Handler on Duty: Didier Stevens
Threat Level: green
Podcast Detail
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/4069.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
Are SOHO Routers SOHOplessly Broken? Google how to use crossdomain.xml files to avoid what happened with BING.
.......
Keeping the RATs out: Part 3
https://isc.sans.edu/forums/diary/Keeping+the+RATs+out+the+trap+is+sprung+-+Part+3/18415
SOHOPlessly Broken Challenge to Find Router Backdoors
http://sohopelesslybroken.com
Siemens ICS Suffer from Various SSL Bugs
http://ics-cert.us-cert.gov/advisories/ICSA-14-198-03
Open CrossDomain.XML file on Bing allows for CSRF
http://sethsec.blogspot.com/2014/07/crossdomain-bing.html
.......
Keeping the RATs out: Part 3
https://isc.sans.edu/forums/diary/Keeping+the+RATs+out+the+trap+is+sprung+-+Part+3/18415
SOHOPlessly Broken Challenge to Find Router Backdoors
http://sohopelesslybroken.com
Siemens ICS Suffer from Various SSL Bugs
http://ics-cert.us-cert.gov/advisories/ICSA-14-198-03
Open CrossDomain.XML file on Bing allows for CSRF
http://sethsec.blogspot.com/2014/07/crossdomain-bing.html
Discussion
New Discussions closed for all Podcasts older than two(2) weeks
Please send your comments to our Contact Form
| Application Security: Securing Web Apps, APIs, and Microservices | San Diego | May 11th - May 16th 2026 |
| Network Monitoring and Threat Detection In-Depth | Online | Arabian Standard Time | Jun 27th - Jul 2nd 2026 |
| Network Monitoring and Threat Detection In-Depth | Riyadh | Jun 27th - Jul 2nd 2026 |
| Application Security: Securing Web Apps, APIs, and Microservices | Washington | Jul 13th - Jul 18th 2026 |
| Application Security: Securing Web Apps, APIs, and Microservices | Online | British Summer Time | Jul 27th - Aug 1st 2026 |
| Application Security: Securing Web Apps, APIs, and Microservices | Las Vegas | Sep 21st - Sep 25th 2026 |
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Nov 9th - Nov 14th 2026 |
| Application Security: Securing Web Apps, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |





