"Wait, Wait! Don't pwn Me!"- AppSec Europe 2014

Preview:

DESCRIPTION

Update: You can now view a recording of the session while testing yourself against the "Expert" panel! https://www.youtube.com/watch?v=VIS9fXZXJ44&feature=youtu.be&t=5h47m12s "Wait, wait! Don't pwn Me!" is a live, security news game show that pits three security experts (Josh Corman, Chris Eng and Matt Tesauro) against each other in a game of wits. Host Mark Miller, selects topics from the week's security news, posing the news items as limericks, fill-in-the-blank, and audience participation questions. The panel competes against each other, and the audience, for speed and accuracy when answering the questions. During the AppSec USA 2013 Conference, this was a rollicking, high spirited session, exposing the prevalence of security issues highlighted in the main stream news. It demonstrates how hard it is to keep up to date with security updates, even for the experts. Audience members should come prepared as we test their knowledge against the panel, trying to determine what is real news and what is fake. This is a fun filled session where panelists and audience members compete for prizes from the OWASP store. It is sure to put you in a good mood for the rest of the conference.

Citation preview

Wait, wait! Don’t pwn me!

June 2014 Security News Headlines Q&A game

Mark Miller Chris Eng

Joshua Corman Matt Tesauro

ONLINE NEWS RESOURCES

Hacker NewsCSOCNNars technicaThe VergeThreat PostNetworkWorldSANS

Brian KrebsPandodailyForbesTeslaFBI.govStar TribuneErrata Security

THE RULESEach correct answer to the initial question is worth 3 pointsA wrong answer subtracts 2 pointsA pass on the question loses 1 pointIf a question is answered incorrectly, the second response is worth 1 pointA correct answer from an audience member gets allocated 2 points to panelist of choice

The moderator may arbitrarily give or take away points at any time

SCORE KEEPER: WE NEED A VOLUNTEER!

AUDIENCE PARTICIPATION:

WARM UP

Name 2 out of 7 podcast series dedicated to security.

What popular software security company came out with a campaign to “Put a Monster in your Corner”?

What popular software security company came out with a campaign to “Put a Monster in your Corner”?

What movie is reportedly getting rebooted by 'Iron Man 3' director Shane Black?

What movie is reportedly getting rebooted by 'Iron Man 3' director Shane Black?

FOR THE PANEL:

HACKS IN THE NEWS

How were two 9th graders able to gain full system credentials on their local ATM?

How were two 9th graders able to gain full system credentials on their local ATM?

Name 2 of 5 hardware companies that had confirmed XSS vulnerabilities within the past month.

Name 2 of 5 hardware companies that had confirmed XSS vulnerabilities within the past month.

The largest DDoS attack in history hit what site in Hong Kong last week?

The largest DDoS attack in history hit what site in Hong Kong last week?

A flaw has been discovered in the motherboards manufactured by the server manufacturer Supermicro. What was the flaw?

A flaw has been discovered in the motherboards manufactured by the server manufacturer Supermicro. What was the flaw?

Columbia University researchers developed a tool they called PlayDrone that indexed and analyzed what?

Columbia University researchers developed a tool they called PlayDrone that indexed and analyzed what?

FOR EXPERTS ONLY

Millions of LinkedIn users were at risk with what common attack method two weeks ago?

Millions of LinkedIn users were at risk with what common attack method two weeks ago?

A recently discovered trojan app encrypts files on what type of devices and asks for ransom?

A recently discovered trojan app encrypts files on what type of devices and asks for ransom?

A new, powerful banking malware called Dyreza has emerged. What type of attack does it use?

A new, powerful banking malware called Dyreza has emerged. What type of attack does it use?

Zeus has a new competitor when it comes to banking malware. Who is it?

Zeus has a new competitor when it comes to banking malware. Who is it?

A loophole in what company’s payment system allows anyone to double their money endlessly?

A loophole in what company’s payment system allows anyone to double their money endlessly?

AUDIENCE PARTICIPATION:

IN THE NEWS

Elon Musk did something unheard of in modern business. What was it?

Elon Musk did something unheard of in modern business. What was it?

Who was found not guilty in the phone hacking trial in the News of the World case?

Who was found not guilty in the phone hacking trial in the News of the World case?

4 of the FBI’s top 10 cybercriminals are from which country?

4 of the FBI’s top 10 cybercriminals are from which country?

REALLY? THAT’S UNBELIEVABLE!

A new phishing campaign says it has a tool to remove what vulnerability from your desktop computer?

A new phishing campaign says it has a tool to remove what vulnerability from your desktop computer?

Why did Germany recently drop prosecution of the NSA?

Why did Germany recently drop prosecution of the NSA?

According to researcher Robert Graham, of 600K servers scanned, how many are still vulnerable to HeartBleed?

According to researcher Robert Graham, of 600K servers scanned, how many are still vulnerable to HeartBleed?

THE BUSINESS SIDE

What restaurant chain has had a credit card breach since Sept 2013?

What restaurant chain has had a credit card breach since Sept 2013?

What is E. Snowden’s former employer developing to help the government track you?

What is E. Snowden’s former employer developing to help the government track you?

What company was recently put out of business after a major hack of their AWS account?

What company was recently put out of business after a major hack of their AWS account?

On June 11, Target shareholders decided to do what with 7 of 10 board members?

On June 11, Target shareholders decided to do what with 7 of 10 board members?

In baffling move, TrueCrypt open-source crypto project decided to what?

In baffling move, TrueCrypt open-source crypto project decided to what?

Researchers found large global botnet of infected systems. What type of systems were they?

Researchers found large global botnet of infected systems. What type of systems were they?

What accounts for 98 percent of worldwide Google Play revenue?

What accounts for 98 percent of worldwide Google Play revenue?

EVERYONE:

FINAL ROUND: LIGHTNING ROUND

Feedly and Evernote went down from DDoS attacks. What did the attackers want?

Feedly and Evernote went down from DDoS attacks. What did the attackers want?

Name 2 of 5 companies that were held for ransom recently, with the attackers demanding to be paid in BitCoin.

Name 2 of 5 companies that were held for ransom recently, with the attackers demanding to be paid in BitCoin.

Vimeo, Mailchimp, Shutterstock, Feedly, Evernote

Robert Scoble called it “the stupidest, most addictive app I’ve ever seen in my life.”

Robert Scoble called it “the stupidest, most addictive app I’ve ever seen in my life.”

What is the most pirated show in history?

What is the most pirated show in history?

“Red Button Flaw” exposes major vulnerability in millions of what?

“Red Button Flaw” exposes major vulnerability in millions of what?

According to Network World, what is the next “circle of hell” for the security community?

According to Network World, what is the next “circle of hell” for the security community?

Within 10%, what percentage of security attacks are the result of human error?

Within 10%, what percentage of security attacks are the result of human error?

According to the NSA, how loud was Edward Snowden’s whistle?

According to the NSA, how loud was Edward Snowden’s whistle?

What European country is used as the NSA’s largest listening post?

What European country is used as the NSA’s largest listening post?

Why were 5 security apps recently booted from Google Play and Amazon?

Why were 5 security apps recently booted from Google Play and Amazon?

Google shuts down malicious 'Google Play Stoy' app. What did the app do?

Google shuts down malicious 'Google Play Stoy' app. What did the app do?

A Chinese company making smartphones ships the phones with what specialized software pre-installed?

A Chinese company making smartphones ships the phones with what specialized software pre-installed?

What is the WiFi password for the Brasil World Cup Security Center?

What is the WiFi password for the Brasil World Cup Security Center?

What is the WiFi password for the Brasil World Cup Security Center?

TALLY THE SCORE: WHO WON?

Mark Miller Chris Eng

Joshua Corman Matt Tesauro

Wait, wait! Don’t pwn me!

June 2014 Security News Headlines Q&A game