https://www.defcon.org/defcon-19/dc-19-presentations/Baldwin/DEFCON-19-Baldwin-DVCS.pdf White Paper Here: https://www.defcon.org/defcon-19/dc-19-presentations/Baldwin/DEFCON-19-Baldwin-DVCS-WP.pdf Distributed Version Control Systems, like git are becoming an increasingly popular way to deploy web applications and web related resources. Our research shows these repositories commonly contain information very useful to an attacker. T....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Baldwin/DEFCON-19-Baldwin-DVCS.pdf White Paper Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Baldwin/DEFCON-19-Baldwin-DVCS-WP.pdf Distributed Version Control Systems, like git are becoming an increasingly popular way to deploy web applications and web related resources. Our research shows these repositories commonly contain information very useful to ....
|
|
Andrea Barisani, Adam Laurie, Zac Franken and Daniele Bianco - Chip and PIN is Definitely Broken
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Barisani-Bianco-Laurie-Franken/DEFCON-19-Barisani-Bianco-Laurie-Franken.pdf The EMV global standard for electronic payments is widely used for inter-operation between chip equipped credit/debit cards, Point of Sales devices and ATMs. Following the trail of the serious vulnerabilities published by Murdoch and Drimer's team at Cambridge University regarding the usage of sto....
|
|
Andrea Barisani, Adam Laurie, Zac Franken and Daniele Bianco - Chip and PIN is Definitely Broken
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Barisani-Bianco-Laurie-Franken/DEFCON-19-Barisani-Bianco-Laurie-Franken.pdf The EMV global standard for electronic payments is widely used for inter-operation between chip equipped credit/debit cards, Point of Sales devices and ATMs. Following the trail of the serious vulnerabilities published by Murdoch and Drimer's team at Cambridge University regarding the usage of sto....
|
|
Andrea Barisani, Adam Laurie, Zac Franken & Daniele Bianco - Chip & PIN is Definitely Broken
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Barisani-Bianco-Laurie-Franken/DEFCON-19-Barisani-Bianco-Laurie-Franken.pdf The EMV global standard for electronic payments is widely used for inter-operation between chip equipped credit/debit cards, Point of Sales devices and ATMs. Following the trail of the serious vulnerabilities published by Murdoch and Drimer's team at Cambridge University regarding the usage of stolen car....
|
|
Andrea Barisani, Adam Laurie, Zac Franken and Daniele Bianco - Chip and PIN is Definitely Broken
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Barisani-Bianco-Laurie-Franken/DEFCON-19-Barisani-Bianco-Laurie-Franken.pdf The EMV global standard for electronic payments is widely used for inter-operation between chip equipped credit/debit cards, Point of Sales devices and ATMs. Following the trail of the serious vulnerabilities published by Murdoch and Drimer's team at Cambridge University regarding the usage of sto....
|
|
Bruce "Grymoire" Barnett - Deceptive Hacking: How Misdirection Can Be Used To Steal Information Without Being Detected
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Barnett/DEFCON-19-Barnett-Deceptive-Hacking.pdf White Paper Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Barnett/DEFCON-19-Barnett-Deceptive-Hacking-WP.pdf There are many similarities between professional hackers and professional magicians. Magicians are experts in creating deception, and these skills can be applied when penetrating a network. The a....
|
|
Bruce "Grymoire" Barnett - Deceptive Hacking: How Misdirection Can Be Used To Steal Information Without Being Detected
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Barnett/DEFCON-19-Barnett-Deceptive-Hacking.pdf White Paper Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Barnett/DEFCON-19-Barnett-Deceptive-Hacking-WP.pdf There are many similarities between professional hackers and professional magicians. Magicians are experts in creating deception, and these skills can be applied when penetrating a network. The a....
|
|
Bruce "Grymoire" Barnett - Deceptive Hacking: How Misdirection Can Be Used To Steal Information Without Being Detected
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Barnett/DEFCON-19-Barnett-Deceptive-Hacking.pdf White Paper Here: https://www.defcon.org/defcon-19/dc-19-presentations/Barnett/DEFCON-19-Barnett-Deceptive-Hacking-WP.pdf There are many similarities between professional hackers and professional magicians. Magicians are experts in creating deception, and these skills can be applied when penetrating a network. The author, with 30....
|
|
Bruce "Grymoire" Barnett - Deceptive Hacking: How Misdirection Can Be Used To Steal Information Without Being Detected
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Barnett/DEFCON-19-Barnett-Deceptive-Hacking.pdf White Paper Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Barnett/DEFCON-19-Barnett-Deceptive-Hacking-WP.pdf There are many similarities between professional hackers and professional magicians. Magicians are experts in creating deception, and these skills can be applied when penetrating a network. The a....
|
|
Olivier Bilodeau - Fingerbank - Open DHCP Fingerprints Database
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Bilodeau/DEFCON-19-Bilodeau-FingerBank.pdf The presentation will first take a step back and offer a basic reminder of what passive fingerprinting is and, more precisely, DHCP fingerprinting. Then we will offer defensive and offensive use cases for DHCP fingerprinting. Next, we will cover the goals and resources offered by the new project and some future plans. As part of the announcem....
|
|
Olivier Bilodeau - PacketFence, The Open Source Nac: What We've Done In The Last Two Years
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Bilodeau/DEFCON-19-Bilodeau-PacketFence.pdf Ever heard of PacketFence? It's a free and open source Network Access Control (NAC) software that's been out there since 2005. In the last two years we had several major releases with important new features that makes it an even more compelling solution. Trying to appeal to both attackers and defenders, this presentation will cover all ....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Bouillon/DEFCON-19-Bouillon-Federation-and-Empire.pdf Federated Identity is getting prevalent in corporate environments. True, solving cross domain access control to Web applications or services is a nagging issue. Today, unsatisfying traditional approaches based on duplicated user accounts or dangerous trust domain relationships are being replaced by neater solutions. One of ....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Bouillon/DEFCON-19-Bouillon-Federation-and-Empire.pdf Federated Identity is getting prevalent in corporate environments. True, solving cross domain access control to Web applications or services is a nagging issue. Today, unsatisfying traditional approaches based on duplicated user accounts or dangerous trust domain relationships are being replaced by neater solutions. One of ....
|
https://www.defcon.org/defcon-19/dc-19-presentations/Bouillon/DEFCON-19-Bouillon-Federation-and-Empire.pdf Federated Identity is getting prevalent in corporate environments. True, solving cross domain access control to Web applications or services is a nagging issue. Today, unsatisfying traditional approaches based on duplicated user accounts or dangerous trust domain relationships are being replaced by neater solutions. One of them is....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Bouillon/DEFCON-19-Bouillon-Federation-and-Empire.pdf Federated Identity is getting prevalent in corporate environments. True, solving cross domain access control to Web applications or services is a nagging issue. Today, unsatisfying traditional approaches based on duplicated user accounts or dangerous trust domain relationships are being replaced by neater solutions. One of ....
|
|
Sam Bowne - Three Generations of DoS Attacks (with Audience Participation, as Victims)
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Bowne/DEFCON-19-Bowne-Three-Generations-of-DoS-Attacks.pdf Denial-of-service (DoS) attacks are very common. They are used for extortion, political protest, revenge, or just LULz. Most of them use old, inefficient methods like UDP Floods, which require thousands of attackers to bring down a Web server. The newer Layer 7 attacks like Slowloris and Rudy are more powerful, and can ....
|
|
Sam Bowne - Three Generations of DoS Attacks (with Audience Participation, as Victims)
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Bowne/DEFCON-19-Bowne-Three-Generations-of-DoS-Attacks.pdf Denial-of-service (DoS) attacks are very common. They are used for extortion, political protest, revenge, or just LULz. Most of them use old, inefficient methods like UDP Floods, which require thousands of attackers to bring down a Web server. The newer Layer 7 attacks like Slowloris and Rudy are more powerful, and can ....
|
|
Sam Bowne - Three Generations of DoS Attacks (with Audience Participation, as Victims)
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Bowne/DEFCON-19-Bowne-Three-Generations-of-DoS-Attacks.pdf Denial-of-service (DoS) attacks are very common. They are used for extortion, political protest, revenge, or just LULz. Most of them use old, inefficient methods like UDP Floods, which require thousands of attackers to bring down a Web server. The newer Layer 7 attacks like Slowloris and Rudy are more powerful, and can stop a ....
|
|
Sam Bowne - Three Generations of DoS Attacks (with Audience Participation, as Victims)
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Bowne/DEFCON-19-Bowne-Three-Generations-of-DoS-Attacks.pdf Denial-of-service (DoS) attacks are very common. They are used for extortion, political protest, revenge, or just LULz. Most of them use old, inefficient methods like UDP Floods, which require thousands of attackers to bring down a Web server. The newer Layer 7 attacks like Slowloris and Rudy are more powerful, and can ....
|
|
David M. N. Bryan, Luiz Eduardo - Building The DEF CON Network, Making A Sandbox For 10,000 Hackers
-
www.defcon.org
-
14 years ago
-
eng
We will cover on how the DEF CON network team builds a network from scratch, in three days with very little budget. How this network evolved, what worked for us, and what didn't work over the last ten years. This network started as an idea, and after acquiring some kick butt hardware, has allowed us to support several thousand users concurrently. In addition I will cover the new WPA2 enterprise deployment, what worked, and what didn't, and ....
|
https://www.defcon.org/defcon-19/dc-19-presentations/Bryner/DEFCON-19-Bryner-Kinectasploit.pdf We've all seen hackers in movies flying through 3D worlds as they hack the gibson. How about trying it for real? Now that we've got the kinect, lets hook it up to some hacking tools and see what it looks like to hack via kinect! Jeff Bryner has 20 years of experience integrating systems, fixing security issues, performing incident respon..
|
Physical memory forensics has gained a lot of traction over the past five or six years. While it will never eliminate the need for disk forensics, memory analysis has proven its efficacy during incident response and more traditional forensic investigations. Previously, memory forensics, although useful, focused on a process' address space in the form of Virtual Address Descriptors (VADs) but ignored other rich sources of information. In the....
|
|
Marcus J. Carey, David Rude & Will Vandevanter - Metasploit vSploit Modules
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Carey/DEFCON-19-Carey-Metasploit-vSploit-Modules.pdf This talk is for security practitioners who are responsible for and need to test enterprise network security solutions. Marcus Carey, David Rude, and Will Vandevanter discuss how to use the Metasploit Framework beyond penetration testing to validate whether security solutions are working as expected. Marcus initiated the creation v....
|
|
George Chamales - Lives On The Line: Securing Crisis Maps In Libya, Sudan, And Pakistan
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Chamales/DEFCON-19-Chamales-Securing-Crisis-Maps.pdf Crisis maps collect and present open source intelligence (Twitter, Facebook, YouTube, news reports) and direct messages (SMS, email) during disasters such as the Haiti earthquake and civil unrest in Africa. The deployment of crisis mapping technology is on its way to becoming a standard tool to collect and track ground truth....
|
|
George Chamales - Lives On The Line: Securing Crisis Maps In Libya, Sudan, And Pakistan
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Chamales/DEFCON-19-Chamales-Securing-Crisis-Maps.pdf Crisis maps collect and present open source intelligence (Twitter, Facebook, YouTube, news reports) and direct messages (SMS, email) during disasters such as the Haiti earthquake and civil unrest in Africa. The deployment of crisis mapping technology is on its way to becoming a standard tool to collect and track ground truth....
|
|
George Chamales - Lives On The Line: Securing Crisis Maps In Libya, Sudan, And Pakistan
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Chamales/DEFCON-19-Chamales-Securing-Crisis-Maps.pdf Crisis maps collect and present open source intelligence (Twitter, Facebook, YouTube, news reports) and direct messages (SMS, email) during disasters such as the Haiti earthquake and civil unrest in Africa. The deployment of crisis mapping technology is on its way to becoming a standard tool to collect and track ground truth from c....
|
|
George Chamales - Lives On The Line: Securing Crisis Maps In Libya, Sudan, And Pakistan
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Chamales/DEFCON-19-Chamales-Securing-Crisis-Maps.pdf Crisis maps collect and present open source intelligence (Twitter, Facebook, YouTube, news reports) and direct messages (SMS, email) during disasters such as the Haiti earthquake and civil unrest in Africa. The deployment of crisis mapping technology is on its way to becoming a standard tool to collect and track ground truth....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Chow/DEFCON-19-Chow-Abusing-HTML5.pdf Extra Material Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Chow/Extras.zip The spike of i{Phone, Pod Touch, Pad}, Android, and other mobile devices that do not support Flash has spurred the growth and interest in HTML5, even though the standard is still evolving. The power of HTML5 allows developers to create alm....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Chow/DEFCON-19-Chow-Abusing-HTML5.pdf Extra Material Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Chow/Extras.zip The spike of i{Phone, Pod Touch, Pad}, Android, and other mobile devices that do not support Flash has spurred the growth and interest in HTML5, even though the standard is still evolving. The power of HTML5 allows developers to create alm....
|
https://www.defcon.org/defcon-19/dc-19-presentations/Chow/DEFCON-19-Chow-Abusing-HTML5.pdf Extra Material Here: https://www.defcon.org/defcon-19/dc-19-presentations/Chow/DEFCON-19-Chow-Abusing-HTML5-Extras.zip The spike of i{Phone, Pod Touch, Pad}, Android, and other mobile devices that do not support Flash has spurred the growth and interest in HTML5, even though the standard is still evolving. The power of HTML5 allows developer....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Chow/DEFCON-19-Chow-Abusing-HTML5.pdf Extra Material Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Chow/Extras.zip The spike of i{Phone, Pod Touch, Pad}, Android, and other mobile devices that do not support Flash has spurred the growth and interest in HTML5, even though the standard is still evolving. The power of HTML5 allows developers to create alm....
|
|
Sandy "Mouse" Clark, Brad "RenderMan" Haines -Familiarity Breeds Contempt
-
www.defcon.org
-
14 years ago
-
eng
Good programmers write code, great programmers reuse" is one of the most well known truisms of software development. But what does that mean for security? For over 30 years software engineering has focused on writing the perfect code and reusing it as often as they can, believing if they can just get the bugs out, the system will be secure. In our talk we will demonstrate how the most prominent doctrine of programming is deadly for security....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Cleary/DEFCON-19-Cleary-Art-of-the-Possible.pdf This session will discuss the "Art of the Possible" when it comes to "Offensive Cyber Operations" and why it is so important for both military and non-military cyber professionals to understand each others perspectives on "Offensive Cyber Operations". Discussion will focus on the military's planning process and how the potential ....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Cleary/DEFCON-19-Cleary-Art-of-the-Possible.pdf This session will discuss the "Art of the Possible" when it comes to "Offensive Cyber Operations" and why it is so important for both military and non-military cyber professionals to understand each others perspectives on "Offensive Cyber Operations". Discussion will focus on the military's planning process and how the potential ....
|
https://www.defcon.org/defcon-19/dc-19-presentations/Cleary/DEFCON-19-Cleary-Art-of-the-Possible.pdf This session will discuss the "Art of the Possible" when it comes to "Offensive Cyber Operations" and why it is so important for both military and non-military cyber professionals to understand each others perspectives on "Offensive Cyber Operations". Discussion will focus on the military's planning process and how the potential introdu....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Cleary/DEFCON-19-Cleary-Art-of-the-Possible.pdf This session will discuss the "Art of the Possible" when it comes to "Offensive Cyber Operations" and why it is so important for both military and non-military cyber professionals to understand each others perspectives on "Offensive Cyber Operations". Discussion will focus on the military's planning process and how the potential ....
|
|
This presentation is an introduction to the new world of automobile communication, data and entertainment systems, highlighting the Ford Sync System. The Ford Sync System is a remarkable technological advance that has changed the automobile industry. While hard drives have been used in automobile entertainment applications for some time now, the Ford Sync System is different. It allows the user to interact with the car's communication ....
|
|
This presentation is an introduction to the new world of automobile communication, data and entertainment systems, highlighting the Ford Sync System. The Ford Sync System is a remarkable technological advance that has changed the automobile industry. While hard drives have been used in automobile entertainment applications for some time now, the Ford Sync System is different. It allows the user to interact with the car's communication ....
|
This presentation is an introduction to the new world of automobile communication, data and entertainment systems, highlighting the Ford Sync System. The Ford Sync System is a remarkable technological advance that has changed the automobile industry. While hard drives have been used in automobile entertainment applications for some time now, the Ford Sync System is different. It allows the user to interact with the car's communication ....
|
|
This presentation is an introduction to the new world of automobile communication, data and entertainment systems, highlighting the Ford Sync System. The Ford Sync System is a remarkable technological advance that has changed the automobile industry. While hard drives have been used in automobile entertainment applications for some time now, the Ford Sync System is different. It allows the user to interact with the car's communication ....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Cook/DEFCON-19-Cook-Kernel-Exploitation.pdf Extra material here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Cook/Extras.zip Leveraging uninitialized stack memory into a full-blown root escalation is easier than it sounds. See how to find these vulnerabilities, avoid the pitfalls of priming the stack, and turn your "memory corruption" into full root privil..
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Cook/DEFCON-19-Cook-Kernel-Exploitation.pdf Extra material here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Cook/Extras.zip Leveraging uninitialized stack memory into a full-blown root escalation is easier than it sounds. See how to find these vulnerabilities, avoid the pitfalls of priming the stack, and turn your "memory corruption" into full root privil..
|
https://www.defcon.org/defcon-19/dc-19-presentations/Cook/DEFCON-19-Cook-Kernel-Exploitation.pdf Extra material here: https://www.defcon.org/defcon-19/dc-19-presentations/Cook/DEFCON-19-Cook-Kernel-Exploitation-Extras.zip Leveraging uninitialized stack memory into a full-blown root escalation is easier than it sounds. See how to find these vulnerabilities, avoid the pitfalls of priming the stack, and turn your "memory corruption" ..
|