|
Jake Kouns and Carsten Eiram - Screw Becoming A Pentester - When I Grow Up I Want To Be A Bug Bounty Hunter!
-
www.defcon.org
-
11 years ago
-
eng
Screw Becoming A Pentester - When I Grow Up I Want To Be A Bug Bounty Hunter! Jake Kouns CISO, RISK BASED SECURITY Carsten Eiram CHIEF RESEARCH OFFICER, RISK BASED SECURITY Everywhere you turn it seems that companies are having serious problems with security, and they desperately need help. Getting into information security provides an incredible career path with what appears to be no end in sight. There are so many disciplines that y....
|
|
Kyle Kelley and Greg Anderson - Is This Your Pipe? Hijacking the Build Pipeline.
-
www.defcon.org
-
11 years ago
-
eng
Is This Your Pipe? Hijacking the Build Pipeline. Kyle Kelley DEVELOPER SUPPORT ENGINEER, RACKSPACE Greg Anderson SOFTWARE SECURITY ENGINEER,RACKSPACE As developers of the web, we rely on tools to automate building code, run tests, and even deploy services. What happens when we're too trusting of CI/CD pipelines? Credentials get exposed, hijacked, and re-purposed. We'll talk about how often and what happens when people leak public clou....
|
|
Ryan Kazanciyan and Matt Hastings, Investigating PowerShell Attacks
-
www.defcon.org
-
11 years ago
-
eng
Investigating PowerShell Attacks Ryan Kazanciyan TECHNICAL DIRECTOR, MANDIANT Matt Hastings CONSULTANT, MANDIANT Over the past two years, we've seen targeted attackers increasingly utilize PowerShell to conduct command-and-control in compromised Windows environments. If your organization is running Windows 7 or Server 2008 R2, you've got PowerShell 2.0 installed (and on Server 2012, remoting is enabled by default!). This has created a....
|
|
Anch - The Monkey in the Middle: A pentesters guide to playing in traffic.
-
www.defcon.org
-
11 years ago
-
eng
The Monkey in the Middle: A pentesters guide to playing in traffic. Anch (MIKE GUTHRIE) Prank your friends, collect session information and passwords, edit traffic as it goes by.. become the Monkey(man)-In-The-Middle and do it all… This presentation will teach you a penetration testers view of man in the middle (MITM) attacks. It will introduce the tools, techniques and methods to get traffic to your hosts. Demonstrations of the tools....
|
NSA Playset: PCIe Joe FitzPatrick HARDWARE SECURITY RESOURCES, LLC Miles Crabill SECURITY RESEARCHER Hardware hacks tend to focus on low-speed (jtag, uart) and external (network, usb) interfaces, and PCI Express is typically neither. After a crash course in PCIe Architecture, we'll demonstrate a handful of hacks showing how pull PCIe outside of your system case and add PCIe slots to systems without them, including embedded platforms. ....
|
Reverse Engineering Mac Malware Sarah Edwards SANS INSTITUTE Dynamic malware reverse engineering helps forensic analysts and reverse engineers gather quick data points such as callout domains, file download URLs or IP addresses, and dropped or modified files. These methods have long been used on Windows malware...so why not Mac malware? This presentation introduces the audience to methods, tools, and resources to assist reversing Mac bi....
|
|
Jim Denaro and Tod Beardsley - How to Disclose an Exploit Without Getting in Trouble
-
www.defcon.org
-
11 years ago
-
eng
How to Disclose an Exploit Without Getting in Trouble Jim Denaro CIPHERLAW Tod Beardsley ENGINEERING MANAGER, METASPLOIT PROJECT You have identified a vulnerability and may have developed an exploit. What should you do with it? You might consider going to the vendor, blogging about it, or selling it. There are risks in each of these options. This session will cover the risks to security researchers involved in publishing or selling in....
|
|
Jeff Kish, contributing editor at the excellent site GearJunkie, spent the summer hiking 1,200 miles on the Pacific Northwest Trail. I followed his journey from that first report in July all the way up to this the conclusion of his trek, and I have to say: I’m both jealous and impressed. If you had the misfortune of missing this great series, head over and check it out: it’s well-worth your time. Follow Thru-Hike Of “Pacific Northwest Trai..
|
|
Oracle In-Memory Column Store Internals – Part 1 – Which SIMD extensions are getting used?
-
tanelpoder.com
-
11 years ago
-
eng
This is the first entry in a series of random articles about some useful internals-to-know of the awesome Oracle Database In-Memory column store . I intend to write about Oracle’s IM stuff that’s not already covered somewhere else and also about some general CPU topics (that are well covered elsewhere, but not always so well known in the Oracle DBA/developer world). Before going into further details, you might want to review the Part 0 ..
|
|
Oracle In-Memory Column Store Internals – Part 1 – Which SIMD extensions are getting used?
-
tanelpoder.com
-
11 years ago
-
eng
This is the first entry in a series of random articles about some useful internals-to-know of the awesome Oracle Database In-Memory column store . I intend to write about Oracle’s IM stuff that’s not already covered somewhere else and also about some general CPU topics (that are well covered elsewhere, but not always so well known in the Oracle DBA/developer world). Before going into further details, you might want to review the Part 0 ..
|
|
The operations log or OpLog is a new Eve feature that I’m currently developing on the oplog experimental branch. It’s supposed to help in addressing a subtle issue that we’ve been dealing with, but I believe it can also emerge as a very useful all-around tool. I am posting about it in the hope of gathering some feedback from Eve contributors and users, so that I can better pinpoint design and implementation before I merge it to the main..
|
|
The operations log or OpLog is a new Eve feature that I’m currently developing on the oplog experimental branch. It’s supposed to help in addressing a subtle issue that we’ve been dealing with, but I believe it can also emerge as a very useful all-around tool. I am posting about it in the hope of gathering some feedback from Eve contributors and users, so that I can better pinpoint design and implementation before I merge it to the main..
|
|
The operations log or OpLog is a new Eve feature that I’m currently developing on the oplog experimental branch. It’s supposed to help in addressing a subtle issue that we’ve been dealing with, but I believe it can also emerge as a very useful all-around tool. I am posting about it in the hope of gathering some feedback from Eve contributors and users, so that I can better pinpoint design and implementation before I merge it to the main..
|
|
Content types are just a means of providing more structure to the data being used on your website. Drupal 7 comes by default with two content types, page and…
|
|
Another week has gone by, made all the better with a few great podcasts. This time around, we have appearances by Exponent, Back to Work, Roderick on the Line, and Defocused. Enjoy. Permalink.
|
|
I recently wrapped up a fun paper with my coauthors Ben Fish, Adam Lelkes, Lev Reyzin, and Gyorgy Turan in which we analyzed the computational complexity of a model of the popular MapReduce framework. Check out the preprint on the arXiv. Update: this paper is now published in the proceedings of DISC2015. As usual I’ll give a less formal discussion of the research here, and because the paper is a bit more technically involved than my previou..
|
|
I recently wrapped up a fun paper with my coauthors Ben Fish, Adam Lelkes, Lev Reyzin, and Gyorgy Turan in which we analyzed the computational complexity of a model of the popular MapReduce framework. Check out the preprint on the arXiv. Update: this paper is now published in the proceedings of DISC2015. As usual I’ll give a less formal discussion of the research here, and because the paper is a bit more technically involved than my previou..
|
|
I recently wrapped up a fun paper with my coauthors Ben Fish, Adam Lelkes, Lev Reyzin, and Gyorgy Turan in which we analyzed the computational complexity of a model of the popular MapReduce framework. Check out the preprint on the arXiv. Update: this paper is now published in the proceedings of DISC2015. As usual I’ll give a less formal discussion of the research here, and because the paper is a bit more technically involved than my previou..
|
|
Robot Onslaught: Multiplayer twin-stick 2D shooter using PubNub
-
thomashunter.name
-
11 years ago
-
eng
|
Before I dived in earnest into writing the new version of my computer game that teaches Python, this time with game mechanics based on the classical puzzle game “Sokoban”, I wanted to make sure that Programmable Sokoban is a fun concept. So I wrote a prototype in a couple of hours. The programmers among you […]
|
|
The first project counted as a warmup, but this is the real thing. My first solo flight covered everything from site functionality to custom theme. Baby steps, people.
|
|
A great companion to yesterday’s post, 10 Typeface Pairs for Cash-Poor Designers , for those looking to improve the design of their site through the adoption of strong design principles. Despite its original publication date of 2009, the best practices Michael Martin puts forth here have retained their value over the years in an excellent resource for aspiring designers. I have applied some of these lessons, too, in the creation of my elus..
|
|
This is just a short blip for people running Docker on CentOS who have encountered problems accessing containers from outside the localhost. The long and short of it is this command: shell sysctl net.ipv4.ip_forward=1 Why? Read this answer on StackExchange first. When Docker configures your iptables rules for network access, it likes to create a docker0 interface alongside any other network interfaces (like eth0) that Cen..
|
|
If you are interested in joining beta program for Wish ‘N U this post will help you to join the program.
|
|
If you are interested in joining beta program for Wish ‘N U this post will help you to join the program.
|
|
A hot subject these days is privacy. Since the Snowden's leaks we have been getting headlines about privacy every two or three days. This post is not about something new but it's to dwell into ways of thinking we haven't been accustomed to. I don't personally have any interest in conspiracy theories and secret societies but it's still interesting to relate it with terrorism, as we are in an era of psychotic people.
|
|
Dameff, Tully, and Hefley - Hacking 911: Adventures in Disruption, Destruction, and Death
-
www.defcon.org
-
11 years ago
-
eng
Hacking 911: Adventures in Disruption, Destruction, and Death Christian “quaddi” Dameff MD Jeff “r3plicant” Tully MD Peter Hefley SENIOR MANAGER - SUNERA Ever wonder what you would do if the people you needed most on the worst day of your entire life just weren’t there? Emergency medical services (EMS) are the safety nets we rely on every day for rapid, life-saving help in the absolute gravest of circumstances, but these services ....
|
|
Adrian Crenshaw- Dropping Docs on Darknets: How People Got Caught
-
www.defcon.org
-
11 years ago
-
eng
Dropping Docs on Darknets: How People Got Caught Adrian Crenshaw TRUSTEDSEC & IRONGEEK.COM Most of you have probably used Tor before, but I2P may be unfamiliar. Both are anonymization networks that allow people to obfuscate where their traffic is coming from, and also host services (web sites for example) without it being tied back to them. This talk will give an overview of both, but will focus on real world stories of how people were ....
|
|
As I continue work on an as of yet unnamed and unreleased project, I came across this great article by Morgan Gilpatrick from a number of years ago that still maintains its relevance today. Here he puts forth nine different font combinations paired according to a matrix of criteria, and to great results. I plan on returning here and to other resources like it when it comes time to redesign this site once again; great advice, especially help..
|
|
Whole frameworks have been written with the purpose of handling the configuration of your application. I prefer a simpler way. If by configuration we mean “everything that is likely to vary between deploys”, it follows that we should try and keep configuration simple. In Java, the simplest option is the humble properties file. The downside of a properties file is that you have to restart your application when you want it to pick up changes.
|
|
Most web applications will add/remove columns over time. This is extremely common early on and even mature applications will continue modifying their schemas with new columns. An all too common pitfall when adding new columns is setting a not null constraint in Postgres. Not null constraints What happens when you have a not null constraint on a table is it will re-write the entire table. Under the cover Postgres is really just an ap....
|
|
Most web applications will add/remove columns over time. This is extremely common early on and even mature applications will continue modifying their schemas with new columns. An all too common pitfall when adding new columns is setting a not null constraint in Postgres. Not null constraints What happens when you have a not null constraint on a table is it will re-write the entire table. Under the cover Postgres is really just an ap....
|
|
Another installment in my ongoing Cabin Porn Roundup series, where I collect interesting pictures of cabins and cool stories about the outdoors from across the world and present them in a single location. Much like my “This Week in Podcasts” series, I feature only the best of the best here. Enjoy. Permalink.
|
|
I do not employ analytics, trackers, affiliate links, or page view counters. Ain’t nobody got time for that . If you do happen to find something that violates that privacy statement, reach out to me so I can fix it, because it’s likely a programming mistake. While I don’t personally collect anything, this site is hosted using GitHub pages , so you should check their privacy policy , specifically: Please note that GitHub may colle..
|
|
I do not employ analytics, trackers, affiliate links, or page view counters. Ain’t nobody got time for that . If you do happen to find something that violates that privacy statement, reach out to me so I can fix it, because it’s likely a programming mistake. While I don’t personally collect anything, this site is hosted using GitHub pages , so you should check their privacy policy , specifically: Please note that GitHub may colle..
|
|
Reading this article from Outside Online, it reminded me of a story a family friend once told me. She explained that her son and daughter-in-law, both schoolteachers in Alaska, had decided to raise their young son without the traditional lessons society dictates a small boy learn during his formative years. As far as his dad was concerned, if he never learned to play baseball, that was just fine: instead he would learn about the outdoors, a..
|
|
This book is an absolute classic! It is basically a dystopian novel where the main character (Winston Smith) lives in. It is set…
|
|
I usually avoid proprietary cloud services because of freedom, privacy and vendor lock-in concerns. In addition, there are some excellent libre (and hosted) services such as WordPress , Wikipedia and OpenShift which don’t have the above problems. Thirdly, there are every day Free Software tools such as Fedora GNU/Linux , Libreoffice , and git-annex-assistant which make my computing much more powerful. Finally, there are some..
|
|
I usually avoid proprietary cloud services because of freedom, privacy and vendor lock-in concerns. In addition, there are some excellent libre (and hosted) services such as WordPress , Wikipedia and OpenShift which don’t have the above problems. Thirdly, there are every day Free Software tools such as Fedora GNU/Linux , Libreoffice , and git-annex-assistant which make my computing much more powerful. Finally, there are some..
|
|
I was interviewed by Anne Fisher of Fortune Magazine regarding the use of Google Glass in the workplace. This is the accompanying article published by Fortune.
|
|
File Hashing: If you look close enough, even files have fingerprints
-
joshuarogers.net
-
11 years ago
-
eng
A little while back I spent some time looking at an interesting issue with a colleage. He was trying to load a virtual machine from an .OVA but kept recieving error messages as he loaded it that the file was invalid. Somehow though, other people used the same file. This one could be fun to diagnose. To start with, the premise of our argument has a problem: it wasn't the same file but rather a copy of the file.
|
|
The Mona Lisa Leonardo da Vinci’s Mona Lisa is one of the most famous paintings of all time. And there has always been a discussion around her enigmatic smile. He used a trademark Renaissance technique called sfumato, which involves many thin layers of glaze mixed with subtle pigments. The striking result is that when you look directly at Mona Lisa’s smile, it seems to disappear. But when you look at the background your peripherals see a sm..
|