|
Frank Breedijk - Seccubus - Analyzing Vulnerability Assessment Data the Easy Way
-
www.defcon.org
-
15 years ago
-
eng
As part of his job as Security Engineer at Schuberg Philis, Frank Breedijk performs regular security scans. The repetitive nature of scanning the same customer infrastructure over and over again made him decide to look for a more automated approach. After building his first scanning scheduler he realized that it actually does not make sense to look at all findings every time they are reported. It would be much better to only investigate the....
|
|
frank^2 - Trolling Reverse-Engineers with Math: Ness... It hurts...
-
www.defcon.org
-
15 years ago
-
eng
y = mx+b? f(x) = sin(x/freq)*amp?! SIN X = (A+BX+CX^2)/(P+QX+RX^2)?! None of these formulas as they stand alone really mean much of anything-- except maybe a headache for some. Isolating the variables, however, will eventually open the door for us to manipulate our code in creative and exciting ways. This isn't necessarily a ground-breaking technique in obfuscation, but who cares if it's fun? Given an arbitrary formula, we can place our cod....
|
|
Frank Breedijk - Seccubus - Analyzing Vulnerability Assessment Data the Easy Way
-
www.defcon.org
-
15 years ago
-
eng
As part of his job as Security Engineer at Schuberg Philis, Frank Breedijk performs regular security scans. The repetitive nature of scanning the same customer infrastructure over and over again made him decide to look for a more automated approach. After building his first scanning scheduler he realized that it actually does not make sense to look at all findings every time they are reported. It would be much better to only investigate the....
|
|
frank^2 - Trolling Reverse-Engineers with Math: Ness... It hurts...
-
www.defcon.org
-
15 years ago
-
eng
y = mx+b? f(x) = sin(x/freq)*amp?! SIN X = (A+BX+CX^2)/(P+QX+RX^2)?! None of these formulas as they stand alone really mean much of anything-- except maybe a headache for some. Isolating the variables, however, will eventually open the door for us to manipulate our code in creative and exciting ways. This isn't necessarily a ground-breaking technique in obfuscation, but who cares if it's fun? Given an arbitrary formula, we can place our cod....
|
|
Frank Breedijk - Seccubus - Analyzing Vulnerability Assessment Data the Easy Way
-
www.defcon.org
-
15 years ago
-
eng
As part of his job as Security Engineer at Schuberg Philis, Frank Breedijk performs regular security scans. The repetitive nature of scanning the same customer infrastructure over and over again made him decide to look for a more automated approach. After building his first scanning scheduler he realized that it actually does not make sense to look at all findings every time they are reported. It would be much better to only investigate the....
|
|
frank^2 - Trolling Reverse-Engineers with Math: Ness... It hurts...
-
www.defcon.org
-
15 years ago
-
eng
y = mx+b? f(x) = sin(x/freq)*amp?! SIN X = (A+BX+CX^2)/(P+QX+RX^2)?! None of these formulas as they stand alone really mean much of anything-- except maybe a headache for some. Isolating the variables, however, will eventually open the door for us to manipulate our code in creative and exciting ways. This isn't necessarily a ground-breaking technique in obfuscation, but who cares if it's fun? Given an arbitrary formula, we can place our cod....
|
|
Most hackers can use Nmap for simple port scanning and OS detection, but the Nmap Scripting Engine (NSE) takes scanning to a whole new level. Nmap's high-speed networking engine can now spider web sites for SQL injection vulnerabilities, brute-force crack and query MSRPC services, find open proxies, and more. Nmap includes more than 125 NSE scripts for network discovery, vulnerability detection, exploitation, and authentication cracking. ....
|
|
Most hackers can use Nmap for simple port scanning and OS detection, but the Nmap Scripting Engine (NSE) takes scanning to a whole new level. Nmap's high-speed networking engine can now spider web sites for SQL injection vulnerabilities, brute-force crack and query MSRPC services, find open proxies, and more. Nmap includes more than 125 NSE scripts for network discovery, vulnerability detection, exploitation, and authentication cracking. ....
|
|
Most hackers can use Nmap for simple port scanning and OS detection, but the Nmap Scripting Engine (NSE) takes scanning to a whole new level. Nmap's high-speed networking engine can now spider web sites for SQL injection vulnerabilities, brute-force crack and query MSRPC services, find open proxies, and more. Nmap includes more than 125 NSE scripts for network discovery, vulnerability detection, exploitation, and authentication cracking. ....
|
|
Learn how to crack crypto contests like a pro. The speaker has awarded half a dozen free round-trip plane tickets to previous contest winners. Maybe you'll be next. From the daily newspaper puzzle to badge contests to codes that keep the National Security Agency awake at night, it all comes down to intuition, perspiration, and math skillz. G. Mark Hardy has been providing information security expertise to government, military, and comm....
|
|
Learn how to crack crypto contests like a pro. The speaker has awarded half a dozen free round-trip plane tickets to previous contest winners. Maybe you'll be next. From the daily newspaper puzzle to badge contests to codes that keep the National Security Agency awake at night, it all comes down to intuition, perspiration, and math skillz. G. Mark Hardy has been providing information security expertise to government, military, and comm....
|
|
Learn how to crack crypto contests like a pro. The speaker has awarded half a dozen free round-trip plane tickets to previous contest winners. Maybe you'll be next. From the daily newspaper puzzle to badge contests to codes that keep the National Security Agency awake at night, it all comes down to intuition, perspiration, and math skillz. G. Mark Hardy has been providing information security expertise to government, military, and comm....
|
|
Behold! Billions of computers are infected with spyware every decade! But how! And why! Let's join our host as he takes you behind the curtain of the mysterious spyware industry. This will be a high level discussion with no technical knowledge needed. I'll be covering how I ended up writing spyware, what the software was capable of, how it was deployed onto millions of machines, how all the money was made (not how you'd expect) and how....
|
|
Behold! Billions of computers are infected with spyware every decade! But how! And why! Let's join our host as he takes you behind the curtain of the mysterious spyware industry. This will be a high level discussion with no technical knowledge needed. I'll be covering how I ended up writing spyware, what the software was capable of, how it was deployed onto millions of machines, how all the money was made (not how you'd expect) and how....
|
|
Behold! Billions of computers are infected with spyware every decade! But how! And why! Let's join our host as he takes you behind the curtain of the mysterious spyware industry. This will be a high level discussion with no technical knowledge needed. I'll be covering how I ended up writing spyware, what the software was capable of, how it was deployed onto millions of machines, how all the money was made (not how you'd expect) and how....
|
|
Greg Conti - Our Instrumented Lives: Sensors, Sensors, Everywhere...
-
www.defcon.org
-
15 years ago
-
eng
Make no mistake, your analog life is under siege. Virtually every facet of your day to day existence is being sampled, digitized, aggregated, collated, shared, and reality mined. Whether the reason is to support your friendly neighborhood targeted advertiser or to help win a war on terror, a thickening web of sensors tracks our day to day existence in the physical world. Sensors are everywhere: our sneakers, cell phones, appliances, game co....
|
|
Greg Conti - Our Instrumented Lives: Sensors, Sensors, Everywhere...
-
www.defcon.org
-
15 years ago
-
eng
Make no mistake, your analog life is under siege. Virtually every facet of your day to day existence is being sampled, digitized, aggregated, collated, shared, and reality mined. Whether the reason is to support your friendly neighborhood targeted advertiser or to help win a war on terror, a thickening web of sensors tracks our day to day existence in the physical world. Sensors are everywhere: our sneakers, cell phones, appliances, game co....
|
|
Greg Conti - Our Instrumented Lives: Sensors, Sensors, Everywhere...
-
www.defcon.org
-
15 years ago
-
eng
Make no mistake, your analog life is under siege. Virtually every facet of your day to day existence is being sampled, digitized, aggregated, collated, shared, and reality mined. Whether the reason is to support your friendly neighborhood targeted advertiser or to help win a war on terror, a thickening web of sensors tracks our day to day existence in the physical world. Sensors are everywhere: our sneakers, cell phones, appliances, game co....
|
|
The proprietary protocol developed by Adobe Systems for streaming audio, video and data over the Internet, the ëReal Time Messaging Protocol- (RTMP) and the proprietary protocol created by Macromedia used for streaming video and DRM, -Encrypted Real Time Messaging Protocol- (RTMPE) implementations for MySpace use security through obscurity and actually provide zero security. This talk will describe methods and demonstrate how to downlo....
|
|
CyberWar has been a controversial topic in the past few years. Some say the the mere term is an error. CyberCrime on the other hand has been a major source of concern, as lack of jurisdiction and law enforcement have made it one of organized crime's best sources of income. In this talk we will explore the uncharted waters between CyberCrime and CyberWarfare, while mapping out the key players (mostly on the state side) and how past even....
|
|
The proprietary protocol developed by Adobe Systems for streaming audio, video and data over the Internet, the ëReal Time Messaging Protocol- (RTMP) and the proprietary protocol created by Macromedia used for streaming video and DRM, -Encrypted Real Time Messaging Protocol- (RTMPE) implementations for MySpace use security through obscurity and actually provide zero security. This talk will describe methods and demonstrate how to downlo....
|
|
CyberWar has been a controversial topic in the past few years. Some say the the mere term is an error. CyberCrime on the other hand has been a major source of concern, as lack of jurisdiction and law enforcement have made it one of organized crime's best sources of income. In this talk we will explore the uncharted waters between CyberCrime and CyberWarfare, while mapping out the key players (mostly on the state side) and how past even....
|
|
The proprietary protocol developed by Adobe Systems for streaming audio, video and data over the Internet, the ëReal Time Messaging Protocol- (RTMP) and the proprietary protocol created by Macromedia used for streaming video and DRM, -Encrypted Real Time Messaging Protocol- (RTMPE) implementations for MySpace use security through obscurity and actually provide zero security. This talk will describe methods and demonstrate how to downlo....
|
|
CyberWar has been a controversial topic in the past few years. Some say the the mere term is an error. CyberCrime on the other hand has been a major source of concern, as lack of jurisdiction and law enforcement have made it one of organized crime's best sources of income. In this talk we will explore the uncharted waters between CyberCrime and CyberWarfare, while mapping out the key players (mostly on the state side) and how past even....
|
|
Itzhak "zuk" Avraham - Exploitation on ARM - Technique and Bypassing Defense Mechanisms
-
www.defcon.org
-
15 years ago
-
eng
In this presentation there will be covered (from scratch) quick talk on security mechanisms on X86 and how to bypass them, how exploits are being used on X86 and why they won't work as is on ARM, How to approach ARM assembly from hacker point of view and how to write exploits in the proper way for a remote and local attacker on ARM, what are the options for ARM hacker, etc. This presentation starts from the very basics of ARM assembly ....
|
|
Itzhak "zuk" Avraham - Exploitation on ARM - Technique and Bypassing Defense Mechanisms
-
www.defcon.org
-
15 years ago
-
eng
In this presentation there will be covered (from scratch) quick talk on security mechanisms on X86 and how to bypass them, how exploits are being used on X86 and why they won't work as is on ARM, How to approach ARM assembly from hacker point of view and how to write exploits in the proper way for a remote and local attacker on ARM, what are the options for ARM hacker, etc. This presentation starts from the very basics of ARM assembly ....
|
|
Itzhak "zuk" Avraham - Exploitation on ARM - Technique and Bypassing Defense Mechanisms
-
www.defcon.org
-
15 years ago
-
eng
In this presentation there will be covered (from scratch) quick talk on security mechanisms on X86 and how to bypass them, how exploits are being used on X86 and why they won't work as is on ARM, How to approach ARM assembly from hacker point of view and how to write exploits in the proper way for a remote and local attacker on ARM, what are the options for ARM hacker, etc. This presentation starts from the very basics of ARM assembly ....
|
|
Jack Daniel & Panel - PCI, Compromising Controls and Compromising Security
-
www.defcon.org
-
15 years ago
-
eng
PCI at DefCon? Are you on drugs? Sadly, no- compliance is changing the way companies "do security", and that has an effect on everyone, defender, attacker, or innocent bystander. If you think all that 0-day you've heard about this week is scary, ask yourself this: if a company accepts credit cards for payment, which is a more immediate threat- failing an audit or the possibility of being compromised by an attacker? That is one of the reason....
|
|
Jack Daniel & Panel - PCI, Compromising Controls and Compromising Security
-
www.defcon.org
-
15 years ago
-
eng
PCI at DefCon? Are you on drugs? Sadly, no- compliance is changing the way companies "do security", and that has an effect on everyone, defender, attacker, or innocent bystander. If you think all that 0-day you've heard about this week is scary, ask yourself this: if a company accepts credit cards for payment, which is a more immediate threat- failing an audit or the possibility of being compromised by an attacker? That is one of the reason....
|
|
Jack Daniel & Panel - PCI, Compromising Controls and Compromising Security
-
www.defcon.org
-
15 years ago
-
eng
PCI at DefCon? Are you on drugs? Sadly, no- compliance is changing the way companies "do security", and that has an effect on everyone, defender, attacker, or innocent bystander. If you think all that 0-day you've heard about this week is scary, ask yourself this: if a company accepts credit cards for payment, which is a more immediate threat- failing an audit or the possibility of being compromised by an attacker? That is one of the reason....
|
|
James Arlen - SCADA and ICS for Security Experts: How to Avoid Cyberdouchery
-
www.defcon.org
-
15 years ago
-
eng
The traditional security industry has somehow decided that they are the white knights who are going to save everyone from the horror of insecure powergrids, pipelines, chemical plants, and cookie factories. Suddenly, every consultant is an expert and every product fixes SCADA. And because they don't know what the hell they're talking about -- 'fake it till ya make it' doesn't work -- they're making all of us look stupid. Attendees will....
|
|
All significant modern applications are ported to the web. Even with custom applications, there is at least one web-based component. Web applications are partially dependent on web clients and are continuously part of the security equation. These issues manifest in ways that make the user vulnerable. For example, privacy vulnerabilities are demonstrated with the EFF's Panopticlick browser fingerprinting project. Whether the weakness is priv....
|
|
James Arlen - SCADA and ICS for Security Experts: How to Avoid Cyberdouchery
-
www.defcon.org
-
15 years ago
-
eng
The traditional security industry has somehow decided that they are the white knights who are going to save everyone from the horror of insecure powergrids, pipelines, chemical plants, and cookie factories. Suddenly, every consultant is an expert and every product fixes SCADA. And because they don't know what the hell they're talking about -- 'fake it till ya make it' doesn't work -- they're making all of us look stupid. Attendees will....
|
|
All significant modern applications are ported to the web. Even with custom applications, there is at least one web-based component. Web applications are partially dependent on web clients and are continuously part of the security equation. These issues manifest in ways that make the user vulnerable. For example, privacy vulnerabilities are demonstrated with the EFF's Panopticlick browser fingerprinting project. Whether the weakness is priv....
|
|
James Arlen - SCADA and ICS for Security Experts: How to Avoid Cyberdouchery
-
www.defcon.org
-
15 years ago
-
eng
The traditional security industry has somehow decided that they are the white knights who are going to save everyone from the horror of insecure powergrids, pipelines, chemical plants, and cookie factories. Suddenly, every consultant is an expert and every product fixes SCADA. And because they don't know what the hell they're talking about -- 'fake it till ya make it' doesn't work -- they're making all of us look stupid. Attendees will....
|
|
All significant modern applications are ported to the web. Even with custom applications, there is at least one web-based component. Web applications are partially dependent on web clients and are continuously part of the security equation. These issues manifest in ways that make the user vulnerable. For example, privacy vulnerabilities are demonstrated with the EFF's Panopticlick browser fingerprinting project. Whether the weakness is priv....
|
|
Jason Scott - You're Stealing It Wrong! 30 Years of Inter-Pirate Battles
-
www.defcon.org
-
15 years ago
-
eng
Historian Jason Scott walks through the many-years story of software piracy and touches on the tired debates before going into a completely different direction - the interesting, informative, hilarious and occasionally obscene world of inter-pirate-group battles. A multi-media extravaganza of threats, CSI-level accusations and evidence trails, decades of insider lingo, and demonstrations of how the more things change, the more they still ha..
|
|
Jason Scott - You're Stealing It Wrong! 30 Years of Inter-Pirate Battles
-
www.defcon.org
-
15 years ago
-
eng
Historian Jason Scott walks through the many-years story of software piracy and touches on the tired debates before going into a completely different direction - the interesting, informative, hilarious and occasionally obscene world of inter-pirate-group battles. A multi-media extravaganza of threats, CSI-level accusations and evidence trails, decades of insider lingo, and demonstrations of how the more things change, the more they still ha..
|
|
Jason Scott - You're Stealing It Wrong! 30 Years of Inter-Pirate Battles
-
www.defcon.org
-
15 years ago
-
eng
Historian Jason Scott walks through the many-years story of software piracy and touches on the tired debates before going into a completely different direction - the interesting, informative, hilarious and occasionally obscene world of inter-pirate-group battles. A multi-media extravaganza of threats, CSI-level accusations and evidence trails, decades of insider lingo, and demonstrations of how the more things change, the more they still ha..
|
|
Jayson E. Street - Deceiving the Heavens to Cross the Sea: Using the 36 Stratagems for Social Engineering
-
www.defcon.org
-
15 years ago
-
eng
There are new threats arising every day. The problem is there has been a vulnerability in the system that has not been patched since the first computer was created by Humans! As the network perimeter hardens and the controls on the desktop tightens. Hackers are going back to the basics and getting through the firewall by going through the front door. They are bypassing the IPS and IDS simply by bypassing the receptionist. We look ....
|
|
Jayson E. Street - Deceiving the Heavens to Cross the Sea: Using the 36 Stratagems for Social Engineering
-
www.defcon.org
-
15 years ago
-
eng
There are new threats arising every day. The problem is there has been a vulnerability in the system that has not been patched since the first computer was created by Humans! As the network perimeter hardens and the controls on the desktop tightens. Hackers are going back to the basics and getting through the firewall by going through the front door. They are bypassing the IPS and IDS simply by bypassing the receptionist. We look ....
|
|
Jayson E. Street - Deceiving the Heavens to Cross the Sea: Using the 36 Stratagems for Social Engineering
-
www.defcon.org
-
15 years ago
-
eng
There are new threats arising every day. The problem is there has been a vulnerability in the system that has not been patched since the first computer was created by Humans! As the network perimeter hardens and the controls on the desktop tightens. Hackers are going back to the basics and getting through the firewall by going through the front door. They are bypassing the IPS and IDS simply by bypassing the receptionist. We look ....
|
|
You downloaded google toolbar because it came with Adobe, or you are a a Google fanboy. You started using it to store your bookmarks because you're too lame to rsync them like real man. Little do you know that google is selling you out to your corporate security staff. They now know about the midget porn...the porn you bookmarked at home, but never view at work. Yes *that* porn Jeff Bryner has 20 years of experience integrating systems..
|
|
You downloaded google toolbar because it came with Adobe, or you are a a Google fanboy. You started using it to store your bookmarks because you're too lame to rsync them like real man. Little do you know that google is selling you out to your corporate security staff. They now know about the midget porn...the porn you bookmarked at home, but never view at work. Yes *that* porn Jeff Bryner has 20 years of experience integrating systems..
|