← All talks

Malware and Exploit Kits: Together Forever?

BSides Peru40:2676 viewsPublished 2017-06Watch on YouTube ↗
About this talk
Malware and Exploit Kits: Together Forever? - Dave Vargas "Exploit kits (EKs) first appeared in 2006 but their initial growth was limited by the high level of technical expertise required to use them. Over time, however, EKs have steadily evolved into easy to use (and important) tools in the growing Crimeware-as-a-Service (CaaS) industry. Due to their effectiveness in delivering many different kinds of malware, Blue Teams should understand them. This presentation will begin by differentiating an exploit from a payload. It will then define the term exploit kit and discuss their most common characteristics, including their management consoles and delivery techniques. To give attendees some perspective, the presentation will examine several famous EKs to explain what makes them so successful. Attendees will then be led through an example EK infection chain, including a discussion of the crucial role that DNS plays in EK effectiveness. The session will close with a discussion of current best practices for protecting against EKs and predictions of what Blue Teams can expect to see from EKs in the future.
Show transcript [en]

Thank You mr. Horner peoplele consultant dat ain't working quite sometimes the speech offense malware in his very time PCC cyber security at several colleges in the Washington DC area the elder graduated magna Laudes for the George Washington University and graduate part and information systems of Johns Hopkins University start certification concluded at CCA yeah I see is without further ado to walk reward [Applause] well we won't give you this word this room was full that was how people that me area alcohol downstairs all right well thank you got any I'm terribly excited I love it it's for the first time last year in fell in love with the city and should tell one of these attentions now come back when I had the

opportunity is very involved at the big city to thank you for having me so or let you know that there's a lot of stuff on this competition because I'm a professor and that's kind of like what we do so if you want to copy the presentation you know email me what you dollars per se not going to do and if there are questions just post them as they arrive really please me in okay alright so I know I don't mention construction work gets up we add to that it violated you can have a sense of humor because I did this hasn't a in Orlando besides Orlando and nobody laughs at my jokes and I was really

offended anybody care about the presentations the fact that nobody laughs at my dot so there's ghosts in there so yeah I've been doing this for over 20 years I get involved if I'm one of those people that my career was chosen by others okay I have no time to anything I did at the start of the military almost actually work with the National Security Agency I was in the Navy and I worked with an admiral Apple said you know I forget where it is you know the entire computer this is a 1986 they know the computing environment was around it you know what computer was but if they're being on set me on and it's been downhill since then all

right so yeah I am a professor of such security at the George Washington University of Chicago University and a full-time professor at City College in Nashville from Columbia College does anybody know those places increment in I love the community college I think it's great I have put it into training of any kind of lucky maybe cryptography Center / - really well and I think the entire intelligence came to the army anybody people use as there are people I look down to San Antonio Texas one of our problem people and having interviewed you know this is before the whole board important thing you different do that in oh yeah I've done a lot of other stuff

those are complete diesel forensics personal I have a super hot sexy mind from what am i this is being paid for because they kid should have to make sure I say that actually told me that and so today we have traffic isn't a fiance after me and I'm a member of obscenity has character and other key Nokia because when you have cyber you can to pray a lot it's not how they wear that know when I started praying anybody ever work with is people doesn't eat those serves tax I remember a pilot or 10:00 at night and trade we've got let this come back up that I want to be from all night so that's how

I started alright so basically we're going to want to talk about exports to charge I found this worthless our security community and by reality mark on that people don't really understand what exploit kids are and they're really you kind of hurting us from us a security perspective and and also we'll talk about the or the lipstick crime where and also ransomware which is becoming very big and so there's going to be all render for today alright so Troy where as a service to becoming a very good thing can you tell me why invoice cyber crime ballooning or whether you don't have a second it's probably on is thank you so much it's awful who's going to jail for this stuff

no one where I'm going to get shocking to me so I mean a good job security broad protector that q1 people grooving if your job motivated make sense I'm hearing enough oh yeah but essentially yeah I mean go anywhere because it's profitable simple as that and you know it's actually even about you know some of these terms like now where is the service some of you have heard of it ransomware data service I mean I'll turn it out I see another way to webinar or why I'm somewhere article under 30 month up I mean I understand it is all over the place and people are going to impact it back and if you can impacted by

ransomware yet yeah I have content that's impacted by I'm not in a very serious way what I'll turn out in a way that I'm talking about prayer I once ran to my started to come popular couple years ago that kept me up enough because coming toward NSA and educating the tower cryptography I knew there wasn't a good solution and I just remember really pointing I hope another like let's get this stuff because they don't edit at all from just encrypting JPEG files and Excel spreadsheets and we're documents after blowing out to mass drives and people including an entire P Drive or a G Drive I mean it would be really really devastating especially since I'm using

them you may pay the ransom and not necessarily get them your money back if that working process rinse and where the service a Venetian honor insurance really it's maybe creating this stuff really not about that in fact that everything about the support cumulative just arrests for Atlanta where you hear about that in Japan they arrested a fourteen-year-old for baiting Rankin we're going to make these 14 years old and so what I think about their ransom are the services are something that could be supported burned out yeah and you're going to see why it should not be illegal to you but typically it's going to be created if we call it a theory atop right you know I

see the hard work of developer create this person is good code and then what I'm going to do I'm not an expert of distribution so I'm going to find someone who's an expert in distribution is distribu that for me and so it's okay it provides away and to the ransom our market without needed technical skills now it almost kind of bothers me where when I hear that on be able to hear about strip games you call them skate now I mean and you don't have some technical ability stuff you want to do this stuff you know to distribute power you know maybe not for the level of the developer because you know a lot of people that

distribution just like awesome aspire to be professional skill set for different why you want to do but you still have to have some technical doing this and have abused at the high level that the developer has so I'm getting a really good example of charges particularly this but this kind of trip speed up the affiliate models and this year this was a semantic on and dark networking services for essentially in this these lines here they're discussing a 70/30 split so you know I'm the ransomware developer other if you know wherever you distribute I'll take 30 percent on me get 70 percent up and continue tactic we should really go in future okay so let's talk talking about exporting payloads as

if people don't understand what they are so exploit is and you look at the Centers for something maybe go to school go Rome or Venice code it takes advantage of volatility sometimes a floor or weakness okay so that's only part of it right all right so that's what this offer applications have the hold on great what but will really want to try to do it to exploit that vulnerability is really execute code okay so exploit once again is the vulnerability but the ultimate goal is to experts are conical code and usually back code we're going to call that payload and what can that pay will be well today looks like you know it right to where three months I'm not presenting

from MarketWatch concession and our same ransomware anybody know who can be done hi I mean guarantee them okay if you remember the early days of malware and I remember just now were these noise or in the numbers of early monies and the midnight you can have a malware that what was supposed you have Bart Simpson not with and told me crazy in well some people remember that yeah I mean it consumed resources but was very very people for every easy to give it up and even early ransomware was easy to get rid of leave to get into that parking fee of Island PC obviously to target rich environment but we got that back scan where we don't even detected

it here is surfing child porn silence is that the FBI warning you know and you know that's kind of a quarterly for repair somewhere because it's not the encrypting page no smells really easy to text you know when it's windows revision when this profile and was gone there's a physical but there's something we're seeing today is more and more sophisticated I'll turn right now I just don't see that opening up and so this table whether it goes to stolen put kind of folder where the defective children or hooky remote access older okay really that's what's really doing a dance and so one of these exploit kids this Christmas work software call abilities to distribute value they typically do

develop and so on some kind of got that market and anybody been on the Tor network right certain rights around on that stuff yeah so um you know white or that wall you know tour provides this anonymity price that they could be because I said to do what they need to do although I think the FBI found to be good it you know really want to find a source of some stuff they're able to do that but to launder stuff is done on the Tor network be sent to create the anonymity next provide and the notice that it's existed since 2006 eighty desk week it so they're not making admit one thing about them is that they come with

these colorful nation okay right and it was very kind of total sexy interesting name and it sort of contra see this but when it is not a study that came out by Palo Alto last year that said the dominant expert if they were seeing as of July 2016 we're between our angler be clear the neutrino manual nucleus that is do those terms calculator you can see them come on headline bill the time so I look at what's in the characters which are pretty desperate kitchen this is an actual screen graph of the black hole exploitation about the people one thing I notice right away why do I keep slender brushing in college because my husband

Amy Amy was the Soviet Union yeah we're community speaking Russian right now what oh yeah that's right so yeah this is definitely suited here but what's beautiful about me that ever have seen a couple of the mansion counselors they're absolutely beautiful but you know they'll he'll show you you know who this excellent expertise of versions of web browsers it'll even coming but country it will tell you what operating system should be more your for bad guys getting maybe in your great products in somewhere immune crates you know managing the top of our system to network you know from the comfort of your home the advantage at console like this so we typically BK you can have a very fancy

management console that's very highly polished and here's our other sample to these interfaces okay they're going to deliver excellence right and the biggest is it'll find out if that system that maybe was take it to some websites okay that is compromised organelles it depends on the attacker whether they're hooking up on some attachment that's in compromise whether that system is going to be vulnerable to that expert or not tender because of many exploits when I started this we that you go to luggage like one website when actually what but it doesn't mean what makes excellent really attractive is that the attackers have a pool of exploits so there I love and I don't know if you notice it on the

back guys okay so you know it ability subset and just one of that people that have a Linux low mass in other words people oh but you're going to go he'll know you know I'll go to this compromised I don't see that a highly polished and certain version and it may not download an excellence at all but invasion originally in Windows 7 okay they Eskimo mobility that we can expose the download Xcode and after we do this is event that decreases the likelihood actually they're being detected they should have done school of uh schools or anything continuing updates in exports is very very aggressive you know when you think about that and impacted by a lot of

crime and then you have to be in the water card I was really unhappy want to cry weeks two weeks ago I was really unhappy we spent a lot of color makes me feel they're applied for all of them and you think if we got the up debate on captions and for the most part we thought we were that was my point or not I have 120,000 as well and it does what their laptops that in a drawer that are only taken out for presentations every couple of months that we have and so yeah I mean you know today truly photos detectives you have to make sure that those systems have been updated but you know when you look at how tellement

tough really poor that experts to be taken advantage of by the bad guys you know whatever it leads part of that they have and wasn't really very long so you know the bad guys are actually military our trip to see bees for minor area or may not hold availability on get what they're pushing out that's where you feedback can anybody get one is what we're doing that what we show even for the traditional for-profit company what are you doing well the contingent fee over it's a way though they've got make you that they thought the best product will compared to competitors it now they may come a technical support okay should be a problem you know that

actually remote into your system and a there's any problems to make things work and they often include license agreements and this one is called areas for me because you know bad guys we can't trust that guy okay it's a suite or the room and on the translates for you what it says here it says the translation in cases of violations of the agreement and being detected the client uses any technical support rural where the binary total robot will be immediately sensing is have our spunky and so no forget they have to protect their remedies so some of our famous expertise that we've seen is dispersals called black that lack of exploitation and encourages him up

name is ponch and I hear God's name oh yeah he was a very very big deal so he was caught and I was encouraged shot Iverson and I on the working us start intelligence company but how do you think going to jail these are Russians in Russia it was June right what we can happen I mean I've got a scary incident right here my fear you know the unwritten rule is Russia is basically Elijah you can have whoever you want just don't tap your fellow Russians and every time and I picked it a lot both of us apostasy went into Russian happiness records because they have internally so my sense if are either reflected and also it's been only

the capitals of collude with Russian government and Russian law enforcement who knows maybe somebody didn't get the payoff they're expecting okay and then this is what happened then we've got this another pony to instill in the Risen air of beauty delivery of still deliverance tables via RLS by talking John Hall very surprised renfa-sama and then um you know ever maybe in a position where you did not see each other organizations yeah I mean at this article and video that's why there's a back you know lapses in the blacks right it's basically some if you can not not need organization show capacity then we have anglers dominated up this spk on Orkut for very long time now notice here

it disappeared into 2015 because there was a rest of fifty work for fifty minutes of this game amused are disputing but look at it they estimated income up to 60,000 a year six minutes we add all our salaries in this room I know I worked insider we do not mix admissible as our your total okay does this give anyone second thoughts about it quickly to decide but she took me all right so come on the Halloween optics so really there to grant the descriptive evening a happy for your sister be compacted by next week get right a person abusers go to visit or more likely is redirected to website is hoping and it's legit and so

you don't necessarily have to attend to doable most effective every bar and some constructs create commercials and early on country adult going to be sacrifice right because there's less than the potential if you're going to get compromised good so all you're gonna do is would go to some optimized website and booster compromised well I know you you're kinda been compromising in there and compromise we almost anyone that's legitimate and we'll see an example of a few legitimate about seconds compliment and then also you have to adderall ability that can be escalation if I go to that top of my choice happens in my bathroom they don't have a map exploit and I'm now going to

be okay or if I multiply the decisions I'm probably going to be oh that's why are they help our signals is thank you so how do they work so there was problem exploits or browser exploits you should find that browser yeah yeah by they're going option surprising right because really what's the application that use me to use the host it's over what that in your end users what's the application of endings of is web browsers right so it's very it's probably right the number one most companies app so why not try to exploit that and notice that is addictive is found to be bundled vulnerability and the kids go to download the payroll process and also an example of that so

you'll notice that I've intimate before it they don't want to be detectives is what happens when will detect then we can do all kinds of blocking and protections against it so when they saw a feel agree but basically query on that computer and they're only go to download the exploit for potato that that just don't stop down below me you know they're they're choosing you know if I got a twenty potential things I can download and I'm going to do I'm going to pick the worst which likely to work on the tribe one-by-one passes and so no not now once they're on your network like and one that device and they can make a great they can do whatever they

want to do and if I was a little toppers doable has all the gold was running in Washington DC we have our government as support governments have supported on for-profit companies right and the motivations are different my guests here in this area that you probably targeted by nation state and please correct me if I'm wrong you're in this mess you know there's lots of opportunity to take a pass by cyber Colonel but I think initiatives members in this area and I see a lot of things I hope rocket well what I mean press on them there's for me yeah I'm using targeted by nation states that like you more to the typical one you just trying on it is

what it is you know we thought after the DC right you know the nature the attack really depends on the goal of crap so let's give an example on compromising start here so this victim is going to visit a compromised website okay is it we don't know how percent unity navigators who directly or maybe they were redirected to that question but it isn't malicious and and then this work there web pages but it's contact from kind of exploit landing page the excellent change is going to find what the best difference is multiple just going to go to look at the characteristics of a visitor let's power and its rules and Spyro levels now notice that it knows all these are

valuable this nothing happens okay you have is 99% or not right oh but your windows eager okay because what's going to happen so send that up certain event don't jumping office all right so since exploit up able to the business okay so this came here determined that this would be appropriate export an Iraqi won't be together and follow that respond that Felipe those but a horrible possible exploits that have is what is really serving the one if you but if the beauty others here that we've got this whole pool of possibility here which makes infection just more like and so let's look at one example of an infection using religious would get and bottom which was a piece of ransomware

that was a pretty famous at the law back prom so this is a look to see if the change next year is injective stripping the page from a Kaka my website will show you this there's going to be other that the day afraid gate comes from the TLB the top-level domain that was being used okay this even against a regex foot kick which is going to redirect you to a download or for walking and then you're going to actually get the locking ransomware stuff and so let's go into the Wireshark decoder disk and you're gonna know here that it has been filtered here this is a display filter on these request pages but what remember

wants is that user actually is going to visit website all things British that there's anybody in there Victor so next okay I've never been to here but to me it seems like something that's which any of your question okay so it seems like the legitimate website this could compromise you know obviously is fun for the mom and pop shop that we can compromise so after they visit this website that has been compromised it's going to redirect them to this site story got opinion on lines up our own what's that are mobile me giving the regardless of Romania shocker okay then after there okay there's now we don't know where this one is requesting or could be in another

country going to go to our unknown target calm and this is absolutely excellent itself okay and now here they send us to this cycle just currencies about give you the download to download walkie wait or happy or that resist so how many dozen okay thanks okay what requires for this to work you know really what we require for this is that we need these sexy you know specifically you need that meaning that's compromised site this is a call me the hardest one to do on the top of my site is given at home all right now so when you look at the indicators up in the Catholic traffic this is what you're going to see

vitally with a whole bunch of them on I have to delete for the moment is our space issues but I do want to bring your attention to UM therapy and s clearly therapy has great therapy is blue okay income honest take it out good thing it is happening in Europe a blue Timur right washing on lots of filthy and s queries and everyone regretting our image often you are out here so you know Russia okay this is tolling and you know this is good information to have well contains perspectives unsubscribe defend yourself so there's nothing you want to try to block these kinds of debated if you can if you do that at the natural place

now the next screen Brown is going to show you who the injected script and here we go so this is what is the injection script here and your lips I'm sorry Michael laughing okay and you'll see here what's being used to a Decker scripted Avery's Peter Thomas with the darkness book right uh can we block that I mean you can block jobs 50 organizations Connecticut block stripping in organization okay everybody find that really interesting how he wound to all this active content and all these scripts on on the on the inner on the web because that's what users want but really aren't being introducing both of them ability to be happening and you just mind one is what

make it up if we could were stripping around forever and what would be the impact of that I don't wonder if I were to I mean I had great Michael my users change the password than she had for 20 years propagated they've got one of my customers are serious work the policy would not to change passwords and they got now and I got a do this I don't care what they think and I really I thought up convicted people were finding me and I was coming down the hall because I had that passion for 20 user and I need to change and really that the kind of reactions I would actually step again someone I'm so

Kara done you're not going to get worked on the websites designed to function with that stuff okay and it appears being redirected so it's been a URL to description with this iPhone that's one student became landing page things and then on this page here will then take you this version of a vehicle talked about I'm not asking parity now we don't know what that little half you know when I see stuff that doesn't make sense I think occupation but nobody really determine that and then we've sent a flash exploit vehicle of the other things that need to be considered off the side scripting and Java and then up next the script here relaxing other expertise actually export okay which is

not really encryption but in the form of obfuscation that but okay yes I mean here's to find a people diversion do want to could you do confiscation to protect against what any kind of network-based intrusion detection team that might be able detect it anything locally under then after we've spent a lot to download the download graph locking itself and and what did the trees blocking been decrees going to have to be impossible for despot those of that so now let's look at the next side the top of the next site these two types of particulars find abuse calm and pro prepare calm but DNS queries for laughing they're doing digital once again in this filter it's doing the

queries for these URL like you see here and you see in here and then for find are less calm notice it didn't work for chrome contain right so guess what no response can't go this will see it's going to try another son so it's really because a pralaya having many many compromised site to be able gamble to subject so there's a query for part idealist that returns this empty address and it's from this site here by desist calm that obviously could be own zip economize that after the retrieval of the downloads blocky demography other queries for these funky URL either call back the reins or right to the cannon commands whole control infrastructure is one of them work but

guess what you know Monica work is business about what answer one okay so notice in this example here this example here the files and support things were encrypted they were given that OPI an extension and that's how they felt encrypted and that's why we call this open version box box so you know as I've been doing this more MORE how do we connect that with a great way of protecting our self-describing pieces of knowledge from DNS okay because you know doing attacker is using domain names they need to get resolved and I think you need to be looking at you know Sarafian s queries on to that protect your network so how are you gonna

protect it is resize it all Osprey is in any matter I mean how many of you feel comfortable that they're doing a great job second is now you know we look at hosting solutions I know there's some bad system that are you know that segregation is for someone partly like a metal face delicious other customers will get to like umbrella open DN a-- f king dramatic improvements in malware as a deafening dramatic filter boxes elbows powerful just by not being English background uh I don't see how we put there but it'll knock down with really real one here that's what I mean you sort of infectious he has been here in drastic end up it depends on how the

neck is being delivered or it depends really a changeling PDF file who's going to have to back yeah if there's an end of the wizard fundamentalism okay so um so you know whether it be mostly system to be exploited in the custom for the type of also is being exploited of the product versions that are being targeted at patentability a piece of the necessary application techniques with your eye on Scooby backer which worked as well you know levels of against them the quorum we never feel really very Celtic I mean a beautiful destination state after other unique concerns and if you're going to have to replace the 14 year old Japan you know might be able to

lessen Germans what they can save our school gave up they have a situation and amount of time required to build a reliable okay so you know when we look at our protection is this typical despair and death stuff I mean really and you know we have to make sure are we doing this stuff well I have some clients in our native have managed it very well although I said wanted by I was your field working 12 14 hour days and if you are laptops or absorb more passionately anti-virus you know we don't look at the efficacy of empirical signature based and devices but concessional have aliens of our race and have people say you're the second

decision in fact our reading article which the biggest said you don't mean the end in our percent just keep the systems fully patched so babies I kind of understood the logic on that because well in the most catches some low-hanging foods to contribute and about you still need it in fact anymore because of sex right you know I PS functionality that's a host-based firewall oh so they are working with the entire web technologies is still kind of early definitely on newest versions of applications of the prominent in modern environment we can't always run the latest version of things because if we do it British enterprise app is anybody in that situation yeah I know what I'm talking about yeah

I don't remember gets like everybody's old versions of IP because you know we can't upgrade even we're going to guess what they can't get the hrf or the Accounts Payable app is not gonna function any more so you know I tend not to beat up people who forgotten today's round of applications because there's a reality just use it as a reason for that then I need to go home call idea about walking software if you want see how painful blocking software is under scripting scripts use no script plugin for Firefox intended use that yeah use motion on Firefox and having to block everything and against be out April it should be about two minutes to turn that

and a really find it interesting that it's easy for browser I remember using the tor browser will run strippers on by default now I can download my squares at or ecology he'll fit those with the same in both at the on time interesting okay there you go Oh Stephanie for uh you know happy perimeter defenses and I said identical reports I really enjoyed BNSF jumpy another identical it secreted service now you know that we can prevent this stuff from getting on your network in the first place oh I'm a big proponent of outsourcing well not because one event job but I found that you know even if I compute my homework there something I want expertise on stuff so I want being

able to get a job to someone who does that except in a 24/7 I think they can do a better job than I can but a really convinced that these services of other you don't have dying and that's on there they provide the service students when they're not being DDOT unemployed botnet or so I'm gonna happen but yeah I really think that you get really the best night we were talking protection when you look at including security as a service as fertilization and then end-user training you know you know we report to training all the time I spoke said to click on things they shouldn't I've done you here uh used to send me pictures of stuff that they were

suspicious I think that's pretty cool because you exactly the data today pea-pickin will be posted vicious now maybe a contractor is awesome pretty quickly by just a photo that's a SME one level a local art so these things exploit kids are going to grow on time are now they're going to realize in require a less routine relatively inexpensive often a financial splinter I thought about that silly Paula that's very appealing to the distributor that surgical integrator they're very flexible they can deliver many different types of matter today just happens to be man to market to that easiest ways to monetize your investment and yours right but if you're in nation states I don't see nations big great other than

North Korean licenses think they want to finer things up what a crime to be attributed to run through anybody's we want o to interesting okay so yeah apparently me who's the right action for people article to deliver but it could be almost anything a very good at avoiding detection because they're using the latest expert that you're claiming constantly being updated and abundant if you want to buy defies you can buy if you want to read up as possible and come with technical support and normalize it just so many targets done okay you know what Windows computers are still over ninety something percent of the market ranks or the club so we density eight drops and export activity this year for

a couple reasons and we have some arrests that went on but guess what that just means that the guys who are doing it to just laying low and just laying low to the attention is turned to something else and guess what they're going to continue so I see here the author's are kind of downside and gun fever they're still doing some development of surprise people people that they hope you know that month you know we're looking at the government its movie reputation based like to just it's not going to make you design a polo shirt that you have to get to know someone so they found resources and Department will do product development with people they know they know

interstate and small and campaign and they're looking in other delivery mechanisms like you doesn't be a macros remember one is not o'clock how old is that you're living an amazing that this sucks just keep sucking back so my prediction is that we're going to continue to see cyber crime using these tools for the foreseeable future you know why internet global so I can happen from you know Seoul Korea up in Washington DC with the posted impunity if you notice an anonymity that goes with that also the enemy provided by crypto currencies okay um we thought these mixers anybody have Bitcoin Bitcoin you stick one yet oh yeah it's very difficult if you're paying to be a Bitcoin so can we figure

out who that person is on them up in that world life because of the development of mixing services and the supply of these exploitable target and that include up guy as anybody here ever conservative then you're going to have malware and we have malice and to shame to existing internet because it should be under percent guy yeah I do this do this for watching beyond the percent but that includes us and one of the existing could be an ass for so good I mean there's like us coming phishing email that I want to go into that fmpp header feels like networks real unsightly for both in goes in essence Pierre I will notice that the first server is

the little phones an idiot would never invent so I'm 10 months of playing people get effective it's not their fault you know the attackers are very clever optimal clever than just low props probably will give a low conjuring up Patrick and propagation we think about this getting caught is erectus I mean you know you can count us maybe one hand in from the last couple years so pretty lucrative and as their continued life of a bidding programs such as s particular service and you're gonna bond is is one of money to be baby either going to be just make sure you out of that with a lot of money and so gold is a lot of money on is going to continue

so looking over our continuing to adapt like most bad guy to right I don't know in law enforcement energy and work in law enforcement no one would you know you have a typical worker person the bad guy girl always I had a law enforcement would you agree and everything came from this bad guys are always ahead of us we're always very reactive right I mean how often do we get to be through a lot because that's one be tools a hosting a I can help with that and it's going to be very difficult to please you know notice even when its creators arrested the code is still out there and will be be used I mean had several infants history of

hope you read it one thing is whatever displacement quarkxpress Stuxnet classified malware right it is bad guys out Holden actually tried to be deployed two times any questions yes sir no but I have thought it to be my wife Africa types of people's living interested interesting CEOs for Jamal so not me right now but we've actually snapped out after the swim past notice what the facts that were addicted to a career visually climate Wow it was God with a billion dollars and I can only by the way was like a million or something we got another number okay I think because of to everything yeah yes you could be looks like it's liver halo spectator to the user could

you down to the system itself yeah they need to cook up the day together good idea mmm any other recommendations for the ABS all right well thank you grabbing anything okay [Applause] [Music] [Applause]

[ feedback ]