINT leveraged in the Ukraine-Russia conflict to vendor APT Naming and more! !! Explicit Language Alert !! Check out my monitor setup via my Desk Setup 2021 postCheck out the apps I typically use via my Mac Tools postHone your coding skills with LeetcodeElite “PewPew” map courtesy of FireEye Ukraine Humanitarian FundGoogle (allegedly) un-blurring Russian satellite imageryTracking Russian soldiers using stolen iPhonesDestructive WipersNamed Vulnerabilities ListCrowdStrike APT Adversary UniverseMandiant APT NamingDragos Threat Activity Group NamesWhat is a Chollima?Offensive Security CoursesOffSec WEB-300/AWAE/OSWECertifications are not like Pokemon CardsShellsharks Podcast on BurnoutMy Reddit AMA“Thought Leader”The CISSPDoD 8570Metasploit Default Credential CVE

Duración:01:03:47

Pídele al anfitrión que permita compartir el control de reproducción

Security Friendliness Engineering

5/9/2024
Join myself (@shellsharks) and Scott Contini (from https://littlemaninmyhead.wordpress.com) as we discuss cryptography, AppSec, Log4J and more! Show Notes Main Show Little Man In My Head: https://littlemaninmyhead.wordpress.com Java Cryptography Architecture (JCA) Reference Guide - https://docs.oracle.com/javase/8/docs/technotes/guides/security/crypto/CryptoSpec.html NaCl: Networking and Cryptography library: https://nacl.cr.yp.to Don’t Roll Your Own Crypto: https://www.vice.com/en/article/wnx8nq/why-you-dont-roll-your-own-crypto Sony Playstation Hardcoded Key: https://www.engadget.com/2010-12-29-hackers-obtain-ps3-private-cryptography-key-due-to-epic-programm.html Cryptology vs Cryptography vs Cryptanalysis: https://militaryembedded.com/comms/encryption/cryptology-cryptography-and-cryptanalysis Deprecating MD5: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-52r2.pdf Ron Rivest: https://people.csail.mit.edu/rivest/ Quantum Cryptography: https://csrc.nist.gov/projects/post-quantum-cryptography AppSec Australia: https://www.meetup.com/en-AU/appsec-australia/ Grover’s Algorithm: https://en.wikipedia.org/wiki/Grover%27s_algorithm Internet Communications - TLS: https://www.cloudflare.com/learning/ssl/what-happens-in-a-tls-handshake/ DevSecOps: Just one definition - https://www.devsecops.org OWASP: https://owasp.org CAPTCHA: https://support.google.com/a/answer/1217728?hl=en reCAPTCHA: https://www.google.com/recaptcha/about/ Analyzing the OWASP Top 10: https://shellsharks.podbean.com/e/analyzing-the-owasp-top-10-2021/ OWASP Top 10: https://owasp.org/www-project-top-ten/ OWASP ASVS: https://owasp.org/www-project-application-security-verification-standard/ SAST: https://www.synopsys.com/glossary/what-is-sast.html Microservices: https://microservices.io DAST: https://www.whitesourcesoftware.com/resources/blog/dast-dynamic-application-security-testing/ OWASP Zap: https://owasp.org/www-project-zap/ SCA: https://www.synopsys.com/glossary/what-is-software-composition-analysis.html Inception: https://www.imdb.com/title/tt1375666/ Checkmarx Codebashing: https://checkmarx.com/product/codebashing-secure-code-training/ Security Champions: https://www.synopsys.com/blogs/software-security/security-champions-program-appsec-culture/ NIST SP 800-63B, Digital Identity Guidelines: https://pages.nist.gov/800-63-3/sp800-63b.html TruffleHog: https://trufflesecurity.com/trufflehog Log4Shell: https://log4shell.com/ CISA on Log4J Issue: https://www.cisa.gov/news/2021/12/11/statement-cisa-director-easterly-log4j-vulnerability Heartbleed: https://heartbleed.com Shellshock: https://nvd.nist.gov/vuln/detail/CVE-2014-6271 The Morris Worm: https://www.fbi.gov/news/stories/morris-worm-30-years-since-first-major-attack-on-internet-110218 ETERNALBLUE: https://nvd.nist.gov/vuln/detail/CVE-2017-0143 WANNACRY: https://www.cisa.gov/uscert/sites/default/files/FactSheets/NCCIC%20ICS_FactSheet_WannaCry_Ransomware_S508C.pdf Mandiant’s Report on Solarwinds Incident: https://www.mandiant.com/resources/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor BurpSuite: https://portswigger.net/burp Postshow Domain Squatting: https://www.godaddy.com/garage/what-is-domain-squatting-and-what-can-you-do-about-it/

Duración:01:12:42

Pídele al anfitrión que permita compartir el control de reproducción

Analyzing the OWASP Top 10 2021

5/9/2024
Join myself (@shellsharks) and my good friend Mike (@QWORDsmith) as we discuss the new OWASP Top 10 for 2021. Note on this episode: My audio was incredibly quiet during the recording so when editing I had to pump up the volume which introduced a fair bit of static. I apologize and hope the episode is bearable despite that static! Show Notes Preshow Simplenote: https://simplenote.com Notion: https://www.notion.so Obsidian: https://obsidian.md Visual Studio Code: https://code.visualstudio.com Notepad++: https://notepad-plus-plus.org/downloads/ GitHub Pages: https://pages.github.com Atom: https://atom.io Main Show Funny OWASP Top 10 2021 Tweet - https://twitter.com/CubicleApril/status/1437531584119386116?s=20 Infosec Blogs: https://shellsharks.com/infosec-blogs An Ode to RSS: https://shellsharks.com/an-ode-to-rss Shortcuts: https://apps.apple.com/us/app/shortcuts/id915249334 Netsparker Article on OWASP Top 10 2021: https://www.netsparker.com/blog/web-security/owasp-top-10-2021-not-what-you-think/ OWASP Top 10: https://owasp.org/www-project-top-ten/ OWASP ASVS: https://owasp.org/www-project-application-security-verification-standard/ OWASP Top 10 2010: https://owasp.org/www-pdf-archive/OWASP_Top_10_-_2010.pdf OWASP Top 10 2013: https://owasp.org/www-pdf-archive/OWASP_Top_10_-_2013.pdf OWASP Top 10 2017: https://owasp.org/www-pdf-archive//OWASP-Top-10-2017-en.pdf OMIGOD: https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure That’s some Galen Eros level shit: https://www.reddit.com/r/cybersecurity/comments/podx9q/omigod_widespread_azure_linux_vulns_in_hidden/ ChaosDB: https://chaosdb.wiz.io

Duración:01:20:27

Pídele al anfitrión que permita compartir el control de reproducción

Blogging & WGU

5/9/2024
Join myself (@shellsharks) and @cradersec as we discuss blogging, Western Governors University (WGU), home labs and more! Audio HijackRogue AmoebaOmniFocusTodoistNotionFantasticalGetting Things GNOME! Crader SecurityWhy I Blog. You Should Too!WGUShellsharks Captain’s LogMIT Open CoursewareRaspberry PiAWS Free TierPluralsightGitHub Developer PackGoogle Cloud Free TierPotent WisdomComing Soon!The Linux SmackComing Soon!The Privacy SmackComing Soon!TryHackMe Shellsharks Inbox ZeroDigital Minimalism

Duración:00:55:47

Pídele al anfitrión que permita compartir el control de reproducción

Burnout & Motivation

5/9/2024
Kyle (@cyberspacekyle) and Masie (@masiehabibi) join me (@shellsharks) once more to chat motivation and burnout in infosec and in life. We also have a fiery fitness challenge throw-down! I hope you enjoy this relatively short but lively episode! Apple Watch Fitness Competitions ShellsharksLinkedinBlind

Duración:00:42:41

Pídele al anfitrión que permita compartir el control de reproducción

Pentesting Chat (and Beer Chat)

5/9/2024
Join myself (@shellsharks) and my guest Sukrit (@sukritdua) as we chat pentesting, training, craft beer and more! Note: I apologize in advance as Sukrit’s audio was a little spotty. Enjoy! Collective Arts BrewingQuebec Maple CokeIcewineDragon Stout Kali LinuxHackerOneBugCrowdSANS Cyber Security BlogPortSwigger BlogINE / eLearnSecurityShellsharksGetting Into Information SecurityReddit FeedbackPTPOSCPTry HarderWeb Application Hackers HandbookWeb Security AcademyHacker101 CTFOverTheWirepicoCTFSANS Holiday Hack ChallengeCybraryPentesterAcademyPentesterLabeWPTeWPTXSANS SEC542INE PlansSANS Work Study ProgramSANS SummitsSAN SEC660Stephen SimsaCloudGuruPluralsightLinux Academy UntappdFoursquare@beersharks@AllPintsHill High MarketplaceuntappdScraperCaptains Log

Duración:01:00:29

Pídele al anfitrión que permita compartir el control de reproducción

Colonial Pipeline Hack & More!

5/9/2024
This week on The Shellsharks Podcast, @masiehabibi joins me (@shellsharks) to talk Clubhouse, ransomware, the Colonial Pipeline hack, Google I/O, iOS vs Android and more! https://www.joinclubhouse.com@shellsharkshttps://msrc-blog.microsoft.com/2021/03/05/microsoft-exchange-server-vulnerabilities-mitigations-march-2021/https://blog.twitter.com/en_us/topics/product/2021/spaces-is-here.htmlhttps://shellsharks.com/podcast https://www.wired.com/story/colonial-pipeline-ransomware-attack/https://www.tesla.comhttps://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/https://www.reuters.com/article/us-home-depot-cyber-settlement/home-depot-reaches-17-5-million-settlement-over-2014-data-breach-idUSKBN2842W5https://securityandtechnology.org/ransomwaretaskforce/report/https://csrc.nist.gov/publications/detail/sp/800-207/finalhttps://cloud.google.com/beyondcorp https://events.google.com/io/?lng=enhttps://www.blog.google/technology/ai/lamdahttps://www.apple.com/apple-events/april-2021/?useASL=truehttps://ai.googleblog.com/2018/05/duplex-ai-system-for-natural-conversation.htmlhttps://developer.apple.com/wwdc21/https://en.wikipedia.org/wiki/IOS_jailbreakinghttp://cydia.saurik.com/package/com.fire30.hackingwithfriends/

Duración:01:14:14

Pídele al anfitrión que permita compartir el control de reproducción

Getting Into Infosec (Part I)

5/9/2024
Join myself (@shellsharks), Kyle (@cyberspacekyle) and Masie (@masiehabibi) as we discuss Getting Into Information Security, what industry certifications are best to get for those new to the field and more! https://www.oldoxbrewery.comhttps://www.beeradvocate.com/beer/profile/215/2512/https://www.comptia.org/certifications/securityhttps://www.sans.orghttps://www.sans.org/cyber-security-courses/intrusion-detection-in-depth/https://acloudguru.comhttps://acloudguru.comhttps://www.giac.org/certifications/dodd-8570

Duración:01:10:28