|
John J. Strauchs, Tiffany Rad, Teague Newman & Dora The SCADA Explorer - SCADA & PLCs in Correctional Facilities: The Nightmare Before Christmas
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Strauchs-Rad-Newman/DEFCON-19-Strauchs_Rad_Newman-SCADA-in-Prisons.pptx.pdf On Christmas Eve, a call was made from a prison warden: all of the cells on death row popped open. Many prisons and jails use SCADA systems with PLCs to open and close doors. Not sure why or if it would happen, the warden called physical security design engineer, John Strauchs, to investigate. As a result of ....
|
|
Panel - SCADA & PLCs in Correctional Facilities: The Nightmare Before Christmas
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Strauchs-Rad-Newman/DEFCON-19-Strauchs_Rad_Newman-SCADA-in-Prisons.pptx.pdf On Christmas Eve, a call was made from a prison warden: all of the cells on death row popped open. Many prisons and jails use SCADA systems with PLCs to open and close doors. Not sure why or if it would happen, the warden called physical security design engineer, John Strauchs, to investigate. As a res....
|
|
Bruce Sutherland - How To Get Your Message Out When Your Government Turns Off The Internet
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Sutherland/DEFCON-19-Sutherland-How-to-Get-Your-Message-Out.pdf How would you communicate with the world if your government turned off the Internet? Sound far-fetched? It isn't. It already happened in Egypt and Lybia and the US Congress is working on laws that would allow it to do the same. In this talk we'll explore how to get short messages out of the country via Email and T..
|
|
Bruce Sutherland - How To Get Your Message Out When Your Government Turns Off The Internet
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Sutherland/DEFCON-19-Sutherland-How-to-Get-Your-Message-Out.pdf How would you communicate with the world if your government turned off the Internet? Sound far-fetched? It isn't. It already happened in Egypt and Lybia and the US Congress is working on laws that would allow it to do the same. In this talk we'll explore how to get short messages out of the country via Email and T..
|
|
Bruce Sutherland - How To Get Your Message Out When Your Government Turns Off The Internet
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Sutherland/DEFCON-19-Sutherland-How-to-Get-Your-Message-Out.pdf How would you communicate with the world if your government turned off the Internet? Sound far-fetched? It isn't. It already happened in Egypt and Lybia and the US Congress is working on laws that would allow it to do the same. In this talk we'll explore how to get short messages out of the country via Email and Twitter ..
|
|
Bruce Sutherland - How To Get Your Message Out When Your Government Turns Off The Internet
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Sutherland/DEFCON-19-Sutherland-How-to-Get-Your-Message-Out.pdf How would you communicate with the world if your government turned off the Internet? Sound far-fetched? It isn't. It already happened in Egypt and Lybia and the US Congress is working on laws that would allow it to do the same. In this talk we'll explore how to get short messages out of the country via Email and T..
|
|
Abstrct - When Space Elephants Attack: A DEFCON Challenge for Database Geeks
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Absrtct/DEFCON-19-Abstrct-The-Schemaverse.pdf The Schemaverse is a vast universe found purely within a PostgreSQL database. Control your fleet of ships manually with SQL commands or write AI in PL/pgSQL so they control themselves while you sit back and enjoy the con. This presentation will help my fellow database geeks to understand the game play mechanics used in The Schemaverse s..
|
|
General Keith B. Alexander - Shared Values, Shared Responsibility
-
www.defcon.org
-
14 years ago
-
eng
Shared Values, Shared Responsibility General Keith B. Alexander Commander, US Cyber Command (USCYBERCOM) and Director, National Security AgenCy/Chief, Central Security Service (NSA/CSS) We as a global society are extremely vulnerable and at risk for a catastrophic cyber event. Global society needs the best and brightest to help secure our most valued resources in cyberspace: our intellectual property, our critical infrastructure and ....
|
|
General Keith B. Alexander - Shared Values, Shared Responsibility
-
www.defcon.org
-
14 years ago
-
eng
Shared Values, Shared Responsibility General Keith B. Alexander Commander, US Cyber Command (USCYBERCOM) and Director, National Security AgenCy/Chief, Central Security Service (NSA/CSS) We as a global society are extremely vulnerable and at risk for a catastrophic cyber event. Global society needs the best and brightest to help secure our most valued resources in cyberspace: our intellectual property, our critical infrastructure an....
|
|
Abstrct - When Space Elephants Attack: A DEFCON Challenge for Database Geeks
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Absrtct/DEFCON-19-Abstrct-The-Schemaverse.pdf The Schemaverse is a vast universe found purely within a PostgreSQL database. Control your fleet of ships manually with SQL commands or write AI in PL/pgSQL so they control themselves while you sit back and enjoy the con. This presentation will help my fellow database geeks to understand the game play mechanics used in The Schemaverse ..
|
|
Abstrct - When Space Elephants Attack: A DEFCON Challenge for Database Geeks
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Absrtct/DEFCON-19-Abstrct-The-Schemaverse.pdf The Schemaverse is a vast universe found purely within a PostgreSQL database. Control your fleet of ships manually with SQL commands or write AI in PL/pgSQL so they control themselves while you sit back and enjoy the con. This presentation will help my fellow database geeks to understand the game play mechanics used in The Schemaverse so they..
|
|
General Keith B. Alexander - Shared Values, Shared Responsibility
-
www.defcon.org
-
14 years ago
-
eng
Shared Values, Shared Responsibility General Keith B. Alexander Commander, US Cyber Command (USCYBERCOM) and Director, National Security AgenCy/Chief, Central Security Service (NSA/CSS) We as a global society are extremely vulnerable and at risk for a catastrophic cyber event. Global society needs the best and brightest to help secure our most valued resources in cyberspace: our intellectual property, our critical infrastructure an....
|
|
Abstrct - When Space Elephants Attack: A DEFCON Challenge for Database Geeks
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Absrtct/DEFCON-19-Abstrct-The-Schemaverse.pdf The Schemaverse is a vast universe found purely within a PostgreSQL database. Control your fleet of ships manually with SQL commands or write AI in PL/pgSQL so they control themselves while you sit back and enjoy the con. This presentation will help my fellow database geeks to understand the game play mechanics used in The Schemaverse s..
|
|
General Keith B. Alexander - Shared Values, Shared Responsibility
-
www.defcon.org
-
14 years ago
-
eng
Shared Values, Shared Responsibility General Keith B. Alexander Commander, US Cyber Command (USCYBERCOM) and Director, National Security AgenCy/Chief, Central Security Service (NSA/CSS) We as a global society are extremely vulnerable and at risk for a catastrophic cyber event. Global society needs the best and brightest to help secure our most valued resources in cyberspace: our intellectual property, our critical infrastructure an....
|
|
Chema Alonso, Juan Garrido "Silverhack" - Bosses love Excel, Hackers too.
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Alonso-Garrido/DEFCON-19-Alonso-Garrido-Excel.pdf Remote applications published in companies are around us in the cloud. In this talk we are going to add ICA and Terminal Server Apps to fingerprinting process, automating data analysis using FOCA. It will allow attacker to fingerprinting internal software, internal networks and combine the info in PTR Scanning, evil-grade attac....
|
|
Chema Alonso, Juan Garrido "Silverhack" - Dust: Your Feed RSS Belongs To You! Avoid Censorship!
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Alonso-Garrido/DEFCON-19-Alonso-Garrido-DUST.pdf Law around the world is trying to control what is published on the Internet. After wikileaks case and HBGary ownage everybody could see how there are many controls that can be used to close a website, a domain name and to cut the communication between the source and the audience. What happened if someone wants to close your blog?....
|
|
Chema Alonso, Juan Garrido "Silverhack" - Bosses love Excel, Hackers too.
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Alonso-Garrido/DEFCON-19-Alonso-Garrido-Excel.pdf Remote applications published in companies are around us in the cloud. In this talk we are going to add ICA and Terminal Server Apps to fingerprinting process, automating data analysis using FOCA. It will allow attacker to fingerprinting internal software, internal networks and combine the info in PTR Scanning, evil-grade attac....
|
|
Chema Alonso, Juan Garrido "Silverhack" - Dust: Your Feed RSS Belongs To You! Avoid Censorship!
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Alonso-Garrido/DEFCON-19-Alonso-Garrido-DUST.pdf Law around the world is trying to control what is published on the Internet. After wikileaks case and HBGary ownage everybody could see how there are many controls that can be used to close a website, a domain name and to cut the communication between the source and the audience. What happened if someone wants to close your blog?....
|
|
Chema Alonso, Juan Garrido "Silverhack" - Bosses love Excel, Hackers too.
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Alonso-Garrido/DEFCON-19-Alonso-Garrido-Excel.pdf Remote applications published in companies are around us in the cloud. In this talk we are going to add ICA and Terminal Server Apps to fingerprinting process, automating data analysis using FOCA. It will allow attacker to fingerprinting internal software, internal networks and combine the info in PTR Scanning, evil-grade attacks and ....
|
|
Chema Alonso, Juan Garrido "Silverhack" - Dust: Your Feed RSS Belongs To You! Avoid Censorship!
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Alonso-Garrido/DEFCON-19-Alonso-Garrido-DUST.pdf Law around the world is trying to control what is published on the Internet. After wikileaks case and HBGary ownage everybody could see how there are many controls that can be used to close a website, a domain name and to cut the communication between the source and the audience. What happened if someone wants to close your blog? Could ....
|
|
Chema Alonso, Juan Garrido "Silverhack" - Bosses love Excel, Hackers too.
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Alonso-Garrido/DEFCON-19-Alonso-Garrido-Excel.pdf Remote applications published in companies are around us in the cloud. In this talk we are going to add ICA and Terminal Server Apps to fingerprinting process, automating data analysis using FOCA. It will allow attacker to fingerprinting internal software, internal networks and combine the info in PTR Scanning, evil-grade attac....
|
|
Chema Alonso, Juan Garrido "Silverhack" - Dust: Your Feed RSS Belongs To You! Avoid Censorship!
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Alonso-Garrido/DEFCON-19-Alonso-Garrido-DUST.pdf Law around the world is trying to control what is published on the Internet. After wikileaks case and HBGary ownage everybody could see how there are many controls that can be used to close a website, a domain name and to cut the communication between the source and the audience. What happened if someone wants to close your blog?....
|
|
At Defcon 17 when a speaker didn't show a bottle of vodka was offered to whoever gave an impromptu talk. Somebody went up and talked about his robot project. He mentioned that it didn't normally drive straight, and talked about all the software solutions he had tried to fix this. I was reasonably intoxicated and wound up shouting at him over the crowd that it did not drive straight because of his drive base design, and not his software. Thi....
|
|
Sterling Archer, Freaksworth - IP4 TRUTH: The IPocalypse is a LIE
-
www.defcon.org
-
14 years ago
-
eng
There is a long tradition of researchers presenting at security conferences on topics that are embarrassing to a large company or government agency: ATM hacking, router vulnerabilities, Massachusetts toll road RFIDs, etc. Many of these brave researchers risk lawsuits or career ruin to reveal the truth. THIS is the first talk that puts the presenters' very lives in peril. Much has been made of the so-called "IPv4 address exhaustion" problem,....
|
|
Phil Cryer - Taking Your Ball And Going Home; Building Your Own Secure Storage Space That Mirrors Dropbox's Functionality
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Cryer/DEFCON-19-Cryer-Taking-Your-Ball-and-Going-Home.pdf When for-profit companies offer a free app, there is always going to be strings attached. As we have increasingly seen, these strings are often tied to your privacy to enable said third party company to monetize you in some way, but in worse cases your security can be compromised leaving you open to identity theft at be....
|
|
Panel - PCI 2.0: Still Compromising Controls and Compromising Security
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/PCI-PANEL/DEFCON-19-JackDaniel-PCI-2-PANEL.pdf Building on last year's panel discussion of PCI and its impact on the world of infosec, we are back for more- including "actionable" information. Having framed the debates in the initial panel, this year we will focus on what works, what doesn't, and what we can do about it. Compliance issues in general, and PCI-DSS in partic....
|
|
Dark Tangent, Rod Beckstrom, Jerry Dixon, Tony Sager, Linton Wells II - Former Keynotes - The Future
-
www.defcon.org
-
14 years ago
-
eng
Former keynotes keep coming back to DEFCON. Join The Dark Tangent, Rod Beckstrom, Jerry Dixon, Tony Sager, and Linton Wells to discuss the future of cyber security. Rod Beckstrom is a highly successful entrepreneur, founder and CEO of a publicly-traded company, a best-selling author, avowed environmentalist, public diplomacy leader and, most recently, the head of a top-level federal government agency entrusted with protecting the natio....
|
|
Tamper evident technologies are quickly becoming an interesting topic for hackers around the world. DEF CON 18 (2010) held the first ever "Tamper Evident" contest, where contestants were given a box sealed with a variety of tamper evident devices, many of which purport to be "tamper proof." All of these devices were defeated, even by those with little experience and a limited toolkit. Like the computer world, many of these devices are overm....
|
|
Ganesh Devarajan, Don LeBert - VDLDS - All Your Voice Are Belong To Us
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Devarajan-LeBert/DEFCON-19-Devarajan-LeBert-VDLDS.pptx.pdf Anytime you want to bypass the system, you tend to have a telephone conversation instead of leaving a paper trail. Data Leakage Prevention (DLP) is on top of the list for most organizations, be it financial or medical industry. In order to overcome this issue we need to devise a new system that can monitor phone conver....
|
|
Deviant Ollam - Safe to Armed in Seconds: A Study of Epic Fails of Popular Gun Safes
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Ollam/DEFCON-19-Ollam-Gun-Safes.pdf Hackers like guns. Hackers like locks. Hackers like to tinker with guns and locks. And, most of the time, hackers protect their guns with high-quality locks. However, while it's one thing to own a nice gun safe protected by a high security dial, that sort of solution tends to be best for the firearms that one doesn't have in daily use. Many ....
|
|
Whitfield Diffie and Moxie Marlinspike - Whitfield Diffie and Moxie Marlinspike
-
www.defcon.org
-
14 years ago
-
eng
Come watch Whitfield Diffie and Moxie Marlinspike talk about certificate authorities, DNSSEC, SSL, dane, trust agility and whatever else they want to. Moderated by the Dark Tangent and with Q&A from the audience.
|
|
Artem Dinaburg - Bit-squatting: DNS Hijacking Without Exploitation
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Dinaburg/DEFCON-19-Dinaburg-Bit-Squatting.pdf We are generally accustomed to assuming that computer hardware will work as described, barring deliberate sabotage. This assumption is mistaken. Poor manufacturing, errant radiation, and heat can cause malfunction. Commonly, such malfunction DRAM chips manifest as flipped bits. Security researchers have known about the danger of su....
|
|
Alva 'Skip' Duckwall - A Bridge Too Far: Defeating Wired 802.1x with a Transparent Bridge Using Linux
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Duckwall/DEFCON-19-Duckwall-Bridge-Too-Far.pdf Using Linux and a device with 2 network cards, I will demonstrate how to configure an undetectable transparent bridge to inject a rogue device onto a wired network that is secured via 802.1x using an existing authorized connection. I will then demonstrate how to set up the bridge to allow remote interaction and how the entire proc....
|
|
Nelson Elhage - Virtualization under attack: Breaking out of KVM
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Elhage/DEFCON-19-Elhage-Virtualization-Under-Attack.pdf KVM, the Linux Kernel Virtual Machine, seems destined to become the dominant open-source virtualization solution on Linux. Virtually every major Linux distribution has adopted it as their standard virtualization technology for the future. And yet, to date, remarkably little work has been done on exploiting vulnerabilities to....
|
|
Tim Elrod, Stefan Morris - I Am Not a Doctor but I Play One on Your Network
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Elrod-Morris/DEFCON-19-Elrod-Morris-Not-a-Doctor.pdf How secure is your Protected Health Information? This talk will expose the world of Health Information Systems with an in depth technical review of their common protocols and technologies. Many of these life-critical systems had once relied on the security provided by air gapped medical networks. Recently, in an effort to re....
|
|
Dr. Patrick Engebretson, Dr. Josh Pauli - Mamma Don't Let Your Babies Grow Up to be Pen Testers - (a.k.a. Everything Your Guidance Counselor Forgot to Tell You About Pen Testing)
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Engebretson-Pauli/DEFCON-19-Engebretson-Pauli-Pen-Testing.pdf Always wanted to be a 1337 penetration tester capable of deciphering Kryptos while simultaneously developing your own custom 0-days? Then this is NOT the talk for you. We will however make you laugh by presenting an honest look at the life and times of a penetration tester today. We promise to open your eyes to aspe....
|
|
There are a lot of great ways to hide your data from prying eyes this talk will give a crash course in the technology and some tools that can be used to secure your data. Will also discuss hiding your files in plain site so an intruder will have no idea that hidden files even exist. These same techniques can also be employed by somebody wishing to transmit messages. Eskimo (Neil Weitzel) is a Technology Analyst for Indiana University. ..
|
|
Tom Eston, Josh Abraham and Kevin Johnson - Don't Drop the SOAP: Real World Web Service Testing for Web Hacker
-
www.defcon.org
-
14 years ago
-
eng
Over the years web services have become an integral part of web and mobile applications. From critical business applications like SAP to mobile applications used by millions, web services are becoming more of an attack vector than ever before. Unfortunately, penetration testers haven't kept up with the popularity of web services, recent advancements in web service technology, testing methodologies and tools. In fact, most of the methodologi....
|
|
Ben Feinstein, Jeff Jarmoc - "Get Off of My Cloud": Cloud Credential Compromise and Exposure
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Feinstein-Jarmoc/DEFCON-19-Feinstein-Jarmoc-Get-Off-of-My-Cloud.pdf An Amazon Machine Image (AMI) is a virtual appliance container used to create virtual machines (VMs) within the Amazon Elastic Compute Cloud (EC2). EC2 instances typically interact with a variety of Amazon Web Services (AWS), and as such require access to AWS credentials and private key materials. In this p....
|
|
Foofus - Handicapping the US Supreme Court: Can We Get Rich by Forceful Browsing?
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Foofus/DEFCON-19-Foofus-Forceful-Browsing-WP.pdf Using only script-kiddie skills, it may be possible to handicap the outcome of decisions of national importance. This talk presents a walk-though of a project to make more accurate predictions of US Supreme Court case outcomes. That could be a useful thing, if you had something at stake. Conventional techniques for predicting....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Fritschie-Witmer/DEFCON-19-Fritschie-Witmer-F-On-the-River.pdf Online poker is a multi-million dollar industry that is rapidly growing, but is not highly regulated. There have been "hacks" recently (i.e. weak SSL implementation, superuser account) that have drawn more attention to security in the poker industry, especially as it moves to full regulation in the United States. T....
|
|
Eric Fulton - Cellular Privacy: A Forensic Analysis of Android Network Traffic
-
www.defcon.org
-
14 years ago
-
eng
People inherently trust their phones, but should they? "Cellular Privacy: A Forensic Analysis of Android Network Traffic" is a presentation of results from forensically analyzing the network traffic of an Android phone. The results paint an interesting picture. Is Google more trustworthy than the application developers? Are legitimate market apps more trustworthy than their rooted counterparts? Perhaps most importantly, should you trust you..
|
|
Andrew Gavin - Gone in 60 Minutes: Stealing Sensitive Data from Thousands of Systems Simultaneously with OpenDLP
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Gavin/DEFCON-19-Gavin-OpenDLP.pdf Got domain admin to a couple of thousand Windows systems? Got an hour to spare? Steal sensitive data from all of these systems simultaneously in under an hour with OpenDLP. OpenDLP is an open source, agent-based, massively distributable, centrally managed data discovery program that runs as a service on Windows systems and is controlled from a....
|
|
Kenneth Geers - Strategic Cyber Security: An Evaluation of Nation-State Cyber Attack Mitigation Strategies
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Geers/DEFCON-19-Geers-Strategic-Cyber-Security.pdf White Paper Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Geers/DEFCON-19-Geers-Strategic-Cyber-Security-WP.pdf This presentation argues that computer security has evolved from a technical discipline to a strategic concept. The world's growing dependence on a powerful but vulnerable Internet - combined....
|