--- title: "Georgia Weidman — Mobile, IoT, and Pen Testing" url: https://appsecpodcast.com/georgia-weidman-mobile-iot-and-pen-testing/ date: 2019-03-31 duration_seconds: 1134 guests: ["Georgia Weidman"] topics: ["Security Testing"] audio: https://www.buzzsprout.com/1730684/episodes/8122652-georgia-weidman-mobile-iot-and-pen-testing.mp3 transcript: true --- # Georgia Weidman — Mobile, IoT, and Pen Testing *March 31, 2019 · 19 min* with [Georgia Weidman](https://appsecpodcast.com/guests/georgia-weidman/) on [Security Testing](https://appsecpodcast.com/topics/security-testing/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122652-georgia-weidman-mobile-iot-and-pen-testing.mp3) ## Show notes A secure mobile application can still sit on a compromised device or depend on an insecure cloud service. Penetration tester and author Georgia Weidman joins Robert at CodeMash to explain why enterprise mobile and IoT security requires a wider view. She describes phishing through mobile channels, a QR-code demonstration that delivered a modified restaurant app, and the infrastructure behind connected devices. Georgia also discusses testing the protections vendors promise, learning the fundamentals through her book Penetration Testing, and the business lessons that came with becoming an entrepreneur. Her path from mathematics to security provides the backdrop for a practical conversation about examining the whole environment and understanding what an attacker can actually reach, rather than stopping at an individual app. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey provides application security education for developers and everyone in the software development lifecycle. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Georgia Weidman: → [Georgia Weidman on LinkedIn](https://www.linkedin.com/in/georgiaweidman/) Mentioned in this episode: → [Penetration Testing: A Hands-On Introduction to Hacking](https://nostarch.com/pentesting) → [CodeMash](https://codemash.org/) Chapters: 00:00 Mobile and IoT security with Georgia Weidman 02:09 From mathematics to security 03:33 The competition that sparked an interest in hacking 05:28 Mobile and IoT in the enterprise 06:37 Why mobile phishing matters 07:45 A QR code and a modified restaurant app 08:43 Looking beyond the app to the whole device 10:10 Testing mobile security products and controls 11:39 Learning with Penetration Testing 13:43 Building a company and understanding business risk 17:04 Conferences and international readers ## Transcript *3,416 words · assemblyai* **0:01 Chris Romeo:** Hey folks, we are back with the Application Security Podcast Season 5, and we've already got a number of exciting episodes in the queue ready to release for you over the next number of weeks. This is Chris Romeo, CEO of Security Journey and one of the co-hosts here of the Application Security Podcast. And so with Episode 1 of Season 5, Robert, one of the other co-hosts, had a chance to catch up with Georgia Weidman at the CodeMash conference. Georgia shares her security origin story and also discusses the talk she did at CodeMash on mobile security and IoT, and gives us an update on some of the other ventures she has going on, like some different companies she's involved with, and an update on her pen testing book that's been very popular in the industry. So, after a word from our sponsor, you'll hear the interview with Georgia Weidman. This episode of the Application Security Podcast is brought to you by Security Journey. Security Journey has a new weekly publication called Hi5, 5 security articles that are worth your time. We scour the internet looking for the best articles on application and product security. We add in just a touch of sarcasm and snark in our descriptions. Just what security people and developers love. To sign up, visit www.securityjourney.com/high5. That's /hi, the number 5. The Application Security Podcast. Here we go. **2:02 Robert Hurlbut:** Hello folks, this is Robert and I am at CodeMash and I'm here with Georgia Weidman. **2:08 Georgia Weidman:** Hi. **2:09 Robert Hurlbut:** And welcome, Georgia. So Georgia, you're speaking here at CodeMash and I'm curious to know what we do typically when we talk to people is ask, first of all, what's your security origin story? **2:22 Georgia Weidman:** Well, my PR people don't like me to tell it because it's not a very PC one, but they haven't come up with a better one yet, so here it is. So I was going to school for math originally, like building bombs kind of math, I guess. Well, theoretical math. But then I realized I didn't really want to be a math professor, and I wasn't Einstein, so really I was going to be teaching calculus to undergrads for the rest of my life. So my mom had a PhD in computer science, so figured I'd go do the computer science thing. So I did that, and they had this cyber defense club, and the captain of the cyber defense club was so hot, so hot. He's married to the same girl he was with then, so that did not work out so well for me. But I did find, I guess you could say, my calling. We did the Collegiate Cyber Defense Competition, so I did that for my 2 years of grad school. My second year, I was the captain of the team, and, you know, I made great contacts. And then after that, I came back and I was, you know, a student— or not a student, but a volunteer red team member after I graduated. So, you know, that's how I found my calling, I guess. **3:33 Robert Hurlbut:** Wow, very cool. And so you started out in math and then you got interested in computers and security and so forth, but what really sparked— I mean, was there some interesting things that just grabbed your attention? **3:46 Georgia Weidman:** Well, it was— I definitely did not want to do computers because my mom did it and I had that, you know, You know, she taught me how to program when I was like 3. There's like, you know, pictures of me playing Tetris when I'm like not yet able to walk. But I did not want to do computers as a career despite enjoying them, just because, you know, the typical teenage rebellion thing. I was like, no, I'm not doing that. But when I was, you know, back in computers and doing the Collegiate Cyber Defense Competition, the red team, which for people who aren't familiar with the competition, it's the students, they are the defensive side, which kind of sucks. It's hard. **4:20 Chris Romeo:** Yeah. **4:21 Georgia Weidman:** You gotta keep all the systems up and you gotta— they're actively under attack by the red team, which are volunteers. And one of the red team members actually, like, it's not like it's hard to break into these boxes. We're talking like missing basic patches and things. So it's not rocket science. But, you know, he got in and I guess he put like nuclear rat on it or something or poison ivy or some— something like that. And he had it like put up. Oh, that's awesome. pop-up windows that said, I like turtles, and I could click out of them, but they just kept coming back. And I was just like, how is he doing this? I want to know. So I guess I just knew that I wanted to be able to do that. **4:58 Robert Hurlbut:** Oh, wow. Yeah, I can relate. I can remember my career being development, but I also started in math as well. But just seeing— when I saw people do certain things, that's exactly me. I wanted to do that too. I want to figure out how to do that. **5:12 Georgia Weidman:** Right. And in hindsight, it wasn't even remotely impressive because it's like, You know, you just put somebody else's remote administration tool on there and then click a button that says put up popup. It's not even hard. But to me in my, like, nascent, not knowing anything about hacking yet, it was just the coolest thing ever. **5:28 Robert Hurlbut:** Wow, yes. So here at the conference, you spoke on mobile security as well as some IoT security. So tell us about your talk. **5:38 Georgia Weidman:** So really I speak about mobile and IoT security in the enterprise and really just Problems in enterprise security these days, I really kind of see like mobility and IoT coming into the enterprise and us using cloud and bring your own device and all that. I mean, they're all kind of falling into the same category of stuff that we can't control as the security department or the IT department. You know, they bring their own issues and what we're doing now in terms of putting preventative solutions on top of them to try to solve these problems is falling short and how we need to be, one, bringing those devices into our security program better in terms of monitoring and penetration testing and simulation, but also, you know, figuring out what we need in terms of those preventative solutions, not just— I don't think the vendor that has the biggest marketing budget should be winning. I just don't. I think the people who are actually solving our problems should be winning. Yeah. **6:37 Robert Hurlbut:** And so, what do you see as some of the major issues right now with mobile, let's say mobile security in particular? What are some of the major issues? **6:45 Georgia Weidman:** Well, I think the biggest thing is probably phishing, and that's surprising, I think, maybe to hear me say that because I guess I have a long history of saying that phishing is like what hackers who can't hack do. Like, you can't write a buffer overflow, so you'll phish somebody. You know, as I've matured and the industry has matured around me, it's— that's the way even the people with the zero days, you know, it's very rare that you don't have some sort of phishing component of just getting someone to open a link even or download an application. So, there's definitely a phishing component, and we certainly haven't solved the phishing on emails. And there's all these different new ways that people can be phished. You know, you can have them scan a QR code. **7:29 Robert Hurlbut:** Yeah. **7:30 Georgia Weidman:** text message, social media. I mean, all those social medias have messenger functions where they can put links in them. So there's so many different ways that people can be attacked via phishing, and I think that's going to continue to be a really, really big one. **7:45 Robert Hurlbut:** Wow. Yeah, I like the example you gave in the talk on the QR code, and you mentioned something about at a company you just put one of those things on the wall along with some information that a Somebody who's an employee would look at it and say, oh, that looks fine, no problem, let me just scan it. **8:01 Georgia Weidman:** Yeah, so what it was, it was in their break room, and we did do a QR code that called back to me and served them an app. It was the actual app of the restaurant that had been broken apart, added some extra to, you know, let me control the device, and, you know, put it on a little poster board that said, you know, download this app and, you know, next time you go you'll get like $5 discount or something, which, you know, it was, it was a reference pilot for my product, so I can tell you about all this. So yeah, I'm not giving away any corporate secrets, but yeah, it was pretty cool. It worked pretty well. **8:43 Robert Hurlbut:** Yeah, but again, it's just interesting to see how that works well. What are some other things that we need to be aware of in terms of mobile security that are issues today? **8:53 Georgia Weidman:** I think, particularly since we're at a developer conference, I think people, myself included, tend to get bogged down in terms of, you know, making what they build secure and not really thinking about the bigger picture. Like, you can build, like, a super secure app, but if, like, the device that it's on is compromised, like ring-zero level, you know, good luck. **9:19 Robert Hurlbut:** Mm-hmm. **9:20 Georgia Weidman:** And I think, you know, people are not taking that into account. And I think, you know, it is really big right now, mobile app security, but what's really being missed, I think, and perhaps is making a resurgence with things like mobile threat defense, is that, you know, it's really a whole device. And not even just whole device, but, you know, as the picture that I showed in one of the slides, that, you know, for every device there's, you know, a backup server, an update server, this server, all these other servers out in the cloud that, you know, they're just Linux boxes that might have EternalBlue. Well, Linux boxes don't have EternalBlue, but you know what I mean. **9:53 Chris Romeo:** Mm-hmm. **9:53 Georgia Weidman:** They have some vulnerability that somebody forgot to patch out there. And, you know, I think we're not really thinking of it in terms of big picture. We're thinking of it in terms of, here's my app, I'm keeping it secure. But, you know, if we're in this zero-trust environment, which we must assume that we are, We're going to have to do a lot better. **10:10 Robert Hurlbut:** Right, right. And so you mentioned we're at the developer conference. What are some things developers, other things that maybe developers can think about or tools that they can use that you might recommend? **10:21 Georgia Weidman:** Well, if you want to get a handle on the state of mobility and IoT in your enterprise, or if you happen to be building a security product for mobile or IoT, or if you're in the business of trying to figure out what you should buy, you know, for mobile and IoT security, because there's vendor booths galore for, I can save your devices from everything, at any show. I don't know, I haven't seen the vendors here yet, but pretty much, we can solve all your security problems with just a blinky light box. You know, I would suggest you check out my product, which we do have a free version. It's a Shevirah, S-H-E-V-I-R-A-H. I really should have come up with a name that I could spell or say, but really that's what we do is, you know, penetration testing of devices, penetration testing of, you know, the whole architecture around the devices. And we do mobile phishing certainly because that's a big part of it, and helping people understand, you know, what their mobile security problems are and what, if any, products that are out there on the preventative side, enterprise mobility management, all those buzzwords, can help them fix their problems. **11:39 Robert Hurlbut:** Okay, good, good. And then, so they've got that, what about any books or other training or things? I know you've written a book. **11:47 Georgia Weidman:** I have written a book. It's called Penetration Testing: A Hands-On Introduction to Hacking. I am currently working on the second edition. You know, like most things, it's— with deadlines, it's an imaginary line that recedes as you approach it, the horizon. But I am hoping to get that out maybe by, you know, the summer conferences. We'll see. Hopefully. The problem is I want it to be really good. I want it to be twice as good as the original one was, and the first one got so much good attention. **12:18 Robert Hurlbut:** Yeah, I enjoyed it. **12:19 Georgia Weidman:** So many people liked it that I really want this one to be just that much better. **12:23 Robert Hurlbut:** So yeah, what I remember in looking at it was very hands-on, just help you, somebody who's not knowing much, be able to get from almost point zero to somewhere else. And so I thought it was really good. **12:34 Georgia Weidman:** Yeah, that's really the goal, to know requirements ahead of time. It helps you set up a lab though. For this one, you're also gonna have an online option. You know, as time has passed, it's easier to get things up online now, so there'll be an online lab. So if you don't want to set up your own lab, you can just you know, hook up to that, um, as well as, you know, there'll be additional exercises after you finish. So try and, you know, make it more of a— more of an enterprise in and of itself. But yeah, it's, it's definitely coming. But, uh, Book 1 is still completely something that people are getting stuff out of, especially if you, uh, want to get into pen testing for the first time or trying to do something like OSCP, the certification. Um, the book that's out there now is still completely relevant. That's the great thing about pen testing. It's all about stuff, missing patches and bad passwords and things like that. So yeah, there's technology moving forward, but it's still the same concept, so it doesn't really go out of date. **13:29 Robert Hurlbut:** Right, so learning the concepts are going to pay a big dividend. I mean, like you said, the technology is changing, there's updates, there's all kinds of things coming out, but learning the basics, learning those kinds of things are going to pay dividends over the long run. **13:42 Georgia Weidman:** Definitely, yeah. **13:43 Robert Hurlbut:** Okay, good. So What other things are going on for you? Other conferences, other kinds of new ventures? I know you started a company. **13:51 Georgia Weidman:** Yeah. **13:51 Robert Hurlbut:** What are some other things going on? **13:53 Georgia Weidman:** So I have Shavira that I mentioned where we do the mobile testing software. So that's a product company. So I am a venture-funded entrepreneur, which is wild and crazy, and I'm learning so much about so many things I knew nothing about. Part of the deal was that, you know, I came right out of school into security and started going to places like DEF CON and Black Hat where it was like security, security all the time. And then now I'm really having to understand like business. **14:22 Robert Hurlbut:** Mm-hmm. **14:22 Georgia Weidman:** And I probably should have figured all that stuff out a long time ago as I was doing like penetration testing engagements for businesses. But no, I really don't think I ever understood it until I was a business owner myself. And it's like, no, we can't spend money on security or else the the lights will go off. Um, so yeah, and I still— I also still have my small business, uh, Bulb Security, where I do, uh, my, my book writing and my pen testing and, you know, more of the like vanilla flavor kind of things as opposed to, you know, the mobile security products. Um, gonna do a few more conferences this year. I'm probably not going to do as many as I have, um, in the past. Try again, trying to grow the business, make some good partnerships, things like that. I've got some good consulting clients that want a lot of my time as well. So, you know, they're going to give me money. I'm also— I am a— to make it go full circle, I am a professor at University of Maryland University College as well as I just started writing a course for Tulane University and their new security program. So lots of different stuff going on in my life. And I, and I wrote a blog post. I totally put out a blog post like earlier this week, which I haven't done in forever. And maybe I'll even do a podcast. I don't know. And then like it was a while ago, right? But I did this pilot. It was going to be for the History Channel. It's like we had to audition and stuff for the History Channel. It was going to be like, you know, Duck Dynasty, except, you know, hackers. **15:55 Robert Hurlbut:** Yeah. **15:55 Georgia Weidman:** I guess. **15:56 Chris Romeo:** No way. **15:57 Georgia Weidman:** But the History Channel passed. But the other day I was thinking about it because before I started doing security talks, I actually really would just shoot like— they were called Clueless Loser for Clueless User training videos. They were supposed to be like really ridiculous, like security awareness training videos, like absolutely ridiculous. They're still online. I mean, the quality is pretty terrible. This was literally just me shooting on my camera. This was before the iPhone. The iPhone makes pretty pictures now, but you know, I was shooting this like on a tape. And I'm like, well, so what if the History Channel doesn't want my show? I should just make my own show. This is why I have no time and nothing ever gets done. But yeah, who knows what's coming with me. But definitely book 2, definitely, you know, moving forward with the security product company. I have like 12 meetings next week with, you know, big important companies to partner with. And who knows, maybe, maybe one of them will buy me someday. **16:52 Robert Hurlbut:** Yeah. **16:53 Georgia Weidman:** And, you know, just getting more consulting work, and I don't know what comes my way beyond that. Okay. **17:04 Robert Hurlbut:** All right. Well, we'll look forward to seeing, you know, more things, new things, seeing you at different conferences. What's next on the conference circuit? **17:10 Georgia Weidman:** I think I'm going back to Brazil. They have a group of conferences in Brazil called RoadSec, and my book was translated into Portuguese. So I have no idea what they're saying to me, but they, they seem to think I'm cool because I wrote that book. Apparently they don't get very many books in their native tongue there. Well, very many security books, I should say. There's plenty of books in Portuguese. But, uh, so I think sometime, I think April or May, I'm going back down there. But it's like they, they have them all over. They have like regional ones, so I'm getting to see like different places. Like, I went to Salvador, Brazil last year, as well as São Paulo, and it's like, you know, São Paulo is a big place, but Salvador was more like old colonial town. It was like, this is real cool. So I'm not— haven't entirely figured out which place I'm going to, but I'm sure it will be very pretty because I, I picked them based on how pretty and historical they are. **18:08 Robert Hurlbut:** Good idea. Okay, well, Georgia, thank you again for joining us. We really appreciate the opportunity to talk to you, listen about what's going on about obviously web and IoT security, helping people to understand what they need to think about as well. **18:24 Georgia Weidman:** Thank you again. Thank you for having me. Thanks for listening to the Application Security Podcast. If you enjoy the podcast, please do us a favor and visit the iTunes Store and give us a 5-star rating. Our intro music is 8-Bit Kung Fu by Born and TJ. And the outro is Southern Delight by Stefan Cartenberg. You can find us on Twitter @AppSecPodcast or on the web at www.appsecpodcast.org. --- Source: https://appsecpodcast.com/georgia-weidman-mobile-iot-and-pen-testing/