|
Alva 'Skip' Duckwall - A Bridge Too Far: Defeating Wired 802.1x with a Transparent Bridge Using Linux
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Duckwall/DEFCON-19-Duckwall-Bridge-Too-Far.pdf Using Linux and a device with 2 network cards, I will demonstrate how to configure an undetectable transparent bridge to inject a rogue device onto a wired network that is secured via 802.1x using an existing authorized connection. I will then demonstrate how to set up the bridge to allow remote interaction and how the entire proc....
|
|
Nelson Elhage - Virtualization under attack: Breaking out of KVM
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Elhage/DEFCON-19-Elhage-Virtualization-Under-Attack.pdf KVM, the Linux Kernel Virtual Machine, seems destined to become the dominant open-source virtualization solution on Linux. Virtually every major Linux distribution has adopted it as their standard virtualization technology for the future. And yet, to date, remarkably little work has been done on exploiting vulnerabilities to....
|
|
Tim Elrod, Stefan Morris - I Am Not a Doctor but I Play One on Your Network
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Elrod-Morris/DEFCON-19-Elrod-Morris-Not-a-Doctor.pdf How secure is your Protected Health Information? This talk will expose the world of Health Information Systems with an in depth technical review of their common protocols and technologies. Many of these life-critical systems had once relied on the security provided by air gapped medical networks. Recently, in an effort to re....
|
|
Dr. Patrick Engebretson, Dr. Josh Pauli - Mamma Don't Let Your Babies Grow Up to be Pen Testers - (a.k.a. Everything Your Guidance Counselor Forgot to Tell You About Pen Testing)
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Engebretson-Pauli/DEFCON-19-Engebretson-Pauli-Pen-Testing.pdf Always wanted to be a 1337 penetration tester capable of deciphering Kryptos while simultaneously developing your own custom 0-days? Then this is NOT the talk for you. We will however make you laugh by presenting an honest look at the life and times of a penetration tester today. We promise to open your eyes to aspe....
|
|
There are a lot of great ways to hide your data from prying eyes this talk will give a crash course in the technology and some tools that can be used to secure your data. Will also discuss hiding your files in plain site so an intruder will have no idea that hidden files even exist. These same techniques can also be employed by somebody wishing to transmit messages. Eskimo (Neil Weitzel) is a Technology Analyst for Indiana University. ..
|
|
Tom Eston, Josh Abraham and Kevin Johnson - Don't Drop the SOAP: Real World Web Service Testing for Web Hacker
-
www.defcon.org
-
14 years ago
-
eng
Over the years web services have become an integral part of web and mobile applications. From critical business applications like SAP to mobile applications used by millions, web services are becoming more of an attack vector than ever before. Unfortunately, penetration testers haven't kept up with the popularity of web services, recent advancements in web service technology, testing methodologies and tools. In fact, most of the methodologi....
|
|
Ben Feinstein, Jeff Jarmoc - "Get Off of My Cloud": Cloud Credential Compromise and Exposure
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Feinstein-Jarmoc/DEFCON-19-Feinstein-Jarmoc-Get-Off-of-My-Cloud.pdf An Amazon Machine Image (AMI) is a virtual appliance container used to create virtual machines (VMs) within the Amazon Elastic Compute Cloud (EC2). EC2 instances typically interact with a variety of Amazon Web Services (AWS), and as such require access to AWS credentials and private key materials. In this p....
|
|
Foofus - Handicapping the US Supreme Court: Can We Get Rich by Forceful Browsing?
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Foofus/DEFCON-19-Foofus-Forceful-Browsing-WP.pdf Using only script-kiddie skills, it may be possible to handicap the outcome of decisions of national importance. This talk presents a walk-though of a project to make more accurate predictions of US Supreme Court case outcomes. That could be a useful thing, if you had something at stake. Conventional techniques for predicting....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Fritschie-Witmer/DEFCON-19-Fritschie-Witmer-F-On-the-River.pdf Online poker is a multi-million dollar industry that is rapidly growing, but is not highly regulated. There have been "hacks" recently (i.e. weak SSL implementation, superuser account) that have drawn more attention to security in the poker industry, especially as it moves to full regulation in the United States. T....
|
|
Eric Fulton - Cellular Privacy: A Forensic Analysis of Android Network Traffic
-
www.defcon.org
-
14 years ago
-
eng
People inherently trust their phones, but should they? "Cellular Privacy: A Forensic Analysis of Android Network Traffic" is a presentation of results from forensically analyzing the network traffic of an Android phone. The results paint an interesting picture. Is Google more trustworthy than the application developers? Are legitimate market apps more trustworthy than their rooted counterparts? Perhaps most importantly, should you trust you..
|
|
Andrew Gavin - Gone in 60 Minutes: Stealing Sensitive Data from Thousands of Systems Simultaneously with OpenDLP
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Gavin/DEFCON-19-Gavin-OpenDLP.pdf Got domain admin to a couple of thousand Windows systems? Got an hour to spare? Steal sensitive data from all of these systems simultaneously in under an hour with OpenDLP. OpenDLP is an open source, agent-based, massively distributable, centrally managed data discovery program that runs as a service on Windows systems and is controlled from a....
|
|
Kenneth Geers - Strategic Cyber Security: An Evaluation of Nation-State Cyber Attack Mitigation Strategies
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Geers/DEFCON-19-Geers-Strategic-Cyber-Security.pdf White Paper Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Geers/DEFCON-19-Geers-Strategic-Cyber-Security-WP.pdf This presentation argues that computer security has evolved from a technical discipline to a strategic concept. The world's growing dependence on a powerful but vulnerable Internet - combined....
|
|
Ramon Gomez - Bulletproofing The Cloud: Are We Any Closer To Security?
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Gomez/DEFCON-19-Gomez-Bulletproofing-The-Cloud.pdf Cloud security has come into focus in the last few years; while many ways to break the cloud have been proposed, few solutions have been put forward. This talk is primarily a conceptual discussion on how cloud providers can and should be (but probably are not) protecting both their own and their clients' assets in their cloud ....
|
|
Vlad Gostom, Joshua Marpet - Smile for the Grenade! "Camera Go Bang!"
-
www.defcon.org
-
14 years ago
-
eng
Cameras are hugely important to urban and suburban battlefields. Reconnaissance is a must-have for commanders, and a force multiplier for actual combat units. A combat-deployable camera system is being developed or used by nearly every military-industrial manufacturer and government agency, ranging from Throwable Camera Balls to Grenade-style launched cameras. But they're expensive and inaccessible to civilians. Would it be possible to buil....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/DC-Groups-Panel/DEFCON-19-DC-Groups-Panel.pdf Fabricating, circumventing, forging, partying, milling, crafting, building breaking - Defcon Groups have risen, fallen, and endured the last 8 years as decentralized and smoldering embers of the local hacker think-tank. This year Defcon sets out to stoke that fire and unite our groups, at and outside of the conference. The talk ....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Hamiel/DEFCON-19-Hamiel-Smartfuzzing_the_Web_DC.pdf Extra Material: https://www.defcon.org/images/defcon-19/dc-19-presentations/Hamiel/Extras.zip It can be scary to think about how little of the modern attack surface many tools cover. There is no one best tool for the job and on top of that some tools don't do a great job at anything. Often in the hands of general users t....
|
|
Rob Havelt, Wendel Guglielmetti Henrique - Earth vs. The Giant Spider: Amazingly True Stories of Real Penetration Tests
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Havelt-Henrique/DEFCON-19-Havelt-Henrique.pdf Earth vs. The Giant Spider: Amazingly True Stories of Real Penetration Tests brings the DEF CON 19 audience the most massive collection of weird, downright bizarre, freaky, and altogether unlikely hacks ever seen in the wild. This talk will focus on those complex hacks found in real environments - some in very high end and importan....
|
|
Deral Heiland - From Printer To Pwnd: Leveraging Multifunction Printers During Penetration Testing
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Heiland/DEFCON-19-Heiland-Printer-To-Pwnd.pdf https://www.defcon.org/images/defcon-19/dc-19-presentations/Heiland/Extras.zip In this presentation we go beyond the common printer issues and focus on harvesting data from multifunction printer (MFP) that can be leveraged to gain access to other core network systems. By taking advantage of poor printer security and vulnerabil....
|
|
Thomas J. Holt, Max Kilger - Assessing Civilian Willingness to Participate in On-Line Political and Social Conflict
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Holt-Kilger/DEFCON-19-Holt-Kilger-Assessing-Civilian-Willingness.pdf Changes in the social dynamics and motivations of the hacking community are a potential catalyst that when combined with the expanding reliance of critical infrastructure components upon networked control systems may provide the genesis for the emergence of what is being called the civilian cyberwarrior Th....
|
|
Rick Howard - An Insider's Look at International Cyber Security Threats and Trends
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Howard/DEFCON-19-Howard-Cyber-Security-Trends.pdf White Paper Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Howard/DEFCON-19-Howard-Cyber-Security-Trends-WP.pdf Verisign iDefense General Manager, Rick Howard, will provide an inside look into current cyber security trends with regard to Cyber War, Cyber Hacktivism, and Cyber Espionage. In this presentat....
|
|
This talk will educate listeners on best practices for safety and privacy on the Internet.It aims to demonstrate the improbability of staying anonymous while engaging in group or social activities on the internet, and especially while engaging in criminal activities as a group. This talk will reveal how Hubris, A5h3r4h, and Backtrace security staged a cyber war against anonymous, using Anonymous' own methods, and how key operatives in ....
|
|
Robert "Hackajar" Imhoff-Dousharm - Economics of Password Cracking in the GPU Era
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Imhoff/DEFCON-19-Imhoff-Password-Cracking.pdf As this shift to "General Computing" and working in the cloud has accelerated in the last 4 years, so has the ability to take advantage of these technologies from an Information Security vantage point. This could not be more apparent than with the sudden uptick in GPU based password cracking technologies. In this presentation we wi....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Jakhar/DEFCON-19-Jakhar-Jugaad-Linux-Thread-Injection.pdf Windows malware conveniently use the CreateRemoteThread() api to delegate critical tasks inside of other processes. However till now there is no API on Linux to perform such operation. This paper talks about my work on creating an API similar to createRemoteThread() on *nix OSes. The kit currently works on Linux, alloca....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Joyce/DEFCON-19-Joyce-trollspotting.png Trolling is something that today has a very negative connotation on the Internet and in the common usage of the word outside of it. However, for better or worse trolling has long enjoyed a close relationship with hacking be it in the area of information security, or simply in technology development. I intend to delve into the definition ....
|
|
Remember when networks represented interesting targets, when TCP/IP was itself a vector for messiness, when packet crafting was a required skill? In this thoroughly retro talk, we're going to play with systems the old fashioned way, cobbling together various interesting behaviors with the last few shreds of what low level networking has to offer. Here's a few things to expect: * IPv4 and IPv6 Fragmentation Attacks, Eight Years In The M..
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Kennedy/DEFCON-19-Kennedy-Pentesting-Over-Powerlines-2.pdf When performing penetration tests on the internal network in conjunction with physical pentests your always concerned about being located. Let's remove that barrier and perform your penitents over power lines and never be detected. In this presentation we'll cover how you can perform full penetration tests over the pow....
|
|
Brian Kennish - Tracking the Trackers: How Our Browsing History Is Leaking into the Cloud
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Kennish/DEFCON-19-Kennish-Tracking-the-Trackers.pdf What companies and organizations are collecting our web-browsing activity? How complete is their data? Do they have personally-identifiable information? What do they do with the data? The speaker, an ex-Google and DoubleClick engineer, will answer these questions by detailing the research he did for The Wall Street Journ....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Kornbrust/DEFCON-19-Kornbrust-Hacking-and-Securing-DB2.pdf DB2 for Linux, Unix and Windows is one of the databases where only little bit information about security problems is available. Nevertheless DB2 LUW is installed in many corporate networks and if not hardened properly could be an easy target for attackers. In many aspects DB2 is different from other databases, starting....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Kotler-Amit/DEFCON-19-Kotler-Amit-Sounds-Like-Botnet.pdf VoIP is one of the most widely-used technologies among businesses and, increasingly, in households. It represents a combination of Internet technology and phone technology that enhances and expands the possibilities of both. One of these possibilities involves using it for botnet command and control infrastructure and a ....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Krick/DEFCON-19-Krick-License-to-Transmit.pdf https://www.defcon.org/images/defcon-19/dc-19-presentations/Krick/Extras.zip When cell phones, land lines and the internet break down in a disaster, Amateur radio is there. Considered to be one of the earliest forms of Hacking, this talk will take a look at some of the things that can be done if you are a licensed amateur radi..
|
|
Anthony Lai, Benson Wu, Jeremy Chiu and PK - Balancing The Pwn Trade Deficit - APT Secrets in Asia
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Lai-Wu-Chiu-PK/DEFCON-19-Lai-Wu-Chiu-PK-APT-Secrets-2.pdf In last year, we have given a talk over China-made malware in both Blackhat and DEFCON, which is appreciated by various parties and we would like to continue this effort and discuss over APT attacks in Asia this year. However, case studies are not just our main dish this time, we will carry out technical analysis over t....
|
|
Shane Lawson, Bruce Potter and Deviant Ollam - And That's How I Lost My Eye: Exploring Emergency Data Destruction
-
www.defcon.org
-
14 years ago
-
eng
Are you concerned that you have become a subject of unwarranted scrutiny? Convinced that the black helicopters are incoming and ruthless feds are determined in to steal your plans of world domination? This talk explores several potential designs for quick and ruthless destruction of data as a last resort, break glass in case of emergency type of situation. Projectiles and chemical warfare will be involved along with other methods. Each meth....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Lenik/DEFCON-19-Lenik-MAC(b)Daddy.pdf The field of Computer Forensics moves more and more in the direction of rapid response and live system analysis every day. As breaches and attacks become more and more sophisticated the responders need to continually re-examine their arsenal for new tactics and faster ways to process large amounts of data. Timelines and super-timelines hav....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Linn/DEFCON-19-Linn-PIG-Finding-Truffles.pdf When we connect to a network we leak information. Whether obtaining an IP address, finding our default gateway, or using Dropbox there are packets that can be used to help identify more about our machine and network. This talk and series of demonstrations will help you learn to passively profile a network through a new Metasploit mo....
|
|
David Litchfield - Hacking and Forensicating an Oracle Database Server
-
www.defcon.org
-
14 years ago
-
eng
David Litchfield is recognized as one of the world's leading authorities on database security. He is the author of Oracle Forensics, the Oracle Hacker's Handbook, the Database Hacker's Handbook and SQL Server Security and is the co-author of the Shellcoder's Handbook. He is a regular speaker at a number of computer security conferences and has delivered lectures to the National Security Agency, the UK's Security Service, GCHQ and the Bundes..
|
|
What Cloak? Recent policy proposals from the US Executive seem to call for government support for strong encryption use by individuals and vendors in the name of protecting privacy and anonymity. Yet strong encryption is still considered a controlled resource, requiring explicit permission to import or export from the US. This is also true for other countries. This talk will try to couch these proposals in light of past crypto rules, illumi..
|
|
Joey Maresca - We're (The Government) Here To Help: A Look At How FIPS 140 Helps (And Hurts) Security
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Maresca/DEFCON-19-Maresca-FIPS-140.pdf Many standards, especially those provided by the government, are often viewed as more trouble the actual help. The goal of this talk is to shed a new light onto onesuch standard (FIPS 140) and show what it is inteded for and how is can sometimes help ensure good design practices for security products. But everything is not roses and there....
|
|
In the early 90's, at the dawn of the World Wide Web, some engineers at Netscape developed a protocol for making secure HTTP requests, and what they came up with was called SSL. Given the relatively scarce body of knowledge concerning secure protocols at the time, as well the intense pressure that everyone at Netscape was working under, their efforts can only be seen as incredibly heroic. But while it's amazing that SSL has endured for as l..
|
|
This presentation will cover the Black Arts of making Cracks, KeyGens, Malware, and more. The information in this presentation will allow a .NET programmer to do unspeakable things .NET applications. I will cover the life cycle of developing such attacks and over coming common countermeasures to stop such attacks. New tools to assist in the attacks will be supplied. This presentation will focus on C# but applies to any application based on ..
|
|
Wesley McGrew - Covert Post-Exploitation Forensics With Metasploit
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/McGrew/DEFCON-19-McGrew-Covert.pdf https://www.defcon.org/images/defcon-19/dc-19-presentations/McGrew/DEFCON-19-McGrew-Covert-WP.pdf https://www.defcon.org/images/defcon-19/dc-19-presentations/McGrew/Extras.zip In digital forensics, most examinations take place after the hardware has been physically seized (in most law enforcement scenarios) or a preinstalled agent a....
|
|
John McNabb - Vulnerabilities of Wireless Water Meter Networks
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/McNabb/DEFCON-19-McNabb-Vulns-Wireless-Water-Meter-Networks.pdf Why research wireless water meters? Because they are a potential security hole in a critical infrastructure, which can lead to a potential leakage of private information, and create the potential to steal water by lowering water bills? It's a technology that's all around us but seems to too mundane to think about.....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Miller/DEFCON-19-Miller-Battery-Firmware-Hacking.pdf Ever wonder how your laptop battery knows when to stop charging when it is plugged into the wall, but the computer is powered off? Modern computers are no longer just composed of a single processor. Computers possess many other embedded microprocessors. Researchers are only recently considering the security implications of m....
|
|
We're baaaaaack! The most talked about panel at DEF CON! Nearly two hours of non-stop FAIL. Come hear some of the loudest mouths in the industry talk about the epic security failures of the last year. We'll be covering mobile phones, cloud, money laundering and food cooked on stage to name just a few topics. Nothing is sacred not even each other. Come for the FAIL stay for the crepes! David Mortman runs Operations and Security for C3, ....
|
|
Steve Ocepek - Blinkie Lights: Network Monitoring with Arduino
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Ocepek/DEFCON-19-Ocepek-Blinkie-Lights-Arduino.pdf https://www.defcon.org/images/defcon-19/dc-19-presentations/Ocepek/Extras.zip Remember the good old days, when you'd stare at Rx and Tx on your shiny new Supra 1200bps modem, and actually know what the heck was going on? Systems tend to talk a lot more nowadays, and somewhere along the line I completely lost track of who ....
|